melo936 / ChromiumHardening

GNU General Public License v3.0
105 stars 12 forks source link

URLs #14

Open ci70 opened 2 years ago

ci70 commented 2 years ago

More URL flags present in the binary.

absolute-url app-launch-url-for-shortcuts-menu-item application-url apps-gallery-download-url apps-gallery-update-url apps-gallery-url autofill-server-url binary-upload-service-url cert-url chrome-urls cloud-print-url collections-base-url connectivity-check-url cross-origin-url deprecated-requested-url device-management-url download-url-checked-update enable-desktop-pwas-url-handling encrypted-reporting-url extensions-on-chrome-urls form-url gaia-url gcm-checkin-url gcm-registration-url google-apis-url google-base-url google-doodle-url google-url gpu-url-chunk history-url ignore-urlfetcher-cert-requests lens-homepage-url Line doc-url lso-url main-frame-url no-safe-url no-url-for-service-worker oauth-account-manager-url omnibox-bubble-url-suggestions omnibox-max-url-matches omnibox-rich-autocompletion-prefer-urls-over-prefixes optimization-guide-service-get-hints-url optimization-guide-service-get-models-url original-url permission-predictions-service-url proxy-pac-url purchase-url-pattern-mapping realtime-reporting-url region-search-lens-homepage-url register-url-protocol reporting-connector-url safe-browsing-url-check-data search-provider-logo-url start-url-not-valid sync-url third-party-doodle-url top-level-url translate-ranker-model-url translate-script-url trustable-web-bundles-file-url trusted-vault-service-url unsafe-url validity-url variations-insecure-server-url variations-server-url vendor-url

melo936 commented 2 years ago

Hello @7wgs0gr04v,

Happy to see new people contributing in this repo and thank you for the suggestion, but there is a problem. We cannot use everything from the list, that you sent, due to most of them are not available, useless, already disabled via features or a security risk. I think It might worth to include --device-management-url in the guide, but as Not Recommended.

ci70 commented 2 years ago

Some of your flags for URLs trigger You are using an unsupported command-line flag: XYZ. Stability and security will suffer Could be --gaia-url="0.0.0.0"