Re: [File Upload] Security problems with File Upload

2006-09-22 Thread Ian Hickson
On Fri, 22 Sep 2006, Robin Berjon wrote: I would feel much more comfortable if the FileList API was provided merely as an extension to the HTMLInputElement interface, thus requiring authors to use an input type=file control, and requiring users to click the Browse button before the

Re: [File Upload] Security problems with File Upload

2006-09-22 Thread Robin Berjon
Hi Ian, On Sep 22, 2006, at 17:15, Ian Hickson wrote: It seems like it would make it possible, through an attack like the famous fast clicking game, to cause a user to select a file (probably at random, but from the user's home directory, so likely a confidential file). There are