Danko Komlen - 2006-08-03

Logged In: YES
user_id=1524933

I understand your consern about dialog requesting web
browser command. But the problem is that i had no choice to
open a web browser other then atempt to run all browser
commands. I implemented only gnome-open command and if it
fails it will ask user to enter his command. Either that or
no report preview at all.

But i don't see any potential security hazard here.

You said:
"Any person with physical access to the terminal on which
TimeSaver is running may be able to do harm to the system ."

Yes, but not because TimeSaver has security problem, I
think it's because the person has physical access to the
terminal :)

The second potential risk you mentioned is: "loading .xml
files for reports on a given session". I really don't see
no risk here. All program does is reading text from xml
file and creates session and task objects.
Btw, report view doesn't load anything. It just saves
session to xml file and runs web browser with that file as
an argument.

But OK i will implement more web browser commands, that is
not such a problem.

Thank you for report