Skip to content

Conversation

@PVince81
Copy link
Contributor

@PVince81 PVince81 commented Apr 1, 2022

image

I'm wondering if we should allow to disable loaders in the configuration, this way if someone is not using formats like IFC they could disable it and bypass the security concerns.

PVince81 added 2 commits April 1, 2022 13:13
Signed-off-by: Vincent Petry <vincent@nextcloud.com>
Signed-off-by: Vincent Petry <vincent@nextcloud.com>
@PVince81
Copy link
Contributor Author

PVince81 commented Apr 1, 2022

or switch to a different loader that doesn't require eval...

@PVince81
Copy link
Contributor Author

PVince81 commented Apr 1, 2022

I managed to temporarily hack the CSP rules to move forward, and now the next error:
image

@v1r0x
Copy link
Owner

v1r0x commented Apr 1, 2022

I'm wondering if we should allow to disable loaders in the configuration, this way if someone is not using formats like IFC they could disable it and bypass the security concerns.

I wouldn't add configuration for each loader. Instead I'd add a setting to enable/disable all loaders that e.g. require eval or any other kind of additional configuration

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants