1.7 checkout dialog open to clipboard injection
From: Stein Somers <ssomers_at_opnet.com>
Date: Fri, 12 Aug 2011 04:39:08 -0700 (PDT)
When opening the checkout dialog on a non-empty folder (to check out into a new subfolder), I was surprised to see gibberish entered into the url and directory fields. After some experiments, I think that if your clipboard contains text starting with a word of at least two letters directly followed by a colon, e.g. "am:pm" (without quotes), the complete clipboard is pasted as value of both the url and directory fields. Maybe this is intended to make it easier to check out a URL in your clipboard, but then I don't understand why the complete URL is proposed as directory - the dialog itself says that colon is not a valid part of a filename (on Windows). If it is intended, it should be a little more strict on what it considers to be a URL. I don't know where the border is, but if the clipboard happens to contain megabytes of lines of text that start with "Error: ", it's not meant as a URL...
------------------------------------------------------
To unsubscribe from this discussion, e-mail: [users-unsubscribe_at_tortoisesvn.tigris.org].
|
This is an archived mail posted to the TortoiseSVN Users mailing list.
This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.