3 ms·
> guess there are simple embedded js interpreters In fact a duktape backend has just landed: https://gitlab.freedesktop.org/polkit/polkit/-/merge_requests/97
by floatboth 5y ago
> guess there are simple embedded js interpreters
In fact a duktape backend has just landed:
https://gitlab.freedesktop.org/polkit/polkit/-/merge_requests/97 https://gitlab.freedesktop.org/polkit/polkit/-/merge_request...
Speaking of security though, I'd trust SpiderMonkey much more because it's battle-tested in the most hostile environment imaginable (millions of browser instances loading completely untrusted code 24/7). But in this context we don't execute untrusted code so whatever :)
> pkexec should not exist
Hmm. For things that do want "just a graphical sudo" for whatever reason, it is kinda the perfect answer. Reusing the per-desktop authorization UI that is used for more fine-grained actions for a sudo-like tool is the correct thing to do. No one wants to have more redundant authorization mechanisms and UIs…
- smorgusofborg 5y ago> I'd trust SpiderMonkey much more because it's battle-tested in the most hostile environment imaginable Enough OSes are behind and everyone using spidermonkey is unable to keep up with the porting requirements in the short window of ESR overlap so you can read vulnerabilities for the latest ESR and apply them to everyone. It would be nice if duktape had complete sandboxing, etc, but it has the advantage that hackers have to do all their own research to mount an attack.
- dathinab 5y agoOk, let me correct myself, `pkexec` as a simple GUI sudo should probably exist. But be differently designed. (I would have to read through the polkit doc again, but there was some massive trap around how polkit configs work and how pkexec _might_ be used, I think related to the "permission caching feature").