[Tickets #10477] Re: default setting for inline images: give link to show them
bugs at horde.org
bugs at horde.org
Thu Sep 1 23:17:04 UTC 2011
DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.
Ticket URL: http://bugs.horde.org/ticket/10477
------------------------------------------------------------------------------
Ticket | 10477
Updated By | Michael Slusarz <slusarz at horde.org>
Summary | default setting for inline images: give link to show
| them
Queue | IMP
Version | 4.3.9
Type | Enhancement
State | Rejected
Priority | 2. Medium
Milestone |
Patch |
Owners |
------------------------------------------------------------------------------
Michael Slusarz <slusarz at horde.org> (2011-09-01 23:17) wrote:
> Cpanel support suggested that the default setting is to diplay the
> message "There are no parts that can be displayed inline." However,
> we were able to change the config so that it displays "Images have
> been blocked to protect your privacy. Show Images?"
>
> I recommend that the "show images" link be offered as the default
> setting, not the" no parts that can be displayed inline" message.
> Please see the attached images for comparison.
>
> So if you are not blocking inline images, I presume the "show
> images' link should already be default, is that correct?
This has nothing to do with blocking images. This has to do with
displaying HTML parts inline. The default is to NOT allow this (html
inline display is false). Displaying HTML messages by default is a
gigantic security hole that an admin has to make a choice to allow
locally. (The HTML filter shipped with H4 is much better than the H3
filter, but there are still no guarantees).
More information about the bugs
mailing list