<?xml version="1.0" encoding="UTF-8"?> 
<?xml-stylesheet href="https://dev.horde.org/themes/horde//default/feed-rss.xsl" type="text/xsl"?> 
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"> 
 <channel> 
  <title>default setting for inline images: give link to show them</title> 
  <pubDate>Fri, 10 Apr 2026 12:09:54 +0000</pubDate> 
  <link>https://bugs.horde.org/ticket/10477</link> 
  <atom:link rel="self" type="application/rss+xml" title="default setting for inline images: give link to show them" href="https://bugs.horde.org/ticket/10477/rss" /> 
  <description>default setting for inline images: give link to show them</description> 
 
   
   
  <item> 
   <title>I am informed that the default setting intentionally blocks </title> 
   <description>I am informed that the default setting intentionally blocks inline images in Horde (IMP 4.3.9), so email such as newsletters cannot be read.

We were able to change the config to offer the reader &quot;show images&quot;, which solved the problem, but why isn&#039;t this set as default? It should be.

Specifically, we updated is the &#039;html&#039; config section in /usr/local/cpanel/base/horde/imp/config/mime_drivers.php  to get the option to &quot;show images&quot;



</description> 
   <pubDate>Thu, 01 Sep 2011 17:33:11 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/10477#t67230</link> 
  </item> 
   
  <item> 
   <title>&gt; I am informed that the default setting intentionally block</title> 
   <description>&gt; I am informed that the default setting intentionally blocks inline 
&gt; images in Horde (IMP 4.3.9), so email such as newsletters cannot be 
&gt; read.

Do you mean images contained in HTML?  We don&#039;t block inline images.

&gt; We were able to change the config to offer the reader &quot;show images&quot;, 
&gt; which solved the problem, but why isn&#039;t this set as default? It 
&gt; should be.

There&#039;s a reason they are blocked by default.  That&#039;s a crazy huge security risk to allow automatic loading of a foreign URL upon opening a message.</description> 
   <pubDate>Thu, 01 Sep 2011 20:49:17 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/10477#t67233</link> 
  </item> 
   
  <item> 
   <title>Cpanel support suggested that the default setting is to dipl</title> 
   <description>Cpanel support suggested that the default setting is to diplay the message &quot;There are no parts that can be displayed inline.&quot; However, we were able to change the config so that it  displays &quot;Images have been blocked to protect your privacy. Show Images?&quot; 

I recommend that the &quot;show images&quot; link be offered as the default setting, not the&quot; no parts that can be displayed inline&quot; message. Please see the attached images for comparison.

So if you are not blocking inline images, I presume the &quot;show images&#039; link should already be default, is that correct?</description> 
   <pubDate>Thu, 01 Sep 2011 21:14:51 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/10477#t67235</link> 
  </item> 
   
  <item> 
   <title>&gt; Cpanel support suggested that the default setting is to di</title> 
   <description>&gt; Cpanel support suggested that the default setting is to diplay the 
&gt; message &quot;There are no parts that can be displayed inline.&quot; However, 
&gt; we were able to change the config so that it  displays &quot;Images have 
&gt; been blocked to protect your privacy. Show Images?&quot;
&gt;
&gt; I recommend that the &quot;show images&quot; link be offered as the default 
&gt; setting, not the&quot; no parts that can be displayed inline&quot; message. 
&gt; Please see the attached images for comparison.
&gt;
&gt; So if you are not blocking inline images, I presume the &quot;show images&#039; 
&gt; link should already be default, is that correct?

This has nothing to do with blocking images.  This has to do with displaying HTML parts inline.  The default is to NOT allow this (html inline display is false).  Displaying HTML messages by default is a gigantic security hole that an admin has to make a choice to allow locally.  (The HTML filter shipped with H4 is much better than the H3 filter, but there are still no guarantees).</description> 
   <pubDate>Thu, 01 Sep 2011 23:17:04 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/10477#t67236</link> 
  </item> 
   
  <item> 
   <title>&gt; Displaying HTML messages by default is a 
&gt; gigantic secu</title> 
   <description>&gt; Displaying HTML messages by default is a 
&gt; gigantic security hole that an admin has to make a choice to allow 
&gt; locally. 

OK can I suggest a better error message, such as HTML view is disabled for security reasons.

Also, are you saying that this is a gigantic security hole in general for all webmail services, even yahoo and gmail? Or specific to horde?

Thank you



</description> 
   <pubDate>Tue, 06 Sep 2011 21:17:28 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/10477#t67341</link> 
  </item> 
   
  <item> 
   <title>&gt;&gt; Displaying HTML messages by default is a
&gt;&gt; gigantic sec</title> 
   <description>&gt;&gt; Displaying HTML messages by default is a
&gt;&gt; gigantic security hole that an admin has to make a choice to allow
&gt;&gt; locally.
&gt;
&gt; OK can I suggest a better error message, such as HTML view is 
&gt; disabled for security reasons.

We already do this in IMP 5

&gt; Also, are you saying that this is a gigantic security hole in general 
&gt; for all webmail services, even yahoo and gmail? Or specific to horde?

It&#039;s a gigantic security hole in general.  Yahoo and gmail are not immune to this.  And advantage they may have is that their filtering is maintained by a (potentially) large group of engineers who are paid full-time.  But that doesn&#039;t mean that their filters are foolproof.</description> 
   <pubDate>Tue, 06 Sep 2011 21:25:44 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/10477#t67342</link> 
  </item> 
   
   
 
 </channel> 
</rss> 
