Re: File/command access confirmation API in GraphicsMagick

Bob Friesenhahn <[email protected]> Wed, 6 May 2009 10:13:38 -0500 (CDT)
Newsgroups gmane.comp.video.graphicsmagick.core
Message-ID <[email protected]>
On Wed, 6 May 2009, Nguyen Vu Hung wrote:
>>
>> Any and all comments are appreciated before the interface is totally
>> set in stone.
> A simple question popped up in my mind:
> Why do you limit your URIs in file:///, ftp://, http://,
> How about more and more widely used protocol
> such as scp:// and rsync://?

Probably because we don't currently support scp and rsync. :-)

As it turns out, even the file:// URL retrieval seems to be broken at 
the moment.  Perhaps this is due to a change in libxml2, or perhaps it 
was always broken.

It is very easy to add additional enumerations as protocols are added. 
Adding enumerations is easy, taking them away is hard.

The file://, ftp://, and http://, URLs are particularly of interest in 
a security concious application since they could be used by a remote 
user to access files (e.g. inside your firewall) that they would not 
otherwise have access to.  This primarily applies to the SVG and MVG 
formats, which can have embedded URLs.

Bob
--
Bob Friesenhahn
[email protected], http://www.simplesystems.org/users/bfriesen/
GraphicsMagick Maintainer,    http://www.GraphicsMagick.org/

------------------------------------------------------------------------------
The NEW KODAK i700 Series Scanners deliver under ANY circumstances! Your
production scanning environment may not be a perfect world - but thanks to
Kodak, there's a perfect scanner to get the job done! With the NEW KODAK i700
Series Scanner you'll get full speed at 300 dpi even with all image 
processing features enabled. http://p.sf.net/sfu/kodak-com