Re: [PATCH] Add a defcustom for whether to block remote images by default.
authorDavid Edmondson <dme@dme.org>
Thu, 29 Jan 2015 06:40:22 +0000 (06:40 +0000)
committerW. Trevor King <wking@tremily.us>
Sat, 20 Aug 2016 21:47:52 +0000 (14:47 -0700)
34/bfa38768faa71fdd8d55960d63893ca3872a2c [new file with mode: 0644]

diff --git a/34/bfa38768faa71fdd8d55960d63893ca3872a2c b/34/bfa38768faa71fdd8d55960d63893ca3872a2c
new file mode 100644 (file)
index 0000000..4a18ac2
--- /dev/null
@@ -0,0 +1,121 @@
+Return-Path: <dme@dme.org>\r
+X-Original-To: notmuch@notmuchmail.org\r
+Delivered-To: notmuch@notmuchmail.org\r
+Received: from localhost (localhost [127.0.0.1])\r
+       by olra.theworths.org (Postfix) with ESMTP id 1B99A431FBC\r
+       for <notmuch@notmuchmail.org>; Wed, 28 Jan 2015 22:40:33 -0800 (PST)\r
+X-Virus-Scanned: Debian amavisd-new at olra.theworths.org\r
+X-Spam-Flag: NO\r
+X-Spam-Score: 1.739\r
+X-Spam-Level: *\r
+X-Spam-Status: No, score=1.739 tagged_above=-999 required=5\r
+       tests=[DNS_FROM_AHBL_RHSBL=2.438, RCVD_IN_DNSWL_LOW=-0.7,\r
+       UNPARSEABLE_RELAY=0.001] autolearn=disabled\r
+Received: from olra.theworths.org ([127.0.0.1])\r
+       by localhost (olra.theworths.org [127.0.0.1]) (amavisd-new, port 10024)\r
+       with ESMTP id G3OH2yBobrtn for <notmuch@notmuchmail.org>;\r
+       Wed, 28 Jan 2015 22:40:28 -0800 (PST)\r
+Received: from mail-wi0-f178.google.com (mail-wi0-f178.google.com\r
+       [209.85.212.178]) (using TLSv1 with cipher RC4-SHA (128/128 bits))\r
+       (No client certificate requested)\r
+       by olra.theworths.org (Postfix) with ESMTPS id 9BF84431FAF\r
+       for <notmuch@notmuchmail.org>; Wed, 28 Jan 2015 22:40:27 -0800 (PST)\r
+Received: by mail-wi0-f178.google.com with SMTP id bs8so11508419wib.5\r
+       for <notmuch@notmuchmail.org>; Wed, 28 Jan 2015 22:40:25 -0800 (PST)\r
+X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;\r
+       d=1e100.net; s=20130820;\r
+       h=x-gm-message-state:to:subject:in-reply-to:references:user-agent\r
+       :from:date:message-id:mime-version:content-type;\r
+       bh=Ffm+dfdb9FmRP51nsCfoDYIBhKq7qLbRdC2k7QOHrsg=;\r
+       b=U3MXWikKW/NfQd/aZaCy2ik/YbQCTv6S2LrCm3Qu0ftLicpEGSPc3T0U4qGBSRwAHC\r
+       artSej6E4bKLyqOduqcq8eQs6qvMMUQTYitOx5lzl6OfzyY/6QyZf3apPjSXDJLIqJfk\r
+       I0Dpc+lXpwL0s2+f1raTQO5gBXNTGJ+QfA9L1Ir7fuc4ZmGIk6fxmVQbhyttHtaAIfKu\r
+       tuNQ3xW71Qcd1nGD1JVvd7SwM93z6duPyCyx7h47uhUtiHthVHjHZC4abbVyML+Hj+TE\r
+       jx3oPLYcP62W3bd3uESZSRoqG/xIQOVQKfW1n6xpMkegnJLZieOTi0di1vX1LLv754BJ\r
+       rUnQ==\r
+X-Gm-Message-State:\r
+ ALoCoQksHCa4OzY/9Co0b1QeX7wyXRToO8yE7o6dC+YGLqS4Quu/tt8lAAyONXCUSW/M4MOqPI5v\r
+X-Received: by 10.180.92.231 with SMTP id cp7mr1244255wib.24.1422513625066;\r
+       Wed, 28 Jan 2015 22:40:25 -0800 (PST)\r
+Received: from disaster-area.hh.sledj.net\r
+       ([2a01:348:1a2:1:ea39:35ff:fe2c:a227])\r
+       by mx.google.com with ESMTPSA id be2sm9063980wjb.38.2015.01.28.22.40.23\r
+       (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);\r
+       Wed, 28 Jan 2015 22:40:24 -0800 (PST)\r
+Received: from localhost (30000@localhost [local]);\r
+       by localhost (OpenSMTPD) with ESMTPA id 00f16893;\r
+       Thu, 29 Jan 2015 06:40:22 +0000 (UTC)\r
