[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re (5): Capability of Iceweasel to open a local file.



From:	Liam O'Toole <liam.p.otoole@gmail.com>
Date:	Tue, 07 Jun 2011 09:09:58 +0000 (UTC)
> ... lynx opens the file ...

Thanks.  I didn't try lynx. 

> ... issue of iceweasel opening file:// links from http:// documents.

Suppose you have the valid file Category2.html in your home directory.
Using File > Open File, Iceweasel interprets Category2.html and 
displays "file:///home/<user>/Category2.html" in the URI bar.  By 
default, a user is allowed to open his/her own files.  

If you type this into the URI bar,
  "file:///home/<user>/Category2.html"<Enter>
Iceweasel opens the file as in the previous case.

Suppose "file:///home/<user>/Category2.html" exists in any selectable 
text.  Select that file URI, copy to the clipboard and paste into the 
Iceweasel URI bar.  Then hit <Enter>.  Again Iceweasel opens the file.

Now suppose that you see a link anchor "Click here" in a page 
displayed by Iceweasel and the target of the link is 
"file:///home/<user>/Category2.html".  If the mouse pointer is on 
the anchor, Iceweasel displays that file URI at the bottom of the 
window but a click produces nothing.

> That is disabled by default for security reasons, ...

The only important difference from the preceeding cases is that the 
user might not focus attention on the target.  Iceweasel is protecting 
a user from careless clicking.  Similar to not allowing a click or 
double click on the icon of a program in a GUI to cause the program 
to begin execution.  But GUIs became popular for such capabilities!

> ... can be enabled by toggling the value of the "security.checkloaduri"
> configuration preference. Go to the special URL "about:config" to change
> it if you wish.

Thanks.  A non-obvious setting if ever there was one.  How might John 
Doe OrdinaryUser discover the existence and effect of this parameter?  

Here "Value" can be unchecked but it doesn't stick.  The file URI still 
won't open and if about:config is opened again, security.checkloaduri is 
back to the original state with Status, Type and Value all checked.  
Something is different in your system.

Yikes!  The default setting is obviously well estabished with zero or 
less chance of being changed.  Thanks for explaining.

Regards,                ... Peter E.




-- 
Telephone 1 360 450 2132.  bcc: peasthope at shaw.ca
Shop pages http://carnot.yi.org/ accessible as long as the old drives survive.
Personal pages http://members.shaw.ca/peasthope/ .


Reply to: