GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Deno (deno_land@fosstodon.org)'s status on Saturday, 05-Aug-2023 02:06:43 JST Deno Deno

    #Deno 1.36 introduces more flexible security options with the new set of `--deny-*` flags:

    In conversation 2 years ago from fosstodon.org permalink

    Attachments


    1. https://cdn.fosstodon.org/media_attachments/files/110/832/437/013/380/350/original/456b8c9ca78e7cb5.png
    • Embed this notice
      Alex Gleason (alex@gleasonator.com)'s status on Saturday, 05-Aug-2023 02:06:49 JST Alex Gleason Alex Gleason
      in reply to
      • Elaine
      @deno_land @elaine Interesting.
      In conversation 2 years ago permalink
    • Embed this notice
      Deno (deno_land@fosstodon.org)'s status on Saturday, 05-Aug-2023 02:07:32 JST Deno Deno
      in reply to

      Here's the set of new deny flags, which have higher precedence over allow flags:

      --deny-env=<VARIABLE_NAME>
      --deny-sys=<API_NAME>
      --deny-hrtime
      --allow-net=<IP/HOSTNAME>
      --deny-ffi=<PATH>
      --deny-read=<PATH>
      --deny-run=<PROGRAM_NAME>
      --deny-write=<PATH>

      Learn more here: https://deno.land/manual/basics/permissions

      In conversation 2 years ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: deno.com
        Permissions | Manual | Deno
        from @deno_land
        Deno is secure by default. Therefore, unless you specifically enable it, a program run with Deno has no file, network, or environment access. Access to security sensitive functionality requires that
      Alex Gleason likes this.
    • Embed this notice
      Alex Gleason (alex@gleasonator.com)'s status on Saturday, 05-Aug-2023 02:09:33 JST Alex Gleason Alex Gleason
      in reply to
      @deno_land Being able to specify a read/write path is where it's at.
      In conversation 2 years ago permalink
    • Embed this notice
      Alex Gleason (alex@gleasonator.com)'s status on Saturday, 05-Aug-2023 02:13:43 JST Alex Gleason Alex Gleason
      in reply to
      • Alex Gleason
      @deno_land Lol Deno would completely avoid the directory traversal attack from Pleroma this morning with this sandboxing configured
      In conversation 2 years ago permalink
      victor likes this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.

Embed this notice