In case the update server may deliver malicious content this would allow an adversary to inject arbitrary HTML into the response. So very bad stuff. While signing the response would be better and something we can also do in the future (considering the code signing work), this is already a good first start.remotes/origin/fix-delete-homeidr-on-userdelete
parent
d305412a35
commit
f3e9106864
Loading…
Reference in new issue