[MPlayer-dev-eng] [PATCH] Make stream support http redirect

Ulion ulion2002 at gmail.com
Sun Nov 18 13:02:44 CET 2007


2007/11/18, Reimar Döffinger <Reimar.Doeffinger at stud.uni-karlsruhe.de>:
> Hello,
> On Sun, Nov 18, 2007 at 09:37:39AM +0800, Ulion wrote:
> [...]
> > Thank you, I missed one 'goto out', did not set the return value
> > correctly. Here's the fixed patch, also deny redirect from http:// to
> > file:// as a little security feature.
>
> That is sometimes called "enumerating badness" and a true security
> anti-pattern. If anything check for mms and explicitly allow redirect to
> that and only that.

OK, here's the http->mms only patch, if need add any other protocol,
just add it.

-- 
Ulion
-------------- next part --------------
A non-text attachment was scrubbed...
Name: stream_http_redirect3.diff
Type: text/x-diff
Size: 3792 bytes
Desc: not available
URL: <http://lists.mplayerhq.hu/pipermail/mplayer-dev-eng/attachments/20071118/76545087/attachment.diff>


More information about the MPlayer-dev-eng mailing list