Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ask users whether they trust the project contents when starting a workspace from a factory link #20249

Closed
ericwill opened this issue Aug 4, 2021 · 1 comment
Assignees
Labels
area/plugins kind/enhancement A feature request - must adhere to the feature request template. sprint/current
Milestone

Comments

@ericwill
Copy link
Contributor

ericwill commented Aug 4, 2021

Is your enhancement related to a problem? Please describe.

A user could start a workspace from a factory link, which points to a project with potentially malicious code. While there isn't much we can do about users running malicious devfiles, we can at least ask them (during workspace startup) whether or not they trust the source.

Describe the solution you'd like

When starting a workspace from a factory link, prompt the user to confirm that they trust the content of the workspace they are starting. If they do not, then abort the workspace startup. This could be done with a dialog.

Of course it would be annoying to have to do this every time. There should probably be a setting where the user can disable this dialog from being shown.

Describe alternatives you've considered

I'm open to any other ideas 😄

@ericwill ericwill added kind/enhancement A feature request - must adhere to the feature request template. area/plugins sprint/next labels Aug 4, 2021
@svor svor added this to the 7.35 milestone Aug 12, 2021
@svor svor mentioned this issue Aug 12, 2021
30 tasks
@tsmaeder
Copy link
Contributor

There used to be other ways to share access to workspaces (I believe "organisations" in che server). If these mechanisms still exist, they would also be a candidate for such a warning.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/plugins kind/enhancement A feature request - must adhere to the feature request template. sprint/current
Projects
None yet
Development

No branches or pull requests

5 participants