On Sat, 30 Aug 2003 12:59:12 -0400 (EDT) "Scott R. Godin"
<[EMAIL PROTECTED]> wrote:
> On Sat, 30 Aug 2003, Marc Wilson wrote:
> > The fact that blackbox allows an *arbitrary* command there is a
> > rather large hole that *I*, for one, would rather not deal with.
> 
> Sean, he actually makes a good point here. Would it be safer to
> specify the program to use for setting the background somewhere else,
> and just have the style specify the /path/to/image to be used as the
> background at this point?

I can't argue with the security issue. On the other hand, you can do so
many nice things with that command, like change the background image as
well as gtk and kde theme and so on upon changing the BB style. I'd like
to keep that flexibility.

As I see it, the compromise would be to have the "background program"
specified in the BB rc file and the background image path be passed as a
parameter. This way I can modify the background program and use a bash
script which will do whatever I want as well as change the background,
while being safe from malicious style files.

Speaking of which, has there been any decision regarding the new BB
resource directory layout? IIRC there was an idea about moving
~/.blackboxrc to ~/.blackbox/rc but that's about all I remember.

-- 
Ciprian Popovici

-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
List archives:  http://asgardsrealm.net/lurker/splash/index.html
Trouble? Contact [EMAIL PROTECTED]

Reply via email to