diff options
| author | 2026-02-05 22:52:35 +0100 | |
|---|---|---|
| committer | 2026-02-05 22:52:35 +0100 | |
| commit | 110032fb486c4491edbfafd906f5784f36bd0f51 (patch) | |
| tree | 86cde217a30f7c654c332e1b4434fe81f55494a1 /data | |
| parent | Updated TODO. (diff) | |
| download | snac2-110032fb486c4491edbfafd906f5784f36bd0f51.tar.gz snac2-110032fb486c4491edbfafd906f5784f36bd0f51.tar.xz snac2-110032fb486c4491edbfafd906f5784f36bd0f51.zip | |
snac(8): Words of caution for strip_exif configuration
Add words of caution and reasoning to the "strip_exif" configuration for
the server.json file, as these commands would be executed outside of the
sandbox - at least on OpenBSD - and both have quite a history on
security issues due to their huge attack surface and variety of
supported protocols.
After getting comfortable with the related code, I would continue using
it on a personal instance, but would reconsider enabling "strip_exif" on
shared instances with multiple users.
IMO, snac administrators should at least know of potential dangers.
Diffstat (limited to 'data')
0 files changed, 0 insertions, 0 deletions