Skip to content
This repository has been archived by the owner on Jun 23, 2023. It is now read-only.

Dashboard should not refer to github for images #443

Open
oren-z0 opened this issue Dec 28, 2022 · 0 comments
Open

Dashboard should not refer to github for images #443

oren-z0 opened this issue Dec 28, 2022 · 0 comments

Comments

@oren-z0
Copy link

oren-z0 commented Dec 28, 2022

The dashboard should not refer to github for images (i.e. when viewing apps in the app-store, before installing them).
It's ok if the node backend will download the images on demand, but using an <img src="..." /> allows github to link the browser's ip to the umbrel apps that the user looks at.

This is especially true for users that use Tailscale and think that they are completely safe - only the requests to their node go through the VPN, not the requests to the other resources.

Obviously you can't enforce this on every app that the user installs, but this is no longer under your control.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant