WebAPI/Security/OpenWebApp: Difference between revisions

Jump to navigation Jump to search
Line 46: Line 46:


Potential mitigations:  
Potential mitigations:  
* Only apps having high privileges can use mgmt.getAll() to see cross-stores installs. [fabrice]
* Only certified apps can use mgmt.getAll() to see cross-stores installs. [Fabrice]
* Allow user control over updates
* Warn when downloading large updates over cellular
* Warn when downloading large updates over cellular
Confirmed users
717

edits

Navigation menu