Okular with GnuPG / Gpg4win
Albert Astals Cid
aacid at kde.org
Tue May 16 22:55:00 BST 2023
El divendres, 12 de maig de 2023, a les 12:40:23 (CEST), Andre Heinecke va
escriure:
> Hi,
>
> our integration of Okular anxd GnuPG (and later on GnuPG VS-Desktop) is
> nearly finished. Not everything is upstream yet but we see no roadblocks on
> the way that might cause us to abort so we would like to go ahead and
> announce this a bit more.
>
> Attached is a first draft of a statement about why we started to work on
> this.
The text looks reasonable to me, but i guess we'd definitely want some input
from the KDE Promo folks. Want me to involve them or will you?
> First of I want to say a big thank you to everyone who helped with reviewing
> etc. and for the excellent design of Okular which allowed a very modular
> build.
>
> But, this is a slight problem because we are targeting a high security
> environment we want to limit the attack surface as much as possible. This
> means that we have stripped down Okular quite a lot.
>
> - It will have only the poppler generator.
> - Basically no optional dependencies. (No JavaScript)
> - No Phonon for Media (patches to cleanly make that optional are incoming, I
> have hacked it for now).
>
> Additionally we carry some patches which allow us to strip down framework
> inter dependencies and brutally hack some parts like KIO to come for example
> without DBus support.
>
> As such I think it would be unfair of us to call this just "Okular" and give
> you a possibly bad name.
>
> My suggestion is the following:
> - Use the name "Okular (GnuPG Edition)" in user visible strings, like the
> start Menu, Window Title, About Dialog etc.
> - Change the bug tracker URL to dev.gnupg.org for us (should be obvious).
That seems reasonable to me.
>
> And finally to add a Message Box on the first launch and add a Text in the
> about dialog to promote the full featured Okular which I draft as
> following:
>
> ----------
> Okular in general is a lightweight and highly secure document viewer for
> many document formats.
>
> To reduce the attack surface even further the GnuPG Edition is stripped
> down to only support PDF documents without any active content.
>
> For the best User Experience you can safely install the fully featured
> Okular from the <a href="https://apps.microsoft.com/store/detail/okular/
> 9N41MSQ1WNM8">Microsoft Store</a>
> ----------
>
> If this seems agreeable to you I would open a merge request regarding
> something like this as a build switch. I would like to have the text
> included upstream instead of patching it in for translation / wording
> support etc.
I can see that how that would make sense for translation but i don't see how
this particular wording makes sense to be in the Okular repository.
Imagine we get 10 different downstreams like you, we would need 10 different
strings.
One thing that comes to mind is we could come up with some kind of "these
functionalities have been disabled" based on FORCE_NOT_REQUIRED_DEPENDENCIES
have been set. (Or maybe just a generic one if any has been set?)
Cheers,
Albert
>
> I don't think that a parallel installation of two Okulars will make much
> sense except in very specific use cases (e.g. If you use Okular (GnuPG
> Edition) to open PDF's from Mails and the regular Okular as default). But
> it is possible and no Problem.
>
>
> Best Regards,
> Andre
More information about the Okular-devel
mailing list