You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Directory ~/.config/etesync-dav is mode 755 and the contents are 644, among which I counted at least one plaintext secret. Consider narrowing permissions and/or moving the sensitive data to the OS keychain.
The text was updated successfully, but these errors were encountered:
It was 755 before, it's now 700. It doesn't necessarily make a parctical
difference because in almost all cases the encompassing directory (the
user's homedir) will have strict enough permissions, but it doesn't
hurt either).
Partially addresses #118
Thanks for the report. I narrowed down the permissions, as suggested, though haven't made the changes to use the OS's keychain yet. It shouldn't be too hard though, using something like https://pypi.org/project/keyring/
On a related note, we are working on making some changes to how EteSync works which should also affect etesync-dav, so the rest of this ticket will probably not be addressed until that is done.
Directory ~/.config/etesync-dav is mode 755 and the contents are 644, among which I counted at least one plaintext secret. Consider narrowing permissions and/or moving the sensitive data to the OS keychain.
The text was updated successfully, but these errors were encountered: