6.0.0-alpha14
7/2/25

[#12599] ckeditor update
Summary ckeditor update
Queue IMP
Queue Version Git master
Type Bug
State Not A Bug
Priority 1. Low
Owners
Requester l.kiraly (at) madalbal (dot) hu
Created 08/22/2013 (4332 days ago)
Due
Updated 08/26/2013 (4328 days ago)
Assigned
Resolved 08/22/2013 (4332 days ago)
Github Issue Link
Github Pull Request
Milestone
Patch No

History
08/26/2013 11:09:05 AM Jan Schneider Comment #7 Reply to this comment
One more note for the security issue.
If it has so much problem, why can I paste formatted text to gmail too?
Gmail has incomparably bigger user base. Why this problem didn't 
appear there?
Why isn't gmail.com in the blacklist in every smtp server?
Because Google has a team of hundreds of developers who can take care 
just of their editor. Pay us or ckeditor a few million dollars and we 
might be able to catch up too.
08/26/2013 11:01:02 AM l (dot) kiraly (at) madalbal (dot) hu Comment #6 Reply to this comment
One more note for the security issue.
If it has so much problem, why can I paste formatted text to gmail too?
Gmail has incomparably bigger user base. Why this problem didn't appear there?
Why isn't gmail.com in the blacklist in every smtp server?

08/23/2013 09:29:04 AM l (dot) kiraly (at) madalbal (dot) hu Comment #5 Reply to this comment
Yes it does.  I can verify dragging/pasting images work just fine in IMP.
For me it doesn't work. If I copy an image to the clipboard, and
paste to the composing field, I got only this in the html source:
Works fine for me.  You must use the paste button (not the paste 
plain text button).
I tried with CTRL-V, drag&drop, pushing the "paste from word" button.
None of them work, but in the same site all method work with the 
installed ckeditor.

Can cause it an IMP setting?
I enabled firebug during the operation, but no error appeared. Nothing 
happened.
We disable pasting non-plain text for various security and resource
limitation reasons.
Yes, security could be a problem if the user copy from foreign sites.
In my case, the user copy only from our site so it isn't a problem.
Because of this restriction the usability is drastically reduced.
The user have to save contents to the disk, than attach each, even 
it's only a simple html snippet.
It increases the working time a lot, and in a html formatted mail it's 
nonsense to attach html contents.
It's a work performance killer.
Can you please at least make this optional, with a setting?
No.  But its open source software so you can feel free to edit as 
you see fit and open security holes and allow users to bypass ALL 
resource restrictions if that's what you want.
The security hole is the USER in this case.

Assume there is a html table with harmful elements, what the user have 
to send to his partner.

In this case, he will do that, because he doesn't know, there is a 
harmful content that he doesn't see.
He only have a task that he has to do somehow. So if he can't paste, 
he will attach it.
He won't paste it as a clear text because this table will be 
unreadable and useless.
Will you win, and prevent infecting the receiver's computer? No, 
because the receiver also needs the information of this content, and 
he will open the attachment.

You only hardened the usability of IMP.


About changing the software: Yes I can change it, but what about the 
future maintenance?
In every update I have to check inconsistency.
You do not want me to do that?

08/23/2013 06:38:48 AM Michael Slusarz Comment #4 Reply to this comment
Yes it does.  I can verify dragging/pasting images work just fine in IMP.
For me it doesn't work. If I copy an image to the clipboard, and 
paste to the composing field, I got only this in the html source:
Works fine for me.  You must use the paste button (not the paste plain 
text button).
We disable pasting non-plain text for various security and resource
limitation reasons.
It's a work performance killer.
Can you please at least make this optional, with a setting?
No.  But its open source software so you can feel free to edit as you 
see fit and open security holes and allow users to bypass ALL resource 
restrictions if that's what you want.
08/23/2013 06:29:07 AM l (dot) kiraly (at) madalbal (dot) hu Comment #3 Reply to this comment
Yes it does.  I can verify dragging/pasting images work just fine in IMP.
For me it doesn't work. If I copy an image to the clipboard, and paste 
to the composing field, I got only this in the html source:

---
&nbsp;<br />
---

What could be the problem? I couldn't find any settings in imp 
regarding this issue.

I unzipped the fresh ckeditor package inside the horde installation, 
and tested with the samples. Everything worked.
We disable pasting non-plain text for various security and resource 
limitation reasons.
It's a work performance killer.
Can you please at least make this optional, with a setting?

08/22/2013 08:36:41 PM Michael Slusarz Comment #2
State ⇒ Not A Bug
Reply to this comment
Yes it does.  I can verify dragging/pasting images work just fine in IMP.

We disable pasting non-plain text for various security and resource 
limitation reasons.
08/22/2013 08:51:32 AM l (dot) kiraly (at) madalbal (dot) hu Comment #1
Priority ⇒ 1. Low
Type ⇒ Bug
Summary ⇒ ckeditor update
Queue ⇒ IMP
Milestone ⇒
Patch ⇒ No
State ⇒ Unconfirmed
Reply to this comment
I tried in the official ckeditor demo to paste rich content (html 
tables, pictures, web links), drag'n'drop pictures to the editor field.
Everything worked, but in IMP those things don't work.

Saved Queries