--
You received this message because you are subscribed to the Google Groups "meteor-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to meteor-talk...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/meteor-talk/fa9e4509-74b4-48af-ab10-671d38d05ccb%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "meteor-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to meteor-talk...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/meteor-talk/66d846fe-a952-4aea-8d18-36d2d81ab1f9%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/meteor-talk/CAJzNrTEw8ZpMN2%3DwoC3kyy_2J9SZETVUz1%3DFs4fiR%2BdemVmHTA%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/meteor-talk/CACXRNDHvZS0N8c%3D8M%2BD6cjNyY2YzO9WrTnq9Pk-emrm%2Bb1tf%3Dw%40mail.gmail.com.
I think that's a clever idea. With this, we'll still get the data.I'm just trying to see is there any issue with that? If now we are good to go.Still the bad user can trigger side-effects related to him, is that gonna make any issues?
On Wed Dec 03 2014 at 11:37:37 PM Emily Stark <em...@meteor.com> wrote:
Hey Arunoda,I had a simple idea for a way that I think fast-render could be fixed for the shared domain case. The problem to fix is that a user might end up with an "evil" login token as their cookie and their real login token in localStorage. So maybe before using any of the fast-render data in the HTTP response, fast-render (on the client) could just check if the login token in the cookie is equal to the token in localStorage. If the cookie is different than the value in localStorage, fast-render should assume that something fishy is going on and ignore the fast-render data.Do you think that would work? I'm not sure if it's a complete fix but I think at the least it makes the attack much harder to pull off.EmilyOn Thu, Nov 27, 2014 at 1:21 PM, Arunoda Susiripala <aru...@meteorhacks.com> wrote:
No it's still there. That's hard to fix. Only fix is to use a custom domain.
On 2014 නොවැ 28, සිකු at පෙ.ව. 12.15 Chris M <chris...@gmail.com> wrote:
Cool! Is it still true that Fast Render should not be used on *.meteor.com hosted apps due to a security issue? Or is that fixed in the new version?--
On Thursday, 27 November 2014 11:43:52 UTC-4, Arunoda Susiripala wrote:Hi,In last couple of weeks, I've almost re-write Fast Render and try to make it more stable. It was a success. Now we've Fast Render 2.0> If you are new to Fast Render, it helps to load and render your Meteor app very quickly. It's something similar to server side rendering. try this lesson on BulletProof Meteor to get started.Feature wise there is no major things. But now FR is more stable and work out of the box in most cases. I also removed some unused API and these are only APIs we've now.
Now, FR comes with a built in debugger where you can test whether Fast Render has been enabled or not.Let me know, how it works with your app.Cheers.
You received this message because you are subscribed to the Google Groups "meteor-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to meteor-talk+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/meteor-talk/fa9e4509-74b4-48af-ab10-671d38d05ccb%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "meteor-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to meteor-talk+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/meteor-talk/CAJzNrTEw8ZpMN2%3DwoC3kyy_2J9SZETVUz1%3DFs4fiR%2BdemVmHTA%40mail.gmail.com.--
You received this message because you are subscribed to the Google Groups "meteor-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to meteor-talk+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/meteor-talk/CAJzNrTFxD0zX6W0adccH%2B3Ph%3DckN8y3HFLM-quk%2BrUYQOvHHew%40mail.gmail.com.To unsubscribe from this group and stop receiving emails from it, send an email to meteor-talk...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/meteor-talk/CACXRNDHUtNv0vv-98_9R5zaSQKwW_PotU%2B6CC8bVedMPptEwwQ%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/meteor-talk/CAJzNrTEWGYO4fskKPVrfTS7wNGZheQ1DimLo55CT3yRRsf_8gA%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/meteor-talk/CACXRNDGrGmeqz4Vs-TvUQJEE_VmQ_fvk-XyxsPC6WP3H3oSxyg%40mail.gmail.com.
To unsubscribe from this group and stop receiving emails from it, send an email to meteor-talk...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/meteor-talk/fa9e4509-74b4-48af-ab10-671d38d05ccb%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "meteor-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to meteor-talk...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/meteor-talk/CAJzNrTEw8ZpMN2%3DwoC3kyy_2J9SZETVUz1%3DFs4fiR%2BdemVmHTA%40mail.gmail.com.
--
You received this message because you are subscribed to the Google Groups "meteor-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to meteor-talk...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/meteor-talk/CACXRNDHvZS0N8c%3D8M%2BD6cjNyY2YzO9WrTnq9Pk-emrm%2Bb1tf%3Dw%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "meteor-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to meteor-talk...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/meteor-talk/CAJzNrTFxD0zX6W0adccH%2B3Ph%3DckN8y3HFLM-quk%2BrUYQOvHHew%40mail.gmail.com.--
You received this message because you are subscribed to the Google Groups "meteor-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to meteor-talk...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/meteor-talk/CACXRNDHUtNv0vv-98_9R5zaSQKwW_PotU%2B6CC8bVedMPptEwwQ%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "meteor-talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to meteor-talk...@googlegroups.com.