mirror of
https://github.com/J3vb/OwnCord.git
synced 2026-09-03 03:50:00 +03:00
Addresses findings from comprehensive security review of the Tauri client: Critical: - Scope fs:allow-write-file from ** to $APPDATA/**,$APPLOG/** - Validate server_url scheme (https://) in update_commands.rs High: - Change CRED_PERSIST_LOCAL_MACHINE to CRED_PERSIST_ENTERPRISE (per-user) - Remove password from IPC response (#[serde(skip)] on CredentialData) - Auto-login uses stored token instead of password - Gate open_devtools behind #[cfg(feature = "devtools")] at registration - Validate remote_host for CRLF/null in livekit_proxy - Guard icons.ts innerHTML with runtime check - Add file upload MIME type allowlist - Clear pendingTotpPartialToken after use Medium: - Add sandbox attribute to YouTube iframes - Remove image/svg+xml from SAFE_MIME_TYPES - Strip trailing punctuation from linkified URLs - Validate host format in api.ts setConfig - Cap error messages at 200 chars (anti-phishing) - Rate limit search requests (500ms interval) - Validate Tenor GIF URLs against trusted origins - Sanitize notification titles (control chars + length cap) - Validate ptt_set_key vk_code range (1-254) - Add host validation to store_cert_fingerprint Docs: - Add "Client Security Hardening" section to docs/security.md