Skip to content

doc: clarify pm limitations and include symlink statement #49153

New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Closed
wants to merge 1 commit into from

Conversation

RafaelGSS
Copy link
Member

This PR improves the "Limitations and known issues" section and includes a statement of relative symlinks.

Refs: https://github.com/nodejs-private/node-private/pull/413#issuecomment-1665749899

@RafaelGSS RafaelGSS requested review from tniessen and mhdawson August 13, 2023 22:09
@nodejs-github-bot
Copy link
Collaborator

Review requested:

  • @nodejs/security-wg

@nodejs-github-bot nodejs-github-bot added the doc Issues and PRs related to the documentations. label Aug 13, 2023
Copy link
Member

@tniessen tniessen left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think this is clear enough w.r.t. how easily the permission model falls apart. I wrote a couple of patches and documentation updates before you disclosed the vulnerability. See #49154, #49155, and #49156.

@RafaelGSS
Copy link
Member Author

I will take a look o those tomorrow, thanks! Anyway, I believe this PR also clarifies most of the current statements.

@RafaelGSS
Copy link
Member Author

I will close this PR and open another one when #49154, #49155, and #49156 land.

@RafaelGSS RafaelGSS closed this Aug 14, 2023
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
doc Issues and PRs related to the documentations.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants