summaryrefslogtreecommitdiff
path: root/data
diff options
context:
space:
mode:
authorGravatar Alvar Penning2026-02-05 22:52:35 +0100
committerGravatar Alvar Penning2026-02-05 22:52:35 +0100
commit110032fb486c4491edbfafd906f5784f36bd0f51 (patch)
tree86cde217a30f7c654c332e1b4434fe81f55494a1 /data
parentUpdated TODO. (diff)
downloadsnac2-110032fb486c4491edbfafd906f5784f36bd0f51.tar.gz
snac2-110032fb486c4491edbfafd906f5784f36bd0f51.tar.xz
snac2-110032fb486c4491edbfafd906f5784f36bd0f51.zip
snac(8): Words of caution for strip_exif configuration
Add words of caution and reasoning to the "strip_exif" configuration for the server.json file, as these commands would be executed outside of the sandbox - at least on OpenBSD - and both have quite a history on security issues due to their huge attack surface and variety of supported protocols. After getting comfortable with the related code, I would continue using it on a personal instance, but would reconsider enabling "strip_exif" on shared instances with multiple users. IMO, snac administrators should at least know of potential dangers.
Diffstat (limited to 'data')
0 files changed, 0 insertions, 0 deletions