shruggr / bottle-upload

7 stars 5 forks source link

Multiple improvements (see description) #7

Open Siko91 opened 5 years ago

Siko91 commented 5 years ago

Multiple improvements:

shruggr commented 5 years ago

Can BitBtn source be saved and linked as a B or BCAT transaction id? As implemented, this will not work with Bottle since githack is not in the trusted sources.

Siko91 commented 5 years ago

It can. But it is still changing quite often. It will quickly get outdated. How about a D:// link?

Also - I never actually tested if it even works from Bottle. It is hard to test, because no desktop wallet supports BitBtn's OutputURI yet.

shruggr commented 5 years ago

To be honest, I'm not even sure that the base functionality even works with bottle any more, but this wallet is not really safe in a regular browser. Any page served over bico.media can access your keys how it is currently implemented

Siko91 commented 5 years ago

It is safe enough in a regular browser if it provided from our own websites, and not from bico.

There are still possible risks (XSS), but considering that this wallet is not really intended for holding of money, I believe it is safe enough.