aboutsummaryrefslogtreecommitdiff
path: root/src
diff options
context:
space:
mode:
authorMichael Vetter <jubalh@iodoru.org>2018-11-12 12:32:41 +0100
committerMichael Vetter <jubalh@iodoru.org>2018-11-12 12:32:41 +0100
commita8dffc63fbe3926498ecb905428f454d0afbe526 (patch)
tree63ec90588c2addd443337fe30b18a01a9a3441e0 /src
parent30a1edd40ef77b1bbbd90be7c848985f064f7060 (diff)
downloadraylib-a8dffc63fbe3926498ecb905428f454d0afbe526.tar.gz
raylib-a8dffc63fbe3926498ecb905428f454d0afbe526.zip
Add warning to OpenURL()
See https://github.com/raysan5/raylib/issues/686
Diffstat (limited to 'src')
-rw-r--r--src/core.c6
1 files changed, 6 insertions, 0 deletions
diff --git a/src/core.c b/src/core.c
index 1f4707c8..88b41935 100644
--- a/src/core.c
+++ b/src/core.c
@@ -1820,6 +1820,12 @@ int StorageLoadValue(int position)
}
// Open URL with default system browser (if available)
+// Note:
+// This function is onlyl safe to use if you control the URL given.
+// A user could craft a malicious string performing another action.
+// Only call this function yourself not with user input or make sure to check the
+// string yourself.
+// See https://github.com/raysan5/raylib/issues/686
void OpenURL(const char *url)
{
char *cmd = calloc(strlen(url) + 10, sizeof(char));