From kde-core-devel Fri Oct 17 22:26:00 2014 From: Kevin Kofler Date: Fri, 17 Oct 2014 22:26:00 +0000 To: kde-core-devel Subject: Re: Porting KUrl::prettyUrl: please do not reintroduce CVE-2013-2074! Message-Id: X-MARC-Message: https://marc.info/?l=kde-core-devel&m=141358479325485 I wrote: > just a small public service announcement: The correct replacement for: > url.prettyUrl() > in Qt 5 is NOT: > url.toString() // BAD! > but: > url.toString(QUrl::RemovePassword) or, even better: url.toDisplayString() as pointed out by Andrea Iacovitti. (I guess his message is pending moderation.) Kevin Kofler