Re: Handling of HTML email

2016-12-08 Thread isdtor
Derek Martin writes: [...] > In any event, I think both parts of what you're suggesting would be > good improvements: > > 1. Put temporary content in its own directory inside $TMPDIR or >equivalent (avoids symlink attacks and such completely) > 2. Extract all of the mime parts of HTML mail in

Re: Handling of HTML email

2016-12-07 Thread Derek Martin
On Wed, Dec 07, 2016 at 01:55:16PM +, isdtor wrote: > Could mutt, upon invoking view-mailcap, save all attachments to a temp > directory and rewrite the html part so that the img src paths are > correct? TBH, for maximum security it should really do this anyway, for ALL temporary files. Creat

Re: Handling of HTML email

2016-12-07 Thread Christian Ebert
* isdtor on Wednesday, December 07, 2016 at 13:55:16 + > Many of us loathe html email, but obviously we have no control over > what we receive and deal with it the best we can. In my experience, > the text browsers are doing a pretty bad rendering job on average, so > an alternative is to use m