Re: [dev] security issue running surf from home folder

From: Christoph Lohmann <20h_AT_r-36.net>
Date: Wed, 07 Jan 2015 21:29:39 +0100

Greetings.

On Wed, 07 Jan 2015 21:29:39 +0100 Ben Woolley <tautolog_AT_gmail.com> wrote:
> The config.def.h file has a define for DOWNLOAD that just opens up curl,
> and surf.c calls DOWNLOAD without any prompting.

Theses patches have been discussed on IRC. The optimal solution has been
to make the default DOWNLOAD macro to ask for a string. If the string is
empty, pass ‐O to curl, if it’s non‐empty add ‐‐create‐dirs and ‐o
$string to curl.

Any comments on this?


Sincerely,

Christoph Lohmann
Received on Wed Jan 07 2015 - 21:29:39 CET

This archive was generated by hypermail 2.3.0 : Wed Jan 07 2015 - 21:36:07 CET