1
0
mirror of https://github.com/rkd77/elinks.git synced 2024-09-30 03:26:23 -04:00
elinks/src
Miciah Dashiel Butler Masters 5c96d430c9 Bug 765: Bypass checks on base tab's view state when copying to a new tab
In setup_session, use copy_location, add_to_history, and
render_document_frames instead of goto_uri and copy_vs to copy the base
tab's view state.  By avoiding goto_uri, setup_session now bypasses MIME
checks, form post confirmations, malicious URL checks, and so on when
copying the base tab's current location and view state to the new tab,
so the new tab should get exactly what was loaded in the base tab.

This fixes bug 765: Opening a new tab can ask about the document of the
previous tab.
2008-06-11 10:32:02 +00:00
..
bfu Strings corrections from Malcolm Parsons 2008-01-27 04:19:23 +00:00
bookmarks get_opt_*: Add ses parameter 2007-08-28 17:24:59 +00:00
cache bug 1009: id variables renamed, added document_id to the document. 2008-04-27 23:22:08 +03:00
config Merge branch 'elinks-0.12' into elinks-0.13 2008-04-28 22:08:19 +03:00
cookies Strings corrections from Malcolm Parsons 2008-01-27 04:19:23 +00:00
dialogs 1008: rename connection.upload_progress to .http_upload_progress 2008-06-03 09:57:58 +03:00
document Bug 620: Reset form fields to default values on reload 2008-06-10 06:41:34 +00:00
dom Merge branch 'elinks-0.12' 2007-09-09 18:25:49 +02:00
ecmascript bug 1009: id variables renamed, added document_id to the document. 2008-04-27 23:22:08 +03:00
encoding Bug 517: read_encoded() == 0 might not mean EOF if non-blocking. 2008-06-07 23:33:23 +03:00
formhist Declare element types of lists. 2007-07-26 22:47:23 +03:00
globhist get_opt_*: Add ses parameter 2007-08-28 17:24:59 +00:00
intl Merge branch 'elinks-0.12' into elinks-0.13 2008-02-03 22:30:46 +02:00
main Bug 824: Disable combining characters unless --enable-combining. 2008-01-19 20:58:22 +02:00
mime bug 638: More comments. Assert that calls don't nest. 2008-03-22 14:06:47 +02:00
network 1008: always erase timer ID in upload_stat_timer() 2008-06-03 10:02:06 +03:00
osdep Debian bug 464384: fix OFF_T_FORMAT mismatches on amd64 2008-02-10 11:30:27 +02:00
protocol 1008: remove unused uri.big_files 2008-06-10 01:05:39 +03:00
scripting Bug 1014: Fix incompatible pointer type in init_perl. 2008-06-08 20:40:17 +03:00
session Bug 765: Bypass checks on base tab's view state when copying to a new tab 2008-06-11 10:32:02 +00:00
terminal Merge branch 'elinks-0.12' into elinks-0.13 2008-06-08 20:47:36 +03:00
util 1008: Centralize random numbers. 2008-05-25 18:44:21 +03:00
viewer 1008: assert there's no FILE_CHAR in file names 2008-06-04 01:15:07 +03:00
.gitignore Ignore tags file 2007-08-08 14:25:38 +02:00
elinks.h Remove now useless $Id: lines. 2005-10-21 09:14:07 +02:00
Makefile BUILD_ID: Fix dirt check when srcdir != builddir. 2008-03-01 14:30:57 +02:00
README Remove now useless $Id: lines. 2005-10-21 09:14:07 +02:00
setup.h Make copyright info independent from translations. 2007-10-03 11:53:09 +02:00
vernum.c Remove now useless $Id: lines. 2005-10-21 09:14:07 +02:00
vernum.h Remove now useless $Id: lines. 2005-10-21 09:14:07 +02:00

				  The Big View

The whole dependency tree is supposed (in ideal world) to look somewhat like
the following. Please note that this deals only with the core parts of ELinks,
not extensions like bookmarks, cookies, globhist, mime etc. Those act like
modules and are generally self-contained - the main visible difference is that
they don't have their UI stuff in dialogs/foo.c but in foo/dialogs.c.

Note also that it isn't all that clean-cut as it looks. Some parts of e.g.
lowlevel/ or osdep/ are omnipresent as well and it's meant to be so (at least
for now). Also some other exceptions are possible; the exception to this is
util/, where no exceptions are permitted - it must have no dependencies to the
rest of the code whatsoever, not even compile-time ones. The other way around,
the gettext part of intl/ is generally omnipresent but the charset part is
pretty isolated - it could be probably drawn as connected to document and
terminal (actually, it is used when encoding forms in viewer too, but that
stuff should be probably moved to document).

viewer/ contains code concerning that big rectangle between bars at the top
and bars at the bottom, documents usually being shown inside. Logically, it
is in fact kind of a BFU widget, but in practice it has little in common with
the bfu/ widgets, it is special in many ways and deeply woven to the fabric
of session/ (e.g. session history is basically a chain of viewer widget
descriptors).

dialogs/ is special too. It in fact means to say "global and unique BFU
instances belonging to the ELinks core"/ but that's a rather long and boring
name, besides the nightmares associated with maintaining files and directories
containing spaces in GIT. The "global and unique BFU instances" part can be
represented by exmode, menus and leds (were they there). The "ELinks core"
part can be represented by options, document and downloads. The reason those
aren't in their respective directories (while bookmarks or formhist have their
dialogs.c) is that it's important to keep the dependencies sorted out
reasonably. Had there been e.g. terminal/dialogs.c, it would mean libterminal
has to depend on libbfu.a and so. (There are two 'managerial' exceptions
to this; don't dig into them, please. ;-)

scripting/ (== browser scripting) is also expected to hook all around, perhaps
it should be better in the omnipresent box.

The edges are directed and represent the "using" relation. Therefore,
"bfu -> terminal" means "bfu/ is using terminal/ services (but not
the other way around)".

.---------.
| util/   | <-- This is omnipresent :)
| config/ |
| intl/   |
`---------'

                   .-------.         .---------.
                   |  bfu  |<------- | dialogs |
                   `-------' \       `---------'
                       v      `---.       |
                 .----------.      \ .--------.
                 | terminal | <----- | viewer | <-----------------.
               / `----------'     .> `--------'                   |
           .--'        v         /        v                       v
.-------. /      .----------.   |    .----------.       .----/ecmascript/----.
| osdep |<------ | lowlevel |   |    | document | ----> | document scripting |
`-------' \      `----------'   |    `----------'       `--------------------'
           `---.       ^         \        ^
                \ .---------.     `> .---------.        .----/scripting/----.
                  | network | <----- | session | -----> | browser scripting |
                  `---------'      / `---------'        `-------------------'
                       ^       .--'
                 .----------. <
                 | protocol |
                 `----------'