alex8088 / electron-vite

Next generation Electron build tooling based on Vite 新一代 Electron 开发构建工具,支持源代码保护
https://electron-vite.org
MIT License
3.56k stars 153 forks source link

Setting sandbox to false so that bytecode plugin works is a security threat #620

Open kotasudhakar opened 2 months ago

kotasudhakar commented 2 months ago

Describe the bug

I understand that it was asked to turn the sandbox option to false in order to protect source code using bytecode plugin as it uses the nodevm, however it is kinda dangerous tbh to do so although there are still other options like contextIsolation to prevent render process accessing the main process.

Can we do in any other alternative way so that we no need to set the sandbox value to false for browserWindow options and improving security? may be using something like Jailed/Hermes

https://electron-vite.org/guide/source-code-protection image

Electron-Vite Version

2.0.0

Electron Version

32.0.0

Vite Version

Not using specifially in my dependencies, i think it comes with the vite-electron

Validations

hifron commented 1 month ago

Ubuntu in next version 24.10 releases Security Centre with Prompting for permission, but in 24.04 is not it enabled or installable due experimental nature of snapd(from 24.10) in 24.04 and therefore backport of snapd or such possibility to make snap install security-center and prompting-client is not yet fully possible as stable option...