Re: [notmuch] New wiki instance on the notmuchmail.org website

Subject: Re: [notmuch] New wiki instance on the notmuchmail.org website

Date: Wed, 03 Feb 2010 18:14:27 +0100

To: Carl Worth, notmuch@notmuchmail.org

Cc:

From: Marten Veldthuis


On Wed, 03 Feb 2010 08:47:41 -0800, Carl Worth <cworth@cworth.org> wrote:
> See this page for details (particularly the "security" and
> "infelicities" sections):
> 
> 	http://ikiwiki.info/tips/untrusted_git_push/

Ah. Probably this section:

  So, unless you have the attachment plugin turned on, non-page files
  cannot be added. And if it's turned on, whatever allowed_attachments
  checks you have configured will also check files pushed into git.

since I was trying to add some screenshots of the Emacs interface. It
makes perfect sense not to enable this plugin though, given the security
implications (people could potentially upload mp3's as png's etc).

Let me know if I should send you the commit off-list or if you don't
mind enabling the attachment plugin for eg common image filetypes.

-- 
- Marten

Thread: