element-hq / element-hq/element-integration-manager
Restricting access to Etherpad / widgets in general
- Dominant language
- No language data
- Stars
- 11
- Forks
- 2
- PR merge metrics
- No merged PRs in 30d
Description
The widgets idea is awesome, even though I managed to lose 30 minutes of (finger) work today, presumably due to spotty connectivity while on a train. I understand it's new and probably far from "stable".
But one thing concerns me. Take for instance Etherpad: if I add an Etherpad to a room that's members-only and encrypted, I'd kinda expect it to be "secure" in the sense that the Etherpad contents are also encrypted, and only accessible by people authenticated to the Matrix-universe.
However, there seems to be a publicly-accessible URL (with a random yet stable URL part) that anyone with knowledge can load, and this at the very least violates the principle of least surprise.
I don't know if this is even possible or how one would do it, but I'd like to vote for somehow embedding widgets within the authentication/authorization constraints that underlie Matrix. Here's an issue to track this. ;)
Contributor guide
No contributing guide indexed for this repository
Research direction
No files, tests, or entry points are named. Start by tracing how Etherpad and other widgets are exposed and how Matrix room membership, authentication, authorization, and encryption currently relate; done means an agreed design and implementation scope for preventing unauthorized widget access.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, authorization, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100