pidgin/pidgin

41e1147347a5
Stop using g_uri_escape_string() to escape the URI before launching it.

This was wrong. Take this URL as an example:
https://developer.pidgin.im/search?q=brains&noquickjump=1&wiki=on

When escaped with g_uri_escape_string() it becomes:
https://developer.pidgin.im/search%3Fq%3Dbrains%26noquickjump%3D1%26wiki%3Don

?, = and & are replaced with %3F, %3D and %26 which means they are considered part of the path component rather than query args. I tested and I get 404s when launching that URL with Firefox, Google Chrome, and these manual commands: gnome-open, xdg-open, firefox, google-chrome.

Strangely I DON'T get a 404 when I launch the URL with Konqueror. The original unescaped URL loads. I consider this to be a bug in Konqueror. They would fail to load when launched with a URL that has a question mark as part of the path component because they would convert the remaining path into the query string.

So I ripped out uri_escaped and used uri in its place everywhere.

This bug never got released. We changed the behavior because someone reported
to us that this URL:
http://example.org/$(xterm)
caused xterm to be executed on his system. Obviously that's bad if that
happens, but I don't think it's a bug in Pidgin. We're correctly escaping
all arguments that we pass to the browser command. If a system unescapes those
at some point and execs them, then that system is dangerously broken.

I tested this newest code with Firefox, Google Chrome, Konqueror, and the
manual commands gnome-open and xdg-open and they all work perfectly for me.
/**
* @file purple.h Header files and defines
* This file contains all the necessary preprocessor directives to include
* libpurple's headers and other preprocessor directives required for plugins
* or UIs to build. Including this file eliminates the need to directly
* include any other libpurple files.
*
* @ingroup core libpurple
* @since 2.3.0
*/
/* purple
*
* Purple is the legal property of its developers, whose names are too numerous
* to list here. Please refer to the COPYRIGHT file distributed with this
* source distribution.
*
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation; either version 2 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program; if not, write to the Free Software
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02111-1301 USA
*/
#ifndef _PURPLE_PURPLE_H_
#define _PURPLE_PURPLE_H_
#include <glib.h>
#ifndef G_GNUC_NULL_TERMINATED
# if __GNUC__ >= 4
# define G_GNUC_NULL_TERMINATED __attribute__((__sentinel__))
# else
# define G_GNUC_NULL_TERMINATED
# endif
#endif
@PLUGINS_DEFINE@
#include <account.h>
#include <accountopt.h>
#include <blist.h>
#include <buddyicon.h>
#include <certificate.h>
#include <cipher.h>
#include <circbuffer.h>
#include <cmds.h>
#include <connection.h>
#include <conversation.h>
#include <core.h>
#include <debug.h>
#include <desktopitem.h>
#include <dnsquery.h>
#include <dnssrv.h>
#include <eventloop.h>
#include <ft.h>
#include <idle.h>
#include <imgstore.h>
#include <log.h>
#include <media.h>
#include <mediamanager.h>
#include <mime.h>
#include <nat-pmp.h>
#include <network.h>
#include <notify.h>
#include <ntlm.h>
#include <plugin.h>
#include <pluginpref.h>
#include <pounce.h>
#include <prefs.h>
#include <privacy.h>
#include <proxy.h>
#include <prpl.h>
#include <request.h>
#include <roomlist.h>
#include <savedstatuses.h>
#include <server.h>
#include <signals.h>
#include <smiley.h>
#include <sound.h>
#include <sound-theme.h>
#include <sound-theme-loader.h>
#include <sslconn.h>
#include <status.h>
#include <stringref.h>
#include <stun.h>
#include <theme.h>
#include <theme-loader.h>
#include <theme-manager.h>
#include <upnp.h>
#include <util.h>
#include <value.h>
#include <version.h>
#include <whiteboard.h>
#include <xmlnode.h>
#endif