diff --git a/etc/thunderbird.profile b/etc/thunderbird.profile index 34594b837..9305d06b0 100644 --- a/etc/thunderbird.profile +++ b/etc/thunderbird.profile @@ -1,7 +1,20 @@ # Firejail profile for Mozilla Thunderbird (Icedove in Debian) include /etc/firejail/disable-mgmt.inc include /etc/firejail/disable-secret.inc -include /etc/firejail/disable-common.inc thunderbird icedove + +# Users have thunderbird set to open a browser by clicking a link in an email +# We are not allowed to blacklist browser-specific directories +#include /etc/firejail/disable-common.inc thunderbird icedove +blacklist ${HOME}/.adobe +blacklist ${HOME}/.macromedia +blacklist ${HOME}/.filezilla +blacklist ${HOME}/.config/filezilla +blacklist ${HOME}/.purple +blacklist ${HOME}/.config/psi+ +blacklist ${HOME}/.remmina +blacklist ${HOME}/.tconn + + include /etc/firejail/disable-history.inc caps.drop all seccomp