Automattic / Automattic/kandelo

Should TLS MITM support come with guardrails to discourage abuse and exploitation?

Open
#825 0 comments 0 reactions 0 assignees View on GitHub
question
Dominant language
TypeScript
Stars
31
Forks
15
Avg merge
11h 7m
Merged PRs (30d)
80

Description

We support a TLS MITM in the browser in order to relay native HTTP requests to the browser's Fetch API. Some questions:

- What dangers are there for abuse?
- How can we discourage abuse?
- How can we design the default path so users are not easily exploitable by default?

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names no files or tests. Start by reviewing the existing browser TLS MITM path that relays native HTTP requests to the Fetch API, then identify abuse risks, trust boundaries, and unsafe defaults. Done means maintainers agree on guardrails, a safer default path, and an implementation plan.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript, wasm
Domain
networking, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.