You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
PR #227 implements the m.space.parent event when creating new projects and when adding/removing space children.
By default this would invlove exposng the room id for a user's application space (draft space and/or published space inside of applications/medienhaus-cms) in these events.
Exposing the room ID might pose security risks? Although room IDs are not secret, exposing them could potentially make it easier for malicious actors to target specific rooms. I guess it could also lead to privacy concerns, if the room contains sensitive information, or is misconfigured.
Is there any benifit of adding the applicaiton space to the m.space.parent event? Other than complying with the specs, and keeping the event up to date.
securityThis issue poses a potential security risk
1 participant
Heading
Bold
Italic
Quote
Code
Link
Numbered list
Unordered list
Task list
Attach files
Mention
Reference
Menu
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
-
PR #227 implements the
m.space.parent
event when creating new projects and when adding/removing space children.By default this would invlove exposng the room id for a user's application space (draft space and/or published space inside of applications/medienhaus-cms) in these events.
Exposing the room ID might pose security risks? Although room IDs are not secret, exposing them could potentially make it easier for malicious actors to target specific rooms. I guess it could also lead to privacy concerns, if the room contains sensitive information, or is misconfigured.
Is there any benifit of adding the applicaiton space to the
m.space.parent
event? Other than complying with the specs, and keeping the event up to date.@robertschnuell @andirueckel
Beta Was this translation helpful? Give feedback.
All reactions