3 ms·
One might argue this should be a fork of Chromium, not Electron. Chromium comes with native tabs and a bunch of other useful parts, without the security issues
by iHateStylo 4y ago
One might argue this should be a fork of Chromium, not Electron. Chromium comes with native tabs and a bunch of other useful parts, without the security issues that Electron exposes.
- nateb2022 4y agoThis isn't a fork of Electron. It is an Electron-based app, and as such the Electron project maintains the core functionality of the browser and Min just presents a unified interface and feature set.
- DoctorOW 4y agoThey didn't say "fork of Electron", rather Electron is essentially "Chromium - browser UI" so they are saying there is a simplification to be made in an app that is "Chromium - browser UI + browser UI"
- jefftk 4y ago> They didn't say "fork of Electron" Flagging that the phrase "this should be a fork of Chromium, not Electron" is ambiguous between "this shouldn't be a fork of Electron" and "this shouldn't be Electron".
- nebulous1 4y agoThe phrasing is ambiguous, I agree. However, as forking Electron to make Min wouldn't make any sense, and the replier knew this, reading it to mean that seems like a mistake to me. The fact is that it can be very difficult to write things that aren't ambiguous at some level (albeit that isn't the case here), so the reader has to make a good-faith effort to understand.
- Wowfunhappy 4y agoFwiw, I read it the same way as nateb2022 at first. It took a second read to realize there was another interpretation. This is why writing is hard!
- deleted 4y ago[deleted]
- calny 4y ago> One might argue this should be a fork of Chromium, not Electron. Fair enough point. One reason it's Electron, I assume, is that it's much easier for typical developers to build than forking Chromium. I've been there. I've hacked at building a touchless-controlled browser that uses hand gesture and speech recognition to interact with the web. I can cobble something basic together in Electron, but it's much more intensive to get off the ground forking Chromium (though you're right the native tabs and useful parts would be helpful). > without the security issues that Electron exposes. Another reasonable point. For reference, here's an overview of security from Electron itself.[1] Security issues are one reason I haven't pursued the touchless browser more actively. I don't know if it's a dealbreaker, but it's not my area of expertise and I'd need to get seriously up to speed before releasing anything. From a glance, it does look like Min is trying to follow good security practices, such as having BrowserView webPreferences default to "nodeIntegration: false", "contextIsolation: true", etc.[2] And in the issues the maintainers seem aware of security issues, eg: > Making internal pages have the same privileges as the browser UI would be nice, although it's kind of difficult to implement. You could add nodeintegration to the webview tag, but I think there's a pretty big risk of accidentaly loading a regular webpage with nodeintegration enabled if we do that, which would be bad.[3] Ideally there wouldn't be such a large Chromium (and Chromium-based) monopoly on browsers, but overall I'm still glad to see projects like this trying to create different UI options. [1] https://www.electronjs.org/docs/latest/tutorial/security https://www.electronjs.org/docs/latest/tutorial/security [2] https://github.com/minbrowser/min/blob/7aba03fb645334366f9ec71867e36fc6fbf4ee15/main/viewManager.js#L9 https://github.com/minbrowser/min/blob/7aba03fb645334366f9ec... [3] https://github.com/minbrowser/min/issues/554#issuecomment-386829195 https://github.com/minbrowser/min/issues/554#issuecomment-38...