On Thu, Sep 05, 2002 at 03:02:06AM -0400, Dan Merillat wrote:
> 
> Ian Clarke writes:
> > 
> > --iFRdW5/EC4oqxDHL
> > Content-Type: text/plain; charset=us-ascii
> > Content-Disposition: inline
> > Content-Transfer-Encoding: quoted-printable
> > 
> > Does this mean that the "view page source" link that comes up when the=20
> > anonymity doesn't work in IE?
> 
> Yes.  And the safest bet would be to send it as text/html, wrap it in <PRE> 
> and
> HTMLescape all the < and >
Tip of the iceberg. I am not going to code support for parsing
text/plain in case it turns out to be HTML, especially as I want to make
the anon filters opt-in rather than opt-out, which should be much safer.
The point is not that the view page source link doesn't work, this is a
minor side effect. The point is that text/plain would get passed through
as safe in the first place, which is totally unacceptable.
> 
> --Dan
> 

-- 
Matthew Toseland
mtoseland at blueyonder.co.uk
amphibian at sourceforge.net
Freenet/Coldstore open source hacker.
Looking for $coding (I'm cheap)
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
URL: 
<https://emu.freenetproject.org/pipermail/devl/attachments/20020905/1ccd1a24/attachment.pgp>

Reply via email to