[plasmashell] [Bug 419310] Kickoff (also maybe for alternative menus too): Security concerns

2020-03-29 Thread Nate Graham
https://bugs.kde.org/show_bug.cgi?id=419310 Nate Graham changed: What|Removed |Added Version Fixed In||5.18.4 -- You are receiving this mail because:

[plasmashell] [Bug 419310] Kickoff (also maybe for alternative menus too): Security concerns

2020-03-29 Thread Gabriel Fernandes
https://bugs.kde.org/show_bug.cgi?id=419310 --- Comment #12 from Gabriel Fernandes --- >But that requires explicit user activity to get it in locations first, right? Yes, the user has to enter the location. Much less likely to happen. I just wanted to point out, even though it says open, in

[plasmashell] [Bug 419310] Kickoff (also maybe for alternative menus too): Security concerns

2020-03-29 Thread David Edmundson
https://bugs.kde.org/show_bug.cgi?id=419310 David Edmundson changed: What|Removed |Added Resolution|--- |FIXED Latest Commit|

[plasmashell] [Bug 419310] Kickoff (also maybe for alternative menus too): Security concerns

2020-03-29 Thread David Edmundson
https://bugs.kde.org/show_bug.cgi?id=419310 --- Comment #10 from David Edmundson --- >But the "Locations" runner does execute the .desktop file But that requires explicit user activity to get it in locations first, right? -- You are receiving this mail because: You are watching all bug

[plasmashell] [Bug 419310] Kickoff (also maybe for alternative menus too): Security concerns

2020-03-28 Thread Nate Graham
https://bugs.kde.org/show_bug.cgi?id=419310 Nate Graham changed: What|Removed |Added CC||n...@kde.org -- You are receiving this mail

[plasmashell] [Bug 419310] Kickoff (also maybe for alternative menus too): Security concerns

2020-03-27 Thread Gabriel Fernandes
https://bugs.kde.org/show_bug.cgi?id=419310 --- Comment #9 from Gabriel Fernandes --- That's really good. I'm afraid it's possible to suffer from the same effect through other runners. It doesn't seem to be possible to execute a file from the "Desktop search" runner as it filters to show only

[plasmashell] [Bug 419310] Kickoff (also maybe for alternative menus too): Security concerns

2020-03-27 Thread David Edmundson
https://bugs.kde.org/show_bug.cgi?id=419310 David Edmundson changed: What|Removed |Added Status|REOPENED|ASSIGNED -- You are receiving this mail

[plasmashell] [Bug 419310] Kickoff (also maybe for alternative menus too): Security concerns

2020-03-27 Thread David Edmundson
https://bugs.kde.org/show_bug.cgi?id=419310 David Edmundson changed: What|Removed |Added Ever confirmed|0 |1 Status|RESOLVED

[plasmashell] [Bug 419310] Kickoff (also maybe for alternative menus too): Security concerns

2020-03-27 Thread Gabriel Fernandes
https://bugs.kde.org/show_bug.cgi?id=419310 --- Comment #7 from Gabriel Fernandes --- In dolphin we have 3 options. 1. You have a popup that asks you what you want to do (open or execute) 2. Set open as default, so always when you click an executable the file is opened with a default application

[plasmashell] [Bug 419310] Kickoff (also maybe for alternative menus too): Security concerns

2020-03-27 Thread David Edmundson
https://bugs.kde.org/show_bug.cgi?id=419310 --- Comment #6 from David Edmundson --- Fix itself is pretty straightforward: https://phabricator.kde.org/P566 Generally there's not too much we can do against the .desktop situation (without also breaking things), but in this case it maybe makes

[plasmashell] [Bug 419310] Kickoff (also maybe for alternative menus too): Security concerns

2020-03-27 Thread David Edmundson
https://bugs.kde.org/show_bug.cgi?id=419310 --- Comment #5 from David Edmundson --- >open the file to have it as a recent file when you search using kickoff or >krunner, But then it's been already run? Unless the user does "open with" the first time. I don't yet understand why it's different

[plasmashell] [Bug 419310] Kickoff (also maybe for alternative menus too): Security concerns

2020-03-27 Thread David Edmundson
https://bugs.kde.org/show_bug.cgi?id=419310 --- Comment #4 from David Edmundson --- *** Bug 419308 has been marked as a duplicate of this bug. *** -- You are receiving this mail because: You are watching all bug changes.

[plasmashell] [Bug 419310] Kickoff (also maybe for alternative menus too): Security concerns

2020-03-27 Thread Gabriel Fernandes
https://bugs.kde.org/show_bug.cgi?id=419310 --- Comment #3 from Gabriel Fernandes --- Oh sorry. I just didn't want to duplicate myself, in this case triplicate (also another report for krunner product). It doesn't work if the file have a common extension, as png, if you name it "file.png." for

[plasmashell] [Bug 419310] Kickoff (also maybe for alternative menus too): Security concerns

2020-03-27 Thread David Edmundson
https://bugs.kde.org/show_bug.cgi?id=419310 --- Comment #2 from David Edmundson --- Edit: my reply was maybe a little curt. I see now you are probably the original reporter, which helps. In any case. Please do paste copy and paste inline. Partly for prosperity, and partly because I don't want

[plasmashell] [Bug 419310] Kickoff (also maybe for alternative menus too): Security concerns

2020-03-27 Thread David Edmundson
https://bugs.kde.org/show_bug.cgi?id=419310 David Edmundson changed: What|Removed |Added Status|REPORTED|RESOLVED Resolution|---