security: the renderer can start a shell and edit instructions without a native confirmation
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 48/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- electron, typescript
Research direction
Start by reading src/main/index.ts:350-356 for terminal IPC and index.ts:279 for instruction edits, then inspect settings_confirm.ts to understand how autoConfirmed is persisted. The issue proposes native confirmation or a main-process-visible user gesture for terminal startup, confirmation for instruction edits, and a fresh prompt whenever Auto mode is enabled. Done means all three paths require the described native user confirmation; runtime IPC validation is tracked separately in #32.
Written by the indexing model from the issue text.
Description
Found in the 2026-10-07 security audit. No XSS path was found, so this is defense in depth.
Problem
The renderer is effectively fully trusted:
terminal:start/terminal:writegive any renderer script a real, unsandboxed shell (src/main/index.ts:350-356).project:set-instructionswrites text into the system prompt without native confirmation (index.ts:279).settings_confirm.tsremembersautoConfirmed, so the renderer can turn Auto mode back on later in the same session without a new dialog.
Runtime IPC argument validation is tracked in #32.
Fix
- Start the terminal only after a user gesture the main process can see (for example a native menu item or an accelerator), or confirm the first
terminal:startof each project natively. - Confirm instruction edits, or show them in a native dialog.
- Ask again whenever Auto mode is turned on.
- Dominant language
- TypeScript
- Stars
- 2
- Forks
- 2
- Avg merge
- 5h 28m
- Merged PRs (30d)
- 24
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from PierrunoYT/patch
-
enhancement platform: windows priority: low severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
PierrunoYT/patch#198 ·
Maintainers usually reply within 1 day
-
priority: medium security severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
PierrunoYT/patch#66 ·
Maintainers usually reply within 1 day
-
bug platform: macos priority: low severity: low tests
Difficulty 3/5 1-2 days Newbie friendliness 56/100
PierrunoYT/patch#218 · 1 comment ·
Maintainers usually reply within 1 day
-
enhancement priority: low security severity: low
Difficulty 4/5 3-5 days Newbie friendliness 55/100
PierrunoYT/patch#211 · 2 comments ·
Maintainers usually reply within 1 day
-
enhancement platform: windows priority: low security severity: low
Difficulty 4/5 3-5 days Newbie friendliness 55/100
PierrunoYT/patch#207 ·
Maintainers usually reply within 1 day
All issues in PierrunoYT/patch
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Maintainers usually reply within 1 day
-
Difficulty 1/5 1-3 hours Newbie friendliness 84/100
answerLoops/answerLoops#345 ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 82/100
siyuan-note/siyuan#20313 ·
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
LanternOps/breeze#8254 ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 1-3 hours Newbie friendliness 82/100
gofish-graphics/gofish-graphics#1084 ·
Maintainers usually reply within 1 day