Skip to content

Hardening: load images only on click #2

@kewde

Description

@kewde

Currently images are loaded by default, if the user has not protected himself enough this would lead to the exposure of the ip address.

I propose a fix that will show a warning image by default that explains the risk.
On clicking the image you are shown a verify box, to make sure you really want to see the image.
When accepted, the external image is loaded.

Ideally this is included along with the patch for proxy support, so opening images in the client does not leak the real ip address of the receiver(s).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions