alist icon indicating copy to clipboard operation
alist copied to clipboard

Clear Storage and Transmission of sensitive informations for Alist v3.2.1 and below

Open BrandenXia opened this issue 2 years ago • 2 comments

Please make sure of the following things

  • [X] I have read the documentation.
  • [X] I'm sure there are no duplicate issues or discussions.
  • [X] I'm sure this feature is not implemented.
  • [X] I'm sure it's a reasonable and popular requirement.

Description of the feature / 需求描述

There are clear Storage and Transmission of sensitive informations for Alist v3.2.1 and below, matching CWE-256, CWE-312, CWE-319, and CWE-922. Hide sensitive informations in local cookie storage and transmission so that it wouldn't be easily found.

Suggested solution / 实现思路

Use hash algorithm or other encryption algorithm to hide sensitive informations.

Additional context / 附件

No response

BrandenXia avatar Oct 25 '22 02:10 BrandenXia

Thanks for opening your first issue here! Be sure to follow the issue template!

welcome[bot] avatar Oct 25 '22 02:10 welcome[bot]

Hello, this issue has been inactive for more than 30 days and will be closed if inactive for another 30 days.

github-actions[bot] avatar Dec 01 '22 00:12 github-actions[bot]

Hello @, this issue was closed due to inactive more than 60 days. You can reopen or recreate it if you think it should continue.

github-actions[bot] avatar Jan 01 '23 00:01 github-actions[bot]