You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Oct 4, 2019. It is now read-only.
Supply a secure build alternative without all the short polled price callbacks and Shifty (provides JS with no checksum checks or other validations) and if possible prevent any connections in Electron(specifically Chromium) to anywhere but the localhost/127.0.0.1.
Once we determine what exactly needs to be changed to harden it, it will just be as simple as creating a script and adding it to the gulp build script.
So this allows people to have a significantly more secure GUI client with very little additional time invested.
I'm worried particularly about potential XSS attacks