Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove CSM screenshot API #6932

Closed
wants to merge 1 commit into from

Conversation

Projects
None yet
5 participants
@red-001
Copy link
Contributor

commented Jan 19, 2018

Can be easily abused to fill all the free space on a players hard drive. Could possibly be re-added later with rate-limiting for use only by user approved mods, but right now this just makes implementing server provided mods needlessly complicated.

Remove CSM screenshot API
reverted from commit 19960e2 (* [CSM] add screenshot api lua)
@paramat

This comment has been minimized.

Copy link
Member

commented Jan 19, 2018

👍

@sfan5 sfan5 added the Trivial label Jan 19, 2018

@nerzhul

This comment has been minimized.

Copy link
Member

commented Jan 20, 2018

instead of removing the call (which is abusive without limits), i prefer implement a rate limit + a client setting to allow this API (toggled to false by default), it permits client to prevent rogue mods to fill all space, but if a user wants, it can be useful

@sfan5

This comment has been minimized.

Copy link
Member

commented Jan 20, 2018

Alternatively, a whitelist similar to "insecure environment" can be added to allow individual mods to use features like these.

@paramat

This comment has been minimized.

Copy link
Member

commented Jan 23, 2018

0425c6b

Almost no justification for this feature, especially for server-sent CSM. CSM features cannot be justified by client-provided CSM alone. In the interest of security, developing and testing server-sent, CSM needs to be kept as as simple as possible, especially at the moment.

@paramat paramat closed this Jan 23, 2018

@red-001 red-001 deleted the red-001:revent_take_screenshot branch Jan 23, 2018

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.