Bug 424456

Summary: Tag filtering / Heuristic: Prevent GHNS packages to offer arbitrary files (like an mp4 for symbol packages)
Product: [Frameworks and Libraries] frameworks-knewstuff Reporter: postix <postix>
Component: generalAssignee: Jeremy Whiting <jpwhiting>
Status: REPORTED ---    
Severity: normal CC: admin, kdelibs-bugs-null, postix
Priority: NOR    
Version First Reported In: 5.72.0   
Target Milestone: ---   
Platform: Other   
OS: Other   
See Also: https://bugs.kde.org/show_bug.cgi?id=415483
Latest Commit: Version Fixed/Implemented In:
Sentry Crash Report:
Attachments: Screenshot.

Description postix 2020-07-20 10:40:18 UTC
Created attachment 130275 [details]
Screenshot.

SystemSettings -> Symbols -> Get New Symbols and search for "OS Catalina" By "zayronXIO". If you click on "install" you are also offered to download a screen recording. I am not sure if this is in the sense of the GHNS feature?
Comment 1 Dan Leinir Turthra Jensen 2020-07-20 10:47:45 UTC
You're correct it's not, but it's more a problem that KNewStuff doesn't really have much in the way of a concept of content types. We could arguably begin filtering out download entries from the list which aren't supported, but we would need a heuristic that makes sense for literally any type of content you can conceive of. The tag filtering may well work for this purpose, but in the meantime, please report this to the author of that entry (who I guess hasn't quite understood what the uploaded data gets used for).
Comment 2 postix 2020-07-20 11:52:18 UTC
(In reply to Dan Leinir Turthra Jensen from comment #1)

> but we would need a heuristic that makes sense for literally any type of
> content you can conceive of. The tag filtering may well work for this
> purpose

This sounds reasonable.


> but in the meantime, please report this to the author of that entry
> (who I guess hasn't quite understood what the uploaded data gets used for).

I will do so that later.