Automattic / Automattic/kandelo
Should TLS MITM support come with guardrails to discourage abuse and exploitation?
- Dominant language
- TypeScript
- Stars
- 31
- Forks
- 15
- Avg merge
- 11h 7m
- Merged PRs (30d)
- 80
Description
We support a TLS MITM in the browser in order to relay native HTTP requests to the browser's Fetch API. Some questions:
- What dangers are there for abuse?
- How can we discourage abuse?
- How can we design the default path so users are not easily exploitable by default?
Contributor guide
No contributing guide indexed for this repository
Research direction
The issue names no files or tests. Start by reviewing the existing browser TLS MITM path that relays native HTTP requests to the Fetch API, then identify abuse risks, trust boundaries, and unsafe defaults. Done means maintainers agree on guardrails, a safer default path, and an implementation plan.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript, wasm
- Domain
- networking, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100