Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Disable certain dangerous features for un-authenticated users #75

Open
jon-betts opened this issue Dec 15, 2020 · 1 comment
Open

Disable certain dangerous features for un-authenticated users #75

jon-betts opened this issue Dec 15, 2020 · 1 comment
Labels
Via Abuse Ideas for reducing abuses of Via

Comments

@jon-betts
Copy link
Contributor

If we could make a user login before seeing the content, we could still allow anonymous access, but with more restrictions.

For example we could:

  • Disable forms
  • Disable links
  • Other actions which make phishing difficult

We should also consider if any of these are acceptable as defaults, or if they break too much genuine content.

@jon-betts jon-betts added this to the 4 - Idea factory milestone Dec 15, 2020
@dwhly
Copy link
Member

dwhly commented Dec 15, 2020

I think there are two ideas here:

Disallowing unauthenticated use.
Disabling certain kinds of HTML features.

I think the first one is a non starter for the main via instance. I need to be able to tweet out a via link and have people easily see my annotations without logging in.

For the second, possibly forms but not links. People need to be able to click thru to another page, though that page doesn’t need to be proxied too.

@jon-betts jon-betts modified the milestones: 4 - Idea factory, 3 - Prevent unwanted uses of Via Jan 5, 2021
@seanh seanh added Via Abuse Ideas for reducing abuses of Via and removed phishing labels Feb 15, 2021
@seanh seanh removed this from the Ideas: Prevent unwanted uses of Via milestone Feb 16, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Via Abuse Ideas for reducing abuses of Via
Projects
None yet
Development

No branches or pull requests

3 participants