draft registration of application/vnd.kde.kpartgui+xml

Ryan Cumming ryan at completely.kicks-ass.org
Wed Jul 3 23:39:53 BST 2002


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On July 3, 2002 15:19, Marc Mutz wrote:
>
> Security considerations:
>
>         KPartGui files can include personal toolbar layouts and
>         keybinding definition.  To the extend that such metadata can
s/definition/definitions/
s/extend/extent/
>         be considered private, sending a KPartGui file could lead to
>         leakage of this type of information.  A well-placed KPartGui
>         file can be used to change the layout of toolbars and the
>         binding of shortcut keys to application actions. This could
>         potentially be used to trick the user in executing an action
>         that she did not intend to execute.
>
> 	Other than the above, it is believed that usage of this
>         mimetype does not introduce security concerns other that those
s/that/than/
>         already inherent in XML documents.

- -Ryan
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)

iD8DBQE9I309LGMzRzbJfbQRAvW+AJ44f+TE7K8K2QYCu+PM6KoS/jc3SACfa64H
WFo0OZ4MyAeQu9kRJ07l0o0=
=KDRp
-----END PGP SIGNATURE-----




More information about the kde-core-devel mailing list