gopasspw / gopass

The slightly more awesome standard unix password manager for teams
https://www.gopass.pw/
MIT License
5.94k stars 496 forks source link

[RFC] Support flexible hooks? #2546

Open dominikschulz opened 1 year ago

dominikschulz commented 1 year ago

Recently gopass gained support for flexible hooks. However being flexible also means there is some potential for abuse. Another password manager got a CVE for the same "feature".

I'm not sure if we should really open that can of worms, too.

dominikschulz commented 8 months ago

There has been no feedback so far, so I think we can keep the current level of support for hooks. But at the same time I don't want to increase it for the time being. Keeping this open in case we want to revisit this feature.