-
@Erwin_vd_Ploeg @cedrickrier @Seb_Beau Where's the security problem? No data leak, no privilege escalation... Basically a possibility for DDoS by the system's users.
-
@Erwin_vd_Ploeg @cedrickrier @Seb_Beau I could write a server action that runs postgres intensive operations in a loop; then how do you filter attacks from legitimate operations?
-
@Erwin_vd_Ploeg @cedrickrier @Seb_Beau If you don't trust users with Settings access, who do you trust?
-
@Erwin_vd_Ploeg @cedrickrier @Seb_Beau (note that I didn't grep all safe_eval calls, just a "hot" opinion on a friday evening :p)