-
Notifications
You must be signed in to change notification settings - Fork 2
Open
Labels
IMPORTANTTHIS IS SERIOUSLY IMPORTANTTHIS IS SERIOUSLY IMPORTANTgood first issueGood for newcomersGood for newcomershelp wantedExtra attention is neededExtra attention is needed
Description
In main.js, webPreferences look like this:
webPreferences: {
nodeIntegration: true,
webviewTag: true,
enableRemoteModule: true,
contextIsolation: false,
preload: `${__dirname}/scripts/preload.js`
},Now, somethings to really look out for:
- Node Integration is on. Hackers could possibly access Node APIs on insecure websites. BE CAREFUL.
- The
<webview>tag is on. This is to enable web browsing. Its Chromium API is undergoing some changes, but as far as I understand, there are no major security risks. - The
@electron/remoteis enabled. This is for the windows controls. - Context Isolation is off. THIS IS A MAJOR SECURITY RISK. USE ICEWOLF AT YOUR OWN RISK.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
IMPORTANTTHIS IS SERIOUSLY IMPORTANTTHIS IS SERIOUSLY IMPORTANTgood first issueGood for newcomersGood for newcomershelp wantedExtra attention is neededExtra attention is needed