Skip to content

Reduce Multiplex permissions #12

@sonnyp

Description

@sonnyp

Follow up to https://floss.social/@[email protected]/111966298529562604
See https://flathub.org/apps/com.pojtinger.felicitas.Multiplex

I'm pretty sure we can get from "potentially unsafe" to "probably safe". We don't do a lot of advocacy around this topic so if we succeed I'd love to publish a blog post on Flathub blog.

Here are some quick suggestions - not sure how realistic

  • Network access: no choice for now until we get a network portal Network permission portal flatpak/xdg-desktop-portal#1166
  • Arbitrary permission: whatever you spawn, do it in the sandbox
  • Download Folder read/write access: instead ask users where they want to save files (one time is fine, document portal entries are permanent)
  • System folder /tmp: there is a $TMPDIR in the sandbox
  • Video folder: same as download folder - use document portal

Flathub:

image

GNOME Softare:

image

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions