scripting proposal draft 3

Henry de Valence hdevalence at gmail.com
Wed Apr 9 03:32:41 UTC 2008


On Tuesday 08 April 2008 19:37:00 K Robinson wrote:
> Has anyone done some security or threat analysis on the script interface,
> or is this planned?  I didn't spot anything in the proposal.  While I want
> scripts to be able to do a lot, I also want users to be able to (at a
> minimum) quickly audit what a script is doing or has done in the past.
>  This also ties in with quality assurance problems.  If a script is causing
> instability in Amarok or elsewhere, it would be nice for users who know
> little to be able to figure out it's a script, not amarok itself.
>
> -K Robinson
I think that's a really good idea. I also think it would be good to have a 
thing that could teach non-technical users a really basic overview about why 
scripts can be dangerous, so only get them from a trusted source, like GHNS. I 
guess that's more of a documentation thing. You'd have to make it short and 
sweet and to the point though, or else people are more likely to ignore it.

Henry de Valence





More information about the Amarok mailing list