[Pkg-matrix-maintainers] Bug#927842: matrix-synapse: Lintian privacy-breach-generic warnings

Linda Lapinlampi linda at lindalap.fi
Wed Apr 24 03:44:33 BST 2019


Package: matrix-synapse
Version: 0.99.2-3
Severity: important
Control: found -1 0.28.1+dfsg-1
Tags: help, upstream

Dear Maintainer,

Lintian throws a privacy-breach-generic warnings as follows:

    usr/lib/python3/dist-packages/synapse/res/templates/notif.html [<img class="sender_avatar" src="https://vector.im/beta/img/50e2c2.png" />] (https://vector.im/beta/img/50e2c2.png)
    usr/lib/python3/dist-packages/synapse/res/templates/notif.html [<img class="sender_avatar" src="https://vector.im/beta/img/76cfa6.png" />] (https://vector.im/beta/img/76cfa6.png)
    usr/lib/python3/dist-packages/synapse/res/templates/notif.html [<img class="sender_avatar" src="https://vector.im/beta/img/f4c371.png" />] (https://vector.im/beta/img/f4c371.png)
    usr/lib/python3/dist-packages/synapse/res/templates/notif_mail.html [<img src="http://matrix.org/img/matrix-120x51.png" width="120" height="51" alt="[matrix]"/>] (http://matrix.org/img/matrix-120x51.png)
    usr/lib/python3/dist-packages/synapse/res/templates/notif_mail.html [<img src="http://matrix.org/img/riot-logo-email.png" width="83" height="83" alt="[riot]"/>] (http://matrix.org/img/riot-logo-email.png)
    usr/lib/python3/dist-packages/synapse/res/templates/notif_mail.html [<img src="http://matrix.org/img/vector-logo-email.png" width="64" height="83" alt="[vector]"/>] (http://matrix.org/img/vector-logo-email.png)
    usr/lib/python3/dist-packages/synapse/res/templates/room.html [<img alt="" src="https://vector.im/beta/img/50e2c2.png" />] (https://vector.im/beta/img/50e2c2.png)
    usr/lib/python3/dist-packages/synapse/res/templates/room.html [<img alt="" src="https://vector.im/beta/img/76cfa6.png" />] (https://vector.im/beta/img/76cfa6.png)
    usr/lib/python3/dist-packages/synapse/res/templates/room.html [<img alt="" src="https://vector.im/beta/img/f4c371.png" />] (https://vector.im/beta/img/f4c371.png)
    usr/lib/python3/dist-packages/synapse/static/client/register/index.html [<script src="https://www.recaptcha.net/recaptcha/api/js/recaptcha_ajax.js">] (https://www.recaptcha.net/recaptcha/api/js/recaptcha_ajax.js)

It's been on my mind for a long time to make this package Lintian free
in collaboration, but I am not really sure how to solve the issues to
contribute a patch. This issue has been ignored for a long time now
between releases.

Since matrix.org infrastructure rebuild recently, the last of images of
matrix.org are now also 404 Not Found. vector.im images have rotted away
for a longer time. For the first 9 <img> tags, would we just remove
those lines with a patch? (This may also benefit the upstream, if
forwarded.)

ReCAPTCHA script on static/client/register/index.html I'd guess is the
deprecated Matrix Console client, and so probably unused? I get it it's
not installed by default anymore (Bug#923574), so could we remove it
with a mention in NEWS file about this (unavailable code)?



More information about the Pkg-matrix-maintainers mailing list