@cronfox https://github.com/ukatech/web-ghost-terminal/invitations
邀请发了
Conversation
Notices
-
steve (steve02081504@ukadon.shillest.net)'s status on Friday, 23-Feb-2024 09:23:00 JST steve -
steve (steve02081504@ukadon.shillest.net)'s status on Friday, 23-Feb-2024 09:22:57 JST steve @cronfox 我的想法是问问ssp维护者能不能把sstp报文的来源网址标注一下,这样ghost就能针对网址白名单了
之前提过好些次,可能是我没说清楚,貌似还没做这块 -
steve (steve02081504@ukadon.shillest.net)'s status on Friday, 23-Feb-2024 09:22:57 JST steve @cronfox @ponapalt help wanted of https://bts.shillest.net/view.php?id=604 !
-
ぽな (C.Ponapalt) (ponapalt@ukadon.shillest.net)'s status on Friday, 23-Feb-2024 09:22:57 JST ぽな (C.Ponapalt) @steve02081504 @cronfox Do you expect the HTTP Origin header to be passed to the ghost as is?
https://developer.mozilla.org/ja/docs/Web/HTTP/Headers/OriginIn conversation permalink Attachments
-
cronfox (cronfox@ukadon.shillest.net)'s status on Friday, 23-Feb-2024 09:22:58 JST cronfox @steve02081504 暂时没做那块功能(悲)
目前实现是中间件过滤(如果是敏感事件+external则直接返回一个报错)In conversation permalink -
cronfox (cronfox@ukadon.shillest.net)'s status on Friday, 23-Feb-2024 09:22:58 JST cronfox @steve02081504 后续应该是区分external/local做个假shell(笑),external只允许访问我后续会搞的客户端大模型
In conversation permalink -
cronfox (cronfox@ukadon.shillest.net)'s status on Friday, 23-Feb-2024 09:22:59 JST cronfox @steve02081504 我只是摘抄了一下SSTP协议的spec(
In conversation permalink -
cronfox (cronfox@ukadon.shillest.net)'s status on Friday, 23-Feb-2024 09:22:59 JST cronfox @steve02081504 你想想文档那个事件支持查询是怎么实现的
In conversation permalink -
steve (steve02081504@ukadon.shillest.net)'s status on Friday, 23-Feb-2024 09:22:59 JST steve @cronfox 问题在于查询事件支持不是敏感操作 没有副作用 所以可以external
In conversation permalink -
steve (steve02081504@ukadon.shillest.net)'s status on Friday, 23-Feb-2024 09:22:59 JST steve @cronfox 你比方说我假如把taromati2的ShioriEcho设置到external,万一有哪个网页来个ShioriEcho('system(\'rm -rf /\')')咋办(
In conversation permalink -
cronfox (cronfox@ukadon.shillest.net)'s status on Friday, 23-Feb-2024 09:22:59 JST cronfox @steve02081504 确实
我那个估计得防各种 child_process.spawnSync啥的(In conversation permalink Attachments
-
steve (steve02081504@ukadon.shillest.net)'s status on Friday, 23-Feb-2024 09:22:59 JST steve @cronfox 评价是不把ShioriEcho列在external最好
In conversation permalink -
steve (steve02081504@ukadon.shillest.net)'s status on Friday, 23-Feb-2024 09:23:00 JST steve @cronfox 艹,我突然想到个问题,浏览器触发的事件是external的,一般ghost不会把shioriEcho整成external
In conversation permalink -
cronfox (cronfox@ukadon.shillest.net)'s status on Friday, 23-Feb-2024 09:23:00 JST cronfox @steve02081504 "This restriction is relaxed only when the Origin of HTTP is localhost and the SecurityLevel of SSTP is local." 感觉应该没问题
In conversation permalink -
steve (steve02081504@ukadon.shillest.net)'s status on Friday, 23-Feb-2024 09:23:00 JST steve @cronfox 你的意思是不通过webpage运行而是运行本地网页文件或者本地js?
那我都能本地跑了为什不用exe呢(In conversation permalink -
steve (steve02081504@ukadon.shillest.net)'s status on Friday, 23-Feb-2024 10:39:46 JST steve In conversation permalink -
steve (steve02081504@ukadon.shillest.net)'s status on Friday, 23-Feb-2024 12:53:19 JST steve @ponapalt I'd also like to know why some of my other proposals (including Icon animation scripts, improvements to the speech recognition system, SSTP support for the UUID standard, delete.txt whitelist mode, and other messy ideas on BTS) are being shelved, is it that I haven't clearly described the requirements or there are already existing alternative implementations, or are you just too busy to do this, or tired of updating the SSP? :meow_thinking:
It's not a push, just an inquiry, so there's no need to rush :blobok:In conversation permalink -
ぽな (C.Ponapalt) (ponapalt@ukadon.shillest.net)'s status on Friday, 23-Feb-2024 12:53:19 JST ぽな (C.Ponapalt) @steve02081504
- Since I am developing in my spare time, I would appreciate a step-by-step approach, preferably starting with a minimal specification.- In the case of the Origin specification for SSTP, the specification was unclear from what I read in the text. Any hints or specific description would be helpful for my consideration.
- Notification area icons tend to cause bugs when frequently updated due to the convenience of inter-process communication with Windows Explorer. For that reason, I really did not want to implement the current specification either.
In conversation permalink -
ぽな (C.Ponapalt) (ponapalt@ukadon.shillest.net)'s status on Friday, 23-Feb-2024 13:12:55 JST ぽな (C.Ponapalt) @steve02081504 Sorry for being so smug. To be honest, it would have been better if I had been more skilled.
In conversation permalink -
steve (steve02081504@ukadon.shillest.net)'s status on Friday, 23-Feb-2024 14:03:47 JST steve In conversation permalink
-