[4suite-dev] Proposal for XSLT extension for sending email

Uche Ogbuji uche at ogbuji.net
Thu Oct 4 10:50:14 MDT 2007


"John L. Clark" wrote:
> Hey Uche,
>
> Thanks for your response.  Yeah, I kind've wondered whether or not
> this might be core enough to justify adding it.  I guess I got hasty.
> Sorry about that.  I'll be happy to back out the change.  Out of
> curiousity, though, why do you see it as a security risk?
>   

Yeah, that's a bit overstated on my part.  My point is that anything
that manipulates a network server in the way our sending e-mail
manipulates smtpd deserves extra security review.  I'm a little gun shy
after having to remove the os.system extensions, which were much more
obvious security risks, but still...

> Also, where do your ftgoodies currently live?
>   

Well, I started to put together a spot in CVS a while back:

http://cvs.4suite.org/viewcvs/ftgoodies/ftgoodies/

But I never did get around to copying the extensions from Akara:

http://cvs.4suite.org/viewcvs/Akara/ftext/


-- 
Uche Ogbuji                       http://uche.ogbuji.net
Founding Partner, Zepheira        http://zepheira.com
Linked-in profile: http://www.linkedin.com/in/ucheogbuji
Articles: http://uche.ogbuji.net/tech/publications/



More information about the 4suite-dev mailing list