2 ms·
That's not really a container though, Firefox by default has a wide-range access. As someone who has to use Zoom, I use firejail, which is a true container, sup
by tagrun 5y ago
That's not really a container though, Firefox by default has a wide-range access. As someone who has to use Zoom, I use firejail, which is a true container, super easy to use and comes with a profile for Zoom out-of-the-box.
To set it up, just create a symlink once
# ln -s /usr/bin/firejail /usr/local/bin/zoom
and you should be all set (assuming that in your PATH, /usr/local/bin comes before wherever the real zoom binary is, more details on firejail: https://wiki.archlinux.org/title/firejail#Using_Firejail_by_default https://wiki.archlinux.org/title/firejail#Using_Firejail_by_...)
In my case, I also have a ~/.config/firejail/zoom.local file with the contents
whitelist ${HOME}/Documents/Zoom/
noblacklist ${HOME}/Documents/Zoom/
to fine-tune access for storing chat logs under the default path.
It is also very easy to sandbox X11 access with firejail (which uses Xpra or Xephyr), but I only have Zoom running when I use it, and I often need share my screen, so I don't enable it.