electron-userland / electron-userland/electron-webpack-quick-start
About security and use
- Dominant language
- JavaScript
- Stars
- 746
- Forks
- 245
- PR merge metrics
- No merged PRs in 30d
Description
Hello I'm relative new in nodejs electron webpack ecosystem.
Fork your current project and try to understand all things.
First I don't understandd where is the configuration files of tools used by apps like webpack conf by example.
Wanting to make a frameless app and need to use electron remote with node integration true to require BUT :
As well I read this paper explain why don't give free access of nodejs tools from renderer and it's better to "compile" a preload file containing nodejs access. sanboxing etc .. : https://doyensec.com/resources/us-17-Carettoni-Electronegativity-A-Study-Of-Electron-Security-wp.pdf
all that is described is still relevant despite the updates and how to implement these good practices ?
And final step for me is to use her tool by curiosity and one more time, try to understand :) : https://github.com/doyensec/electronegativity
Best regards
Contributor guide
No contributing guide indexed for this repository
Research direction
No specific file, test, or entry point is named; begin by locating the webpack configuration and Electron preload and renderer setup in the fork. Compare the current node integration and remote usage with the linked security paper and Electronegativity tool. Done would require a documented, concrete recommendation or implementation scope, which this issue does not define.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- electron, javascript, node.js, webpack
- Domain
- build-system, desktop, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100