+To: Jinwoo Lee <jinwoo68@gmail.com>, notmuch@notmuchmail.org\r
+Subject: Re: [PATCH] Add a defcustom for whether to block remote images by\r
+       default.\r
+In-Reply-To: <1422495572-40384-1-git-send-email-jinwoo68@gmail.com>\r
+References: <1422495572-40384-1-git-send-email-jinwoo68@gmail.com>\r
+User-Agent: none\r
+From: David Edmondson <dme@dme.org>\r
+Date: Thu, 29 Jan 2015 06:40:22 +0000\r
+Message-ID: <cunlhkm2ip5.fsf@gargravarr.hh.sledj.net>\r
+MIME-Version: 1.0\r
+Content-Type: text/plain\r
+X-BeenThere: notmuch@notmuchmail.org\r
+X-Mailman-Version: 2.1.13\r
+Precedence: list\r
+List-Id: "Use and development of the notmuch mail system."\r
+       <notmuch.notmuchmail.org>\r
+List-Unsubscribe: <http://notmuchmail.org/mailman/options/notmuch>,\r
+       <mailto:notmuch-request@notmuchmail.org?subject=unsubscribe>\r
+List-Archive: <http://notmuchmail.org/pipermail/notmuch>\r
+List-Post: <mailto:notmuch@notmuchmail.org>\r
+List-Help: <mailto:notmuch-request@notmuchmail.org?subject=help>\r
+List-Subscribe: <http://notmuchmail.org/mailman/listinfo/notmuch>,\r
+       <mailto:notmuch-request@notmuchmail.org?subject=subscribe>\r
+X-List-Received-Date: Thu, 29 Jan 2015 06:40:35 -0000\r
+\r
+A defcustom for `notmuch-show-text/html-blocked-images', which is used\r
+to set `shr-blocked-images', would be more usable. It can default to "."\r
+to achieve the same result.\r
+\r
+On Thu, Jan 29 2015, Jinwoo Lee wrote:\r
+> ---\r
+>  emacs/notmuch-show.el | 15 +++++++++++----\r
+>  1 file changed, 11 insertions(+), 4 deletions(-)\r
+>\r
+> diff --git a/emacs/notmuch-show.el b/emacs/notmuch-show.el\r
+> index 66350d4..bc48922 100644\r
+> --- a/emacs/notmuch-show.el\r
+> +++ b/emacs/notmuch-show.el\r
+> @@ -136,6 +136,11 @@ indentation."\r
+>    :type 'boolean\r
+>    :group 'notmuch-show)\r
+>  \r
+> +(defcustom notmuch-show-block-remote-images t\r
+> +  "Block remote images by default."\r
+> +  :type 'boolean\r
+> +  :group 'notmuch-show)\r
+> +\r
+>  (defvar notmuch-show-thread-id nil)\r
+>  (make-variable-buffer-local 'notmuch-show-thread-id)\r
+>  (put 'notmuch-show-thread-id 'permanent-local t)\r
+> @@ -798,10 +803,12 @@ will return nil if the CID is unknown or cannot be retrieved."\r
+>         ;; URL-decode it (see RFC 2392).\r
+>         (let ((cid (url-unhex-string url)))\r
+>           (first (notmuch-show--get-cid-content cid)))))\r
+> -    ;; Block all external images to prevent privacy leaks and\r
+> -    ;; potential attacks.  FIXME: If we block an image, offer a\r
+> -    ;; button to load external images.\r
+> -    (shr-blocked-images "."))\r
+> +    ;; By default, block all external images to prevent privacy\r
+> +    ;; leaks and potential attacks.  FIXME: If we block an image,\r
+> +    ;; offer a button to load external images.\r
+> +    (shr-blocked-images (if notmuch-show-block-remote-images\r
+> +                            "."\r
+> +                          shr-blocked-images)))\r
+>      (shr-insert-document dom)\r
+>      t))\r
+>  \r
+> -- \r
+> 2.2.2\r
+>\r
+> _______________________________________________\r
+> notmuch mailing list\r
+> notmuch@notmuchmail.org\r
+> http://notmuchmail.org/mailman/listinfo/notmuch\r