Comment 1 for bug 773049

Revision history for this message
John A Meinel (jameinel) wrote : Re: [Bug 773049] [NEW] Enable option see as plain text on file summary

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 4/29/2011 10:52 AM, Angel Guzman Maeso wrote:
> Public bug reported:
>
> I think that add a option "see as plain text" on file summary could be
> useful for some users.
>

There is code (in lp:~loggerhead-team/loggerhead/experimental) that adds
a "/raw" output. (along with /view and /annotate). The main problem is
that it is a huge cross-site-scripting vector. Even if we tell the
browser "this is plain text", IE browsers see "oh, plain text with
<html> in it, let me render it as HTML".

I think there was some work to use special realms when exposing /raw so
that it can't get access to your other cookies, and other XSS tricks.

So this is somewhat in-progress, but requires a lot of security related
work still.

 status: confirmed
 importance: low

John
=:->
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (Cygwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAk26jO8ACgkQJdeBCYSNAAPbtgCfWFxY/HJQIYXoMyMAjXRnhsda
Xm0AoKQsO4SN6RaFASWQ94zO6uVaOl0C
=gret
-----END PGP SIGNATURE-----