Files
sogo/UI/MailPartViewers/UIxMailPartViewer.h
T
Jan Kahmen 045a0b9c0a fix(mail): escape mail data placed in attributes of a compiled part
the generic attribute writer used for these two spots does not escape what it
writes, so a value taken from the message ends the attribute and starts a new
one. both are inside a part that is compiled, which is where an injected
handler runs.

* the organizer link took inEvent.organizer.email verbatim. a value such as
  mailto:x@y" onpointerover="... produced a live handler on the anchor, and an
  entity encoded scheme such as javascript: reached the href, where the
  browser decodes it. the href is now built as mailto: plus the parsed address
  and escaped as an attribute value.

* the attachment name paragraph of the image and the link viewer took
  filenameForDisplay verbatim. a quote inside an RFC 2231 encoded filename
  ended the title attribute. the writer escapes & < > there but not the quote,
  so the accessor drops the quote instead of escaping it, which keeps a plain
  filename such as A&B.pdf unchanged in the tooltip.

the img title of the image viewer is left alone: attributes of that element are
escaped by the framework already.
2026-08-17 23:48:41 +02:00

104 lines
2.6 KiB
Objective-C

/*
Copyright (C) 2015-2017 Inverse inc.
Copyright (C) 2004-2005 SKYRIX Software AG
This file is part of SOGo.
SOGo is free software; you can redistribute it and/or modify it under
the terms of the GNU Lesser General Public License as published by the
Free Software Foundation; either version 2, or (at your option) any
later version.
SOGo is distributed in the hope that it will be useful, but WITHOUT ANY
WARRANTY; without even the implied warranty of MERCHANTABILITY or
FITNESS FOR A PARTICULAR PURPOSE. See the GNU Lesser General Public
License for more details.
You should have received a copy of the GNU Lesser General Public
License along with SOGo; see the file COPYING. If not, write to the
Free Software Foundation, 59 Temple Place - Suite 330, Boston, MA
02111-1307, USA.
*/
#ifndef __Mailer_UIxMailPartViewer_H__
#define __Mailer_UIxMailPartViewer_H__
#include <SOGoUI/UIxComponent.h>
/*
UIxMailPartViewer
This class is the superclass for MIME content viewers.
Since part-viewers can be reused for multiple parts, you need to be careful
in subclass to properly reset your specific state by overriding
- resetPathCaches
The part viewers have access to the rendering state using the
[[self context] mailRenderingContext]
object. This class provides several convenience methods to access mailpart
content.
*/
@class NSArray;
@class NSData;
@class NSFormatter;
@class NSMutableDictionary;
@class NSNumber;
@class SOGoMailBodyPart;
@interface UIxMailPartViewer : UIxComponent
{
NSArray *partPath;
id bodyInfo;
NSData *flatContent;
id decodedContent;
NSDictionary *attachmentIds;
BOOL _shouldDisplayAttachment;
}
/* accessors */
- (void)setPartPath:(NSArray *)_path;
- (NSArray *)partPath;
- (void)setBodyInfo:(id)_info;
- (id)bodyInfo;
- (SOGoMailBodyPart *) clientPart;
- (id) renderedPart;
- (NSDictionary *) attachmentIds;
- (void) setAttachmentIds: (NSDictionary *) newAttachmentIds;
- (void) setAttachmentIds:(NSDictionary *)newAttachmentIds displayAttachment:(BOOL)shouldDisplayAttachment;
- (NSData *)flatContent;
- (void) setFlatContent: (NSData *) theData;
- (id) decodedFlatContent;
- (void) setDecodedContent: (id) theData;
- (NSString *)flatContentAsString;
- (NSString *)preferredPathExtension;
- (NSString *)filename;
- (NSString *)filenameForDisplay;
- (NSString *)filenameForTitle;
- (NSFormatter *)sizeFormatter;
/* caches */
- (void)resetPathCaches;
- (void)resetBodyInfoCaches;
/* part URLs */
- (NSString *)pathToAttachment; /* download link */
@end
#endif /* __Mailer_UIxMailPartViewer_H__ */