[prev in list] [next in list] [prev in thread] [next in thread] 

List:       kde-pim
Subject:    Re: [Kde-pim] reminder program on alarm.
From:       David Jarvie <lists () astrojar ! org ! uk>
Date:       2005-06-25 15:49:46
Message-ID: 200506251649.47832.lists () astrojar ! org ! uk
[Download RAW message or body]

On Friday 24 Jun 2005 19:06, Mario Teijeiro Otero wrote:
> Hi,
>  Attached goes the patch that permits pass params to the program. It
> understand certains macros (%d, %e,%D,%s ,%o) to expand.
>  There are one security problem in the deal with the execution of programs
> on alarms. This problem resides  on the remote calendars, that have
> assigned a "rm -rf /home/*" on the program.
>  Evolution treats this asking for the user to execute the command. This has
> the objection that avoid the unmaintenance operation.
>  How should we treat this ?
>
>  Please, review the i18n's strings (my english is not very good), like you
> could noticed ;-).

Your patch doesn't appear to comply with RFC2445, which specifies that any 
program arguments should be stored in the DESCRIPTION property of the alarm. 
The ATTACH property, which is where the alarm->programFile() is stored, 
should contain only the program name/path/URL. You need to modify it to use 
Alarm::programArguments() etc. for the arguments.

Cheers,
David.
_______________________________________________
kde-pim mailing list
kde-pim@kde.org
https://mail.kde.org/mailman/listinfo/kde-pim
kde-pim home page at http://pim.kde.org/
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic