electron-userland / electron-userland/electron-webpack-quick-start

About security and use

Open
#67 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
746
Forks
245
PR merge metrics
No merged PRs in 30d

Description

Hello I'm relative new in nodejs electron webpack ecosystem.

Fork your current project and try to understand all things.
First I don't understandd where is the configuration files of tools used by apps like webpack conf by example.

Wanting to make a frameless app and need to use electron remote with node integration true to require BUT :
As well I read this paper explain why don't give free access of nodejs tools from renderer and it's better to "compile" a preload file containing nodejs access. sanboxing etc .. : https://doyensec.com/resources/us-17-Carettoni-Electronegativity-A-Study-Of-Electron-Security-wp.pdf

all that is described is still relevant despite the updates and how to implement these good practices ?

And final step for me is to use her tool by curiosity and one more time, try to understand :) : https://github.com/doyensec/electronegativity

Best regards

Contributor guide

No contributing guide indexed for this repository

Research direction

No specific file, test, or entry point is named; begin by locating the webpack configuration and Electron preload and renderer setup in the fork. Compare the current node integration and remote usage with the linked security paper and Electronegativity tool. Done would require a documented, concrete recommendation or implementation scope, which this issue does not define.

Written by the indexing model from the issue text.

Assessment

Tech stack
electron, javascript, node.js, webpack
Domain
build-system, desktop, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.