flathub / flathub/org.gnome.World.Secrets
Please avoid --device=all
Open
- Dominant language
- No language data
- Stars
- 3
- Forks
- 4
- PR merge metrics
- No merged PRs in 30d
Description
--device=all is a known sandbox escape vector and should be avoided if possible. Is it possible to remove this permission or use a less broad permission? This application already has --socket=pcsc which should cover the smart unlock thing I think?
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by locating the Flatpak manifest and reviewing how --device=all and --socket=pcsc are declared. Check whether the application still supports its smart-unlock behavior without the broad device permission, then build and run the application to confirm the sandbox configuration works.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100