3 ms·
Given its a wasm app running client side completely from static assets, I'm not worried at all. Do you know of any risk in terms of attack vectors? I guess mayb
by morphicpro 3y ago
Given its a wasm app running client side completely from static assets, I'm not worried at all. Do you know of any risk in terms of attack vectors? I guess maybe someone could exploit the client by some other means and then take advantage of the export in some manner the could end up getting the client to download an "image" with embed script. That's also just conjecture I have no clue.
- BandButcher 3y agomost likely there are no security issues in the code, but there could be potentially, see this link: https://security.stackexchange.com/a/81926 https://security.stackexchange.com/a/81926 tldr: its possible for images to not really be images. Whenever you are getting user input, its usually best practice to always validate it "server side", in this case, the rust code, which is compiled machine code. An attacker could possibly upload a malicious "image" and if there are rust functions that operate on that data blindly, it could lead to a pwnage (ex. access to memory outside the browser/colorizer program)