Building a Secure Electron App

栏目: IT技术 · 发布时间: 6年前

内容简介:The best way to build Electron apps with security in mind.If you are curious about what makes an electron app secure, please check outTaken from the

secure-electron-template

The best way to build Electron apps with security in mind.

If you are curious about what makes an electron app secure, please check out this page .

Features

Taken from the best-practices official page, here is what this repository offers!

  1. Only load secure content - (Need help!)
  2. Do not enable node.js integration for remote content - :white_check_mark:
  3. Enable context isolation for remote content - :white_check_mark:
  4. Handle session permission requests from remote content - :white_check_mark:
  5. Do not disable websecurity - :white_check_mark:
  6. Define a content security policy - :white_check_mark:
  7. Do not set allowRunningInsecureContent to true - :white_check_mark:
  8. Do not enable expirimental features - :white_check_mark:
  9. Do not use enableBlinkFeatures - :white_check_mark:
  10. Do not use allowpopups - :white_check_mark:
  11. <webview> verify options and params - :white_check_mark:
  12. Disable or limit navigation - :white_check_mark:
  13. Disable or limit creation of new windows - :white_check_mark:
  14. Do not use openExternal with untrusted content - :white_check_mark:
  15. Disable remote module - :white_check_mark:
  16. Filter the remote module - todo!
  17. Use a current version of electron - :white_check_mark:

Included frameworks

Built-in to this template are a number of popular frameworks already wired up to get you on the road running.

Roadmap

There are a number of additions that I'd like to implement in this repository, namely:

Both of these plans are being held back by some enhancements I'm going to tackle detailed in this issue . They will come soon.

I'd also like to get features such as auto-updating and more release-focused enhancements as well as a redux undo/redo history and test suites, but those are lower priority (but I welcome PRs!).

Architecture

For a more detailed view of the architecture of the template, please check out here . I would highly recommend reading this document to get yourself familiarized with this template.

How to get started

git clone https://github.com/reZach/secure-electron-template.git
cd secure-electron-template
npm i
npm run dev

以上就是本文的全部内容,希望对大家的学习有所帮助,也希望大家多多支持 码农网

查看所有标签

本站部分资源来源于网络,本站转载出于传递更多信息之目的,版权归原作者或者来源机构所有,如转载稿涉及版权问题,请联系我们

数据结构与算法

数据结构与算法

2009-8 / 32.00元

《数据结构与算法》系统地介绍了数据结构的基本概念和基本算法,主要内容包括:绪论,线性表,栈与队列,串,数组、特殊矩阵和广义表,树,图,排序,查找,算法的分析与设计,实验与上机指导。《数据结构与算法》特别注重突出应用性和实践性,实例和习题丰富,并在附录中给出了各章习题的答案。 《数据结构与算法》适合作为应用型本科院校和成人教育计算机专业数据结构课程的教材,也可作为数据结构培训班的教材以及软件从......一起来看看 《数据结构与算法》 这本书的介绍吧!

Markdown 在线编辑器
Markdown 在线编辑器

Markdown 在线编辑器

RGB HSV 转换
RGB HSV 转换

RGB HSV 互转工具

RGB CMYK 转换工具
RGB CMYK 转换工具

RGB CMYK 互转工具