8000 Audit security stuff · Issue #40 · giscus/giscus · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

Audit security stuff #40

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and t 8000 he community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
laymonage opened this issue May 5, 2021 · 0 comments
Open

Audit security stuff #40

laymonage opened this issue May 5, 2021 · 0 comments
Labels
enhancement Nice to have help wanted Extra attention is needed placeholder May need to be addressed again in the future

Comments

@laymonage
Copy link
Member

I'm no security expert. There certainly are things that can be changed to improve the security aspect of this project. They are things like:

  • The <iframe> tag and how the widget page behaves with it
  • Security headers (CORS, etc.)
  • Maybe store the session data (encrypted user token) in cookies instead of localStorage

The list is non-exhaustive, so this is just more like a placeholder issue.

@laymonage laymonage added enhancement Nice to have help wanted Extra attention is needed labels May 5, 2021
@laymonage laymonage mentioned this issue May 5, 2021
21 tasks
@laymonage laymonage added the placeholder May need to be addressed again in the future label May 5, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement Nice to have help wanted Extra attention is needed placeholder May need to be addressed again in the future
Projects
None yet
Development

No branches or pull requests

1 participant
0