• Pantherina@feddit.de
    link
    fedilink
    arrow-up
    1
    ·
    1 year ago

    A ton of extensions are executing scripts, but this is generally behind a warning.

    This REALLY has to change guys, and for that the getnewstuff backend must become better.

    For example Dolphin extensions are still downloaded to some random download location that is not actually used.

    And the packaging of addons is extremely random too.

    • Klara@lemmy.blahaj.zone
      link
      fedilink
      arrow-up
      0
      ·
      1 year ago

      This is different from the Wayland security model, as Wayland restricts the ability for clients to modify and read from other clients arbitrarily. This is an extension to a Wayland compositor, and as all extensions do, it contains code which runs on your system. Any code, unless sandboxed, can access your filesystem no matter if it’s run under Wayland, X11, or no windowing system at all for that matter.

      • Zamundaaa@discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        1 year ago

        It is not related to Wayland or the compositor in any way. This is a plasmashell extension.

        Similar caveats do apply to KWin scripts and effects though