4 ms·
I know it's biased because it's an opinion from a competitor, but it's interesting nevertheless: https://blog.standardnotes.com/33536/how-not-to-build-a-secure
by fguerraz 5y ago
I know it's biased because it's an opinion from a competitor, but it's interesting nevertheless:
https://blog.standardnotes.com/33536/how-not-to-build-a-secure-plugins-architecture https://blog.standardnotes.com/33536/how-not-to-build-a-secu...
- randomluck040 5y agoI‘ll give it a read, thank you!
- jitl 5y agoHave you considered adding a capability for plugins to draw HTML into an <iframe sandbox>? I'm always pondering such features, but I'm wary of letting a plugin potentially block the CPU forever with custom <script> elements. I have a solution to plugin CPU blocking for pure API plugins (https://github.com/justjake/quickjs-emscripten https://github.com/justjake/quickjs-emscripten) but not a way to meld it safely with HTML access.