[Sugar-devel] [PATCH Browse] Error page SL #3500

Daniel Narvaez dwnarvaez at gmail.com
Tue Sep 25 13:12:22 EDT 2012


The API description is not very clear and I didn't read the code. But
I guess it would allow remote web pages (http) to access local files?
If so you don't want to enable it :)

On 25 September 2012 18:43, Manuel Kaufmann <humitos at gmail.com> wrote:
> On Fri, Sep 21, 2012 at 8:32 PM, Martin Langhoff
> <martin.langhoff at gmail.com> wrote:
>> So just put <img src="file:///path/to/file" >. That saves a some of
>> pointless CPU cycles, some RAM.
>> This old man doesn't like inefficient code, even in small details.
>
> I agree with you in this point but I would like to mention that this
> "feature" (reading from file:// uri) has to be enabled because it is
> not enabled by default[1] and this is because it was marked as a
> security issue[2].
>
> ** Message: console message:  @0: Not allowed to load local resource:
> file:///home/humitos/src/browse/browse.png
>
> What do you think? Should I go for the file:// approach anyway?
>
> [1] http://webkitgtk.org/reference/webkitgtk/stable/WebKitWebSettings.html#WebKitWebSettings--enable-file-access-from-file-uris
> [2] http://en.wikipedia.org/wiki/File_URI_scheme
>
> --
> Kaufmann Manuel
> Blog: http://humitos.wordpress.com/
> Porfolio: http://fotos.mkaufmann.com.ar/
> PyAr: http://www.python.com.ar/
> _______________________________________________
> Sugar-devel mailing list
> Sugar-devel at lists.sugarlabs.org
> http://lists.sugarlabs.org/listinfo/sugar-devel



-- 
Daniel Narvaez


More information about the Sugar-devel mailing list