6.0.0-beta1
7/22/25

[#2076] Need for safe URLs
Summary Need for safe URLs
Queue Horde Base
Queue Version HEAD
Type Enhancement
State Rejected
Priority 1. Low
Owners
Requester kevin_myer (at) iu13 (dot) org
Created 06/05/2005 (7352 days ago)
Due
Updated 11/09/2008 (6099 days ago)
Assigned
Resolved 11/09/2008 (6099 days ago)
Milestone
Patch No

History
11/09/2008 04:20:52 PM Chuck Hagenbuch Comment #6
State ⇒ Rejected
Reply to this comment
Since we only use go.php now when not using cookies, this is much less 
of an issue.
06/06/2005 11:22:27 AM Jan Schneider State ⇒ Stalled
 
06/06/2005 01:29:34 AM kevin_myer (at) iu13 (dot) org Comment #5 Reply to this comment
I don't have any good suggestions on how to handle it.  Like I said, I 
understand why the check is there but it hampers the use of some of 
Horde's own modules features.  Security and useability are often at 
odds with each other.
06/05/2005 11:40:38 PM Chuck Hagenbuch Comment #4 Reply to this comment
I'm open to suggestions, if you like. Consider the case of an image in 
an html email that deletes your calendar, vs. the attend.php links. 
Should we just make a big ugly list of things we might link to in 
Horde? I sure don't want to maintain it....
06/05/2005 11:33:58 PM kevin_myer (at) iu13 (dot) org Comment #3 Reply to this comment
Hrm.. that leaves me at an impasse.  I want people to use Horde.  And 
I want people to heed warnings on links that make scary (to them) 
warning statements :)  And for once, some of them are actually heeding 
the warning.



That really puts a damper on using linked attachments though.
06/05/2005 11:04:52 PM Chuck Hagenbuch Comment #2
State ⇒ Feedback
Reply to this comment
There is no way we can do this without rewriting all of Horde to 
ensure that no destructive action can ever occur on a GET. That's a 
reasonable long-term goal, though...
06/05/2005 04:03:14 AM kevin_myer (at) iu13 (dot) org Comment #1
Priority ⇒ 1. Low
Type ⇒ Enhancement
Summary ⇒ Need for safe URLs
Queue ⇒ Horde Base
State ⇒ New
Reply to this comment
On two occasions now, Horde has generated Potentially Dangerous URL 
warnings - when clicking on Kronolith attend.php links from IMP, and 
when clicking on linked attachments links from IMP.  I understand the 
idea behind the warning but it would be helpful if Horde treated 
things like linked attachments and Kronolith attend.php links as "safe".

Saved Queries