Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

About security and use #67

Open
panpansh opened this issue Oct 5, 2019 · 0 comments
Open

About security and use #67

panpansh opened this issue Oct 5, 2019 · 0 comments

Comments

@panpansh
Copy link

panpansh commented Oct 5, 2019

Hello I'm relative new in nodejs electron webpack ecosystem.

Fork your current project and try to understand all things.
First I don't understandd where is the configuration files of tools used by apps like webpack conf by example.

Wanting to make a frameless app and need to use electron remote with node integration true to require BUT :
As well I read this paper explain why don't give free access of nodejs tools from renderer and it's better to "compile" a preload file containing nodejs access. sanboxing etc .. : https://doyensec.com/resources/us-17-Carettoni-Electronegativity-A-Study-Of-Electron-Security-wp.pdf

all that is described is still relevant despite the updates and how to implement these good practices ?

And final step for me is to use her tool by curiosity and one more time, try to understand :) : https://github.com/doyensec/electronegativity

Best regards

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant