element-hq / element-hq/element-integration-manager

Restricting access to Etherpad / widgets in general

Open
#14 9 comments 1 reaction 0 assignees View on GitHub
C-Widgets T-Enhancement
Dominant language
No language data
Stars
11
Forks
2
PR merge metrics
No merged PRs in 30d

Description

The widgets idea is awesome, even though I managed to lose 30 minutes of (finger) work today, presumably due to spotty connectivity while on a train. I understand it's new and probably far from "stable".

But one thing concerns me. Take for instance Etherpad: if I add an Etherpad to a room that's members-only and encrypted, I'd kinda expect it to be "secure" in the sense that the Etherpad contents are also encrypted, and only accessible by people authenticated to the Matrix-universe.

However, there seems to be a publicly-accessible URL (with a random yet stable URL part) that anyone with knowledge can load, and this at the very least violates the principle of least surprise.

I don't know if this is even possible or how one would do it, but I'd like to vote for somehow embedding widgets within the authentication/authorization constraints that underlie Matrix. Here's an issue to track this. ;)

Contributor guide

No contributing guide indexed for this repository

Research direction

No files, tests, or entry points are named. Start by tracing how Etherpad and other widgets are exposed and how Matrix room membership, authentication, authorization, and encryption currently relate; done means an agreed design and implementation scope for preventing unauthorized widget access.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, authorization, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.