RE: MIME disable option? (hopefully not FAQ)

From: Paul Haldane <Paul.Haldane_at_newcastle.ac.uk_at_hypermail-project.org>
Date: Tue, 20 Apr 1999 15:43:35 +0100 (GMT)
Message-ID: <Pine.GSO.3.95-960729.990420153631.311E-100000_at_carr6.ncl.ac.uk>


On Tue, 20 Apr 1999, Tom von Alten wrote:

...
> I thought of a simpler approach. What if we just prefix user names with
> something innocuous? Add on "x-" or some such, so
> .htaccess -> xhm-.htaccess
> for example.

That sounds attractive to me. I was just looking back at some work I did on Hypermail 1 to deal with attachments and found that I was always storing them as att-<msgno>-<attachmentno>

But this was probably laziness rather than concern over security.

Tom's suggestion of a prefix seems sensible as we do want to preserve any given extension. An alternative would be defining a set of acceptable types of file name - not starting with a '.', only alphanumerics and 'safe' other characters in the name - and map any other given file names into that set.

Paul

-- 
Paul Haldane
Received on Tue 20 Apr 1999 05:20:14 PM GMT

This archive was generated by hypermail 2.2.0 : Thu 22 Feb 2007 07:33:50 PM GMT GMT