-
Notifications
You must be signed in to change notification settings - Fork 860
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[GH-3074] Fix issues with media permissions on Linux and Jitsi Meet in embedded mode on all platforms #3331
base: master
Are you sure you want to change the base?
Conversation
… mode on all platforms
Hello @j0794, Thanks for your pull request! A Core Committer will review your pull request soon. For code contributions, you can learn more about the review process here. Per the Mattermost Contribution Guide, we need to add you to the list of approved contributors for the Mattermost project. Please help complete the Mattermost contribution license agreement? This is a standard procedure for many open source projects. Please let us know if you have any questions. We are very happy to have you join our growing community! If you're not yet a member, please consider joining our Contributors community channel to meet other contributors and discuss new opportunities with the core team. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Code looks okay to me, will defer to @enzowritescode for security review.
Thanks @j0794!
@j0794 can you break out the The other code allows for any subdomain to be arbitrarily trusted. In MM-60965 I outlined the security requirements to ensure there wouldn't be any issues with subdomain takeovers. The security requirements that I outlined will definitely take some work, but we don't want to sacrifice on security here. |
@@ -159,6 +154,28 @@ export class PermissionsManager extends JsonFileManager<PermissionsByOrigin> { | |||
return true; | |||
} | |||
|
|||
const preparsedURL = parseURL(url); |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Does not meet ticket requirements
Summary
systemPreferences.getMediaAccessStatus
, which is only implemented on Windows and macOS (https://www.electronjs.org/docs/latest/api/system-preferences#systempreferencesgetmediaaccessstatusmediatype-windows-macos)mattermost.example.com
will also propagate to Jitsi Meetjitsi.example.com
in embedded mode, or any other service with the address*.example.com
Ticket Link
Fixes #3074
https://mattermost.atlassian.net/browse/MM-60965
Checklist
npm run lint:js
for proper code formattingRun Desktop E2E Tests
Device Information
This PR was tested on: Ubuntu 22.04
Release Note