[Asterisk-Users] * INSTRUCTIONS FOR THE ASTERISK COMMUNITY - PLEASE READ NOW *

Walt Reed asterisk at linuxguy.com
Thu Jul 22 06:36:25 MST 2004


On Thu, Jul 22, 2004 at 02:09:51PM +0100, steve at nexusuk.org said:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> On Thu, 22 Jul 2004, Walt Reed wrote:
> 
> > Agree 1000%. Any attachments other than PGP / SMIME signatures should be
> > rejected or stripped. If people want to post stuff, use a web or FTP
> > site and post a pointer.
> 
> Sounds good to me, except - what about ascii attachments of logs, etc.  
> When searching the archives for references to a problem it's often useful 
> to see the relevent logs which may since have been removed from someone's 
> own website.

Good point. Maybe check the mime types and have a select few that are
allowed. I'm a little leary on this though - if someone attaches a large
log instead of a snippit, it gets multiplied 50,000 times. Maybe a size
check on attachments. That also allows for reasonable patches and such,
but the bug DB is a better place for that stuff anyway.



More information about the asterisk-users mailing list