From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.io!.POSTED.blaine.gmane.org!not-for-mail From: =?UTF-8?Q?Sebasti=C3=A1n_?= =?UTF-8?Q?Mon=C3=ADa?= Newsgroups: gmane.emacs.bugs Subject: bug#65973: [PATCH] ; send filename, not full path, on EWW form submit Date: Tue, 05 Nov 2024 22:30:01 -0500 Message-ID: <87y11x11l2.fsf@sebasmonia.com> References: <86bjyttxql.fsf@gnu.org> <4215339a-e797-6198-2e40-8d577e1fec42@gmail.com> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Injection-Info: ciao.gmane.io; posting-host="blaine.gmane.org:116.202.254.214"; logging-data="34490"; mail-complaints-to="usenet@ciao.gmane.io" User-Agent: Gnus/5.13 (Gnus v5.13) Cc: Eli Zaretskii , ozzloy@challenge-bot.com, 65973@debbugs.gnu.org, ozzloy@gmail.com To: Jim Porter Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Wed Nov 06 04:31:22 2024 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane-mx.org Original-Received: from lists.gnu.org ([209.51.188.17]) by ciao.gmane.io with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1t8WlM-0008nD-M9 for geb-bug-gnu-emacs@m.gmane-mx.org; Wed, 06 Nov 2024 04:31:21 +0100 Original-Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1t8Wl8-0002tD-92; Tue, 05 Nov 2024 22:31:06 -0500 Original-Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1t8Wl5-0002sq-Dt for bug-gnu-emacs@gnu.org; Tue, 05 Nov 2024 22:31:04 -0500 Original-Received: from debbugs.gnu.org ([2001:470:142:5::43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1t8Wl4-0005Sp-K4 for bug-gnu-emacs@gnu.org; Tue, 05 Nov 2024 22:31:03 -0500 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debbugs.gnu.org; s=debbugs-gnu-org; h=MIME-Version:Date:References:In-Reply-To:From:To:Subject; bh=WWY70pN6njsmfnom4L0U+cfbagH81GWkOyEIoO7MiaA=; b=VON5zvnnz/cQbnluQEhYtBYdu9IXgE7EB0esU2rHF1BcRz4k9PJ3PU+/SdnvqtObtM4MU+JCjfjRAQYSv6oqTGeFINyNxk+aQFjM0sxh0j1Hfv7uG1QG3HT1IHZ0hjrSVdUbj7cBHABfS86gV1GvjaVQfA8gfdYtpj8Vo6Nhl5IdwNDP0JrgHS5m9Uh6RyeJgrRp/Q8AdrcIAf8IR4+1T7ua3D+z2W9wIpEWu98SGkrLE+ucHDqPr1HBj6UnTouMwnMcAlsvrjT/qF7htybmERDklnm7pu8B95YvK88bkcrq5JhW8nsebFNnXQ+deurB3+zPTBaeR9Wj1+dWmBx2Yw==; Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1t8Wl4-0006kU-EW for bug-gnu-emacs@gnu.org; Tue, 05 Nov 2024 22:31:02 -0500 X-Loop: help-debbugs@gnu.org Resent-From: =?UTF-8?Q?Sebasti=C3=A1n_?= =?UTF-8?Q?Mon=C3=ADa?= Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Wed, 06 Nov 2024 03:31:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 65973 X-GNU-PR-Package: emacs X-GNU-PR-Keywords: patch Original-Received: via spool by 65973-submit@debbugs.gnu.org id=B65973.173086380925717 (code B ref 65973); Wed, 06 Nov 2024 03:31:02 +0000 Original-Received: (at 65973) by debbugs.gnu.org; 6 Nov 2024 03:30:09 +0000 Original-Received: from localhost ([127.0.0.1]:38802 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t8WkD-0006gX-4F for submit@debbugs.gnu.org; Tue, 05 Nov 2024 22:30:09 -0500 Original-Received: from fhigh-a5-smtp.messagingengine.com ([103.168.172.156]:52669) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t8WkA-0006bs-W3 for 65973@debbugs.gnu.org; Tue, 05 Nov 2024 22:30:08 -0500 Original-Received: from phl-compute-08.internal (phl-compute-08.phl.internal [10.202.2.48]) by mailfhigh.phl.internal (Postfix) with ESMTP id E4CC9114015A; Tue, 5 Nov 2024 22:30:01 -0500 (EST) Original-Received: from phl-mailfrontend-02 ([10.202.2.163]) by phl-compute-08.internal (MEProxy); Tue, 05 Nov 2024 22:30:01 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sebasmonia.com; h=cc:cc:content-transfer-encoding:content-type:content-type :date:date:from:from:in-reply-to:in-reply-to:message-id :mime-version:references:reply-to:subject:subject:to:to; s=fm3; t=1730863801; x=1730950201; bh=WWY70pN6njsmfnom4L0U+cfbagH81GWk OyEIoO7MiaA=; b=LPBs1JgjqB8pDRz8L7kxj+jvM2cvNal3iINx13rRyfkpuM+0 /D/RAG6B+xr7a43AeppWboZntikzdAAvgExvMFeB42PtcNmlBEu5wPppUnGxcU2q nIuixKDyCsNj6xVERbbH2e8YWcYGkr0vHLN58UZRQaxX0IStWJJlmme+tthviRNm RsefO0AcVtHevVz4WZvI/IQIu6VC38xdaohp/GRYFBVCSm4giMtQvi7IkeZbVkRO /P3XzGTSs6Fd+XGrXbCjv/jlRnzX3BZ848cSt+f7pQsZzHs14lD3AzBIrWDjNEqP kk5oTcQm1L7d4WQZMMHvit6KaNPWLXigvXLeFw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:content-type:date:date:feedback-id:feedback-id :from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm3; t=1730863801; x= 1730950201; bh=WWY70pN6njsmfnom4L0U+cfbagH81GWkOyEIoO7MiaA=; b=B b/M6cnPqvLDY5itrByBFyIpgmKlX5jZ8CK4WreC2KkQkgSm2sWTnDzWknWBqmfBy cRVIZDx/Yf9f6HfIAPL+mQfNNTsIF6R9ZgNW5Leb9UTXdDJBmgCX5ukLnMLrBH+s jEl1keJT+nM68vS3q9mbBNDRKpRYXjAngRpQVH5FPHdfNPSUkfev3kThdQf66a70 1yoseMeRpX66uZ/WFmcEPIHQ8E2vH8+fVA2nWlXSzTz6FezUwdQU4MlMHBsUPjEP bYt5ggcdddZkA7c0rMpMwDmN3TRFt0fqiufeJc0p+CRRNq3Qlxz/vtS6mTkm7CYA SJplphfsCUY+QCWJhdBxw== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefuddrtddugdeitdcutefuodetggdotefrodftvf curfhrohhfihhlvgemucfhrghsthforghilhdpggftfghnshhusghstghrihgsvgdpuffr tefokffrpgfnqfghnecuuegrihhlohhuthemuceftddtnecusecvtfgvtghiphhivghnth hsucdlqddutddtmdenucfjughrpefhvfevufgjfhffkfgfgggtgfesthhqredttderjeen ucfhrhhomhepufgvsggrshhtihojnhcuofhonhovrgcuoehsvggsrghsthhirghnsehsvg gsrghsmhhonhhirgdrtghomheqnecuggftrfgrthhtvghrnheplefhtdfgfeegudejveek hfffjefhfeefleeuhfelueehiefhtdffhfdufeeltdefnecuffhomhgrihhnpehmohiiih hllhgrrdhorhhgpdhsvggsrghsmhhonhhirgdrtghomhenucevlhhushhtvghrufhiiigv pedtnecurfgrrhgrmhepmhgrihhlfhhrohhmpehsvggsrghsthhirghnsehsvggsrghsmh honhhirgdrtghomhdpnhgspghrtghpthhtohephedpmhhouggvpehsmhhtphhouhhtpdhr tghpthhtohepohiiiihlohihsehgmhgrihhlrdgtohhmpdhrtghpthhtohepieehleejfe esuggvsggsuhhgshdrghhnuhdrohhrghdprhgtphhtthhopehoiiiilhhohiestghhrghl lhgvnhhgvgdqsghoth X-ME-Proxy: Feedback-ID: iab2c46da:Fastmail Original-Received: by mail.messagingengine.com (Postfix) with ESMTPA; Tue, 5 Nov 2024 22:30:01 -0500 (EST) In-Reply-To: <4215339a-e797-6198-2e40-8d577e1fec42@gmail.com> (Jim Porter's message of "Tue, 5 Nov 2024 11:36:25 -0800") X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Original-Sender: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Xref: news.gmane.io gmane.emacs.bugs:294932 Archived-At: Jim Porter writes: > On 11/5/2024 9:08 AM, Eli Zaretskii wrote: >> I'd like some rationale for this change. The original report never >> explains why sending the full absolute file name to the server is bad. > > I see three possible reasons: 1) there could be (probably minor) > privacy issues with sending the directory structure along to a server; > 2) as far as I'm aware, other browsers only pass the "leaf" of the > filename; 3) RFC 2813 says that *recipients* should ignore any > directories: [...] > RFC 2813 is primarily about mail clients, but MDN suggests following > it in a web context as well: > . > So I think the RFC would suggest that it's *allowed* to send the > directories in the "filename" field, but since the server is supposed > to ignore it, there's no benefit to doing so. I didn't get as far as Jim did. I assumed the concern was #1, and I knew the rest of the path is ignored, so figured we should go ahead. Regards, Seb --=20 Sebasti=C3=A1n Mon=C3=ADa https://site.sebasmonia.com/