<?xml version="1.0" encoding="UTF-8"?> 
<?xml-stylesheet href="https://dev.horde.org/themes/horde//default/feed-rss.xsl" type="text/xsl"?> 
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"> 
 <channel> 
  <title>Need for safe URLs</title> 
  <pubDate>Fri, 10 Apr 2026 09:35:40 +0000</pubDate> 
  <link>https://bugs.horde.org/ticket/2076</link> 
  <atom:link rel="self" type="application/rss+xml" title="Need for safe URLs" href="https://bugs.horde.org/ticket/2076/rss" /> 
  <description>Need for safe URLs</description> 
 
   
   
  <item> 
   <title>On two occasions now, Horde has generated Potentially Danger</title> 
   <description>On two occasions now, Horde has generated Potentially Dangerous URL warnings - when clicking on Kronolith attend.php links from IMP, and when clicking on linked attachments links from IMP.  I understand the idea behind the warning but it would be helpful if Horde treated things like linked attachments and Kronolith attend.php links as &quot;safe&quot;.</description> 
   <pubDate>Sun, 05 Jun 2005 04:03:14 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/2076#t8863</link> 
  </item> 
   
  <item> 
   <title>There is no way we can do this without rewriting all of Hord</title> 
   <description>There is no way we can do this without rewriting all of Horde to ensure that no destructive action can ever occur on a GET. That&#039;s a reasonable long-term goal, though...</description> 
   <pubDate>Sun, 05 Jun 2005 23:04:52 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/2076#t8872</link> 
  </item> 
   
  <item> 
   <title>Hrm.. that leaves me at an impasse.  I want people to use Ho</title> 
   <description>Hrm.. that leaves me at an impasse.  I want people to use Horde.  And I want people to heed warnings on links that make scary (to them) warning statements :)  And for once, some of them are actually heeding the warning.



That really puts a damper on using linked attachments though.</description> 
   <pubDate>Sun, 05 Jun 2005 23:33:58 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/2076#t8873</link> 
  </item> 
   
  <item> 
   <title>I&#039;m open to suggestions, if you like. Consider the case of a</title> 
   <description>I&#039;m open to suggestions, if you like. Consider the case of an image in an html email that deletes your calendar, vs. the attend.php links. Should we just make a big ugly list of things we might link to in Horde? I sure don&#039;t want to maintain it....</description> 
   <pubDate>Sun, 05 Jun 2005 23:40:38 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/2076#t8874</link> 
  </item> 
   
  <item> 
   <title>I don&#039;t have any good suggestions on how to handle it.  Like</title> 
   <description>I don&#039;t have any good suggestions on how to handle it.  Like I said, I understand why the check is there but it hampers the use of some of Horde&#039;s own modules features.  Security and useability are often at odds with each other.</description> 
   <pubDate>Mon, 06 Jun 2005 01:29:34 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/2076#t8878</link> 
  </item> 
   
  <item> 
   <title>Since we only use go.php now when not using cookies, this is</title> 
   <description>Since we only use go.php now when not using cookies, this is much less of an issue.</description> 
   <pubDate>Sun, 09 Nov 2008 16:20:52 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/2076#t50598</link> 
  </item> 
   
   
 
 </channel> 
</rss> 
