Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add privacy warning #6

Closed
Rudxain opened this issue Nov 2, 2024 · 2 comments · Fixed by #7
Closed

Add privacy warning #6

Rudxain opened this issue Nov 2, 2024 · 2 comments · Fixed by #7
Assignees
Labels
documentation Improvements or additions to documentation

Comments

@Rudxain
Copy link
Collaborator

Rudxain commented Nov 2, 2024

If a repo script persistently stores sensitive data (as cookie, localStorage, etc...), then other repos opened by the user will also have access to this data. This isn't inherently a problem of bypassing CORS, so it should be mentioned as an additional risk (both in the README and the index)

I haven't tested if this "vulnerability" actually works, but I assume it's likely that it can be easily exploited

@hoijui
Copy link

hoijui commented Nov 2, 2024

Sorry, I did not get notifications for this repo, even though I created it. :/
(now I do)
... and you can now do this yourself! :-)

@Rudxain
Copy link
Collaborator Author

Rudxain commented Nov 2, 2024

Thank you for the invite! I'm sorry for being late: I was sleeping, and I had to do some stuff.

I've created a separate branch, and I'll merge to master when ready.

For some reason, I can't link the branch to this issue, so I'll open a PR

@Rudxain Rudxain added the documentation Improvements or additions to documentation label Nov 2, 2024
@Rudxain Rudxain self-assigned this Nov 2, 2024
@Rudxain Rudxain closed this as completed in #7 Nov 3, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants