From 64bae6924f950602dbdf1f96a0b53d4230eaaa2c Mon Sep 17 00:00:00 2001 From: Jakub Vrana Date: Sat, 3 Oct 2026 10:31:21 +0200 Subject: [PATCH] mail: documented that only images inside the base path are embedded Co-Authored-By: Claude Opus 5.5 --- mail/cs/@home.texy | 2 ++ mail/en/@home.texy | 2 ++ 2 files changed, 4 insertions(+) diff --git a/mail/cs/@home.texy b/mail/cs/@home.texy index 0f3be9c6ec..5b4389f4eb 100644 --- a/mail/cs/@home.texy +++ b/mail/cs/@home.texy @@ -68,6 +68,8 @@ $mail->setHtmlBody( Algoritmus vkládající obrázky vyhledává tyto vzory: ``, ``, `url(...)` uvnitř HTML atributu `style` a speciální syntaxi `[[...]]`. +Vkládá jen obrázky uložené v uvedeném adresáři. Odkaz na neexistující soubor, na jiný soubor než obrázek nebo na soubor mimo adresář vyhodí výjimku. Syntaxi `[[...]]` ale v takovém případě nechá beze změny, takže HTML může obsahovat i text od uživatelů a ti do e-mailu nevloží libovolný soubor ze serveru. .{data-version:4.3.0} + Může být odesílání e-mailů ještě jednodušší? .[tip] diff --git a/mail/en/@home.texy b/mail/en/@home.texy index 8f0f1668cb..e746774183 100644 --- a/mail/en/@home.texy +++ b/mail/en/@home.texy @@ -68,6 +68,8 @@ $mail->setHtmlBody( The image embedding algorithm searches for these patterns: ``, ``, `url(...)` inside the HTML `style` attribute, and the special syntax `[[...]]`. +Only images stored in the given directory are embedded. A reference to a file that is missing, is not an image or is outside of the directory throws an exception. The `[[...]]` syntax is left unchanged in such a case, so the HTML may contain text from users without letting them embed an arbitrary file from the server. .{data-version:4.3.0} + Could sending emails be even easier? .[tip]