Skip to content

Conversation

@guardrex
Copy link
Collaborator

@guardrex guardrex commented May 18, 2021

Addresses #19286

Courtesy ping for @blowdart 🎯 ... I'm working with Blazor security subject matter here. 😨😄

Internal Review Topic (links to section, See NOTE)

  • Multiple users have hit this problem where a heuristic scanner throws a false positive.
  • Not going to go with an INCLUDE for now. This is the only spot in Blazor docs that we need to cover this at this time. [Note tho that this is a wider problem across the repo, i.e. ... non-Blazor scenarios.]
  • Explains that an exception is required for the file, BUT calls out a strong warning on file security when creating exceptions AND briefly covers performing a checksum comparison ....... and calls out that even that doesn't guarantee 100% safety.

@guardrex guardrex requested a review from mkArtakMSFT May 18, 2021 13:51
Copy link
Contributor

@mkArtakMSFT mkArtakMSFT left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @guardrex !

@guardrex guardrex requested a review from HaoK May 18, 2021 18:09
@guardrex
Copy link
Collaborator Author

guardrex commented May 18, 2021

@HaoK ... See if I went too far 😅 with the NOTE and/or phrased it well. I don't want to leave devs hanging, but I don't want to get too deep in the weeds either .... and checksums aren't an iron-clad guarantee anyway.

@guardrex guardrex merged commit 891afef into main May 20, 2021
@guardrex guardrex deleted the guardrex-patch-1 branch May 20, 2021 10:01
@HaoK
Copy link
Member

HaoK commented May 20, 2021

Looks good as usual @guardrex !

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants