Draft: Turn off node integration #6945
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains:
A demonstration that nodeIntegration can be false (and contextIsolation can be true) when using RxDB in Electron.
It seems that one reason (hopefully the only reason) it is set to true today is because of the way node_modules are being imported in the renderer.js code. Adding webpack seems to let me turn off nodeIntegration and the example still works.
Can someone more familiar with the RxDB take a look and determine if this is correct?
Describe the problem you have without this PR
There are warnings in the Electron docs against enabling nodeIntegration and disabling contextIsolation: https://www.electronjs.org/docs/latest/tutorial/security