summaryrefslogtreecommitdiff
path: root/vendor/github.com/toqueteos/webbrowser/webbrowser.go
diff options
context:
space:
mode:
authorLibravatar kim <grufwub@gmail.com>2025-11-03 13:55:04 +0100
committerLibravatar tobi <tobi.smethurst@protonmail.com>2025-11-17 14:12:09 +0100
commit81e3cdda44a2aed1ad0805fa738429c891b6209d (patch)
treed9c3c95eb721e1dc1c613ee7370eaad9ec8796f7 /vendor/github.com/toqueteos/webbrowser/webbrowser.go
parent[chore] add a 'nos3' build tag to support compiling without S3 storage suppor... (diff)
downloadgotosocial-81e3cdda44a2aed1ad0805fa738429c891b6209d.tar.xz
[chore] update dependencies (#4539)
- github.com/KimMachineGun/automemlimit: v0.7.4 -> v0.7.5 - github.com/tdewolff/minify/v2: v2.24.4 -> v2.24.5 - modernc.org/sqlite: v1.39.1 -> v1.40.0 w/ concurrency workaround - github.com/go-swagger/go-swagger: v0.32.3 -> v0.33.1 (and drops use of our custom fork now the fix is available upstream) Reviewed-on: https://codeberg.org/superseriousbusiness/gotosocial/pulls/4539 Co-authored-by: kim <grufwub@gmail.com> Co-committed-by: kim <grufwub@gmail.com>
Diffstat (limited to 'vendor/github.com/toqueteos/webbrowser/webbrowser.go')
-rw-r--r--vendor/github.com/toqueteos/webbrowser/webbrowser.go8
1 files changed, 5 insertions, 3 deletions
diff --git a/vendor/github.com/toqueteos/webbrowser/webbrowser.go b/vendor/github.com/toqueteos/webbrowser/webbrowser.go
index f4f19b6b3..5a0a4aa7a 100644
--- a/vendor/github.com/toqueteos/webbrowser/webbrowser.go
+++ b/vendor/github.com/toqueteos/webbrowser/webbrowser.go
@@ -30,9 +30,11 @@ type Browser interface {
}
// Open tries to open a URL in your default browser ensuring you have a display
-// set up and not running this from SSH. NOTE: This may cause your program to
-// hang until the browser process is closed in some OSes, see
-// https://github.com/toqueteos/webbrowser/issues/4.
+// set up and not running this from SSH.
+// NOTE: This may cause your program to hang until the browser process is closed in
+// some OSes, see https://github.com/toqueteos/webbrowser/issues/4.
+// SECURITY(windows): Do not use a file:// URLs pointing to an executable, this
+// can execute programs, see https://github.com/toqueteos/webbrowser/issues/10
func Open(s string) (err error) {
if len(Candidates) == 0 {
return ErrNoCandidates