zeronet-conservancy / zeronet-conservancy

zeronet-conservancy is a client for decentralized p2p web 0net, focusing on preserving 0net and transition to riza network
Other
230 stars 25 forks source link

This site requests permission: ADMIN #82

Closed slrslr closed 2 years ago

slrslr commented 2 years ago

Step 1: Please describe your environment

Step 2: Describe the problem:

ZeroHello site http://127.0.0.1:43110/126NXcevn1AUehWFZLTBw7FrX1crEizQdr/ asks:

This site requests permission: ADMIN Modify your client's configuration and access all site (Dangerous!) [ Grant ]

I read that this it is risky to grant this permission. What are advantages and disadvantages of granting/not granting. Etc.

caryoscelus commented 2 years ago

I read that this it is risky to grant this permission. What are advantages and disadvantages of granting/not granting. Etc.

original ZeroNet client granted ADMIN permission to the starting page and page of update by default , without asking . we decided that before settling with better solution , we'll make sure users understand that the start page uses ADMIN permissions and grants them explicitly . if you don't want it / don't trust that it's a safe site , you can clone (so that no one but you can edit it) an old zerohello and grant it ADMIN permissions and use it as dashboard/admin page

if you don't grant permission to any of admin pages , you won't be able to use features like site list and notifications , but other functionality will be still in place

slrslr commented 2 years ago

Thanks, by the way, when there is a note "Dangerous!" i as a layman user would like some extended/easily accessible description where is mentioned why this is needed, risks of granting, possibly the suggestion not to grant permission unless the site owner is trusted.

caryoscelus commented 2 years ago

yeah , all true . PRs are welcome ;) but we're a little underhanded to handle everything with the core team

caryoscelus commented 2 years ago

i've changed the warning ;)

Allow this site to administrate your 0net node (Make sure you trust site developer before accepting!)

please feel free to close the issue if you think it is good enough