Open coldwaterq opened 10 years ago
An idea how to do this maybe, more testing definitely needed, and security needs to be considered thorougly.
have it work like the win token, a value can be returned that when found will cause the server to interpret the response as a phantomjs script, and which will be run under it's own apparmor profile as a service.
The server can return a message, suplied by the user, or a redirect supplied by the user. This has obvious security concerns so maybe just a redirect to the root of the challenge.
This has got to be done as a separate service, the app armour profile does not provide enough memory for phantomjs. Maybe a button on the profile allows users to trigger a target to visit the page.
add support for people to create phantomjs scripts