From 9b4187a216ab4038786b1a2fb6bfdbeee1f2eee2 Mon Sep 17 00:00:00 2001 From: Antoine James Tournepiche <26577763+AntoineJT@users.noreply.github.com> Date: Sat, 8 Aug 2020 15:52:43 +0200 Subject: [PATCH] Version 0.3.1 - Security fixes (#7) * Fixes security issues * Updates version number to 0.3.1 --- src/index.js | 3 ++- src/package.json | 2 +- src/public/index.html | 3 ++- src/public/preload.js | 5 +++++ src/public/thirdparty/widgetbot_html-embed.js | 6 ++++++ src/public/titlebar.js | 5 ++++- 6 files changed, 20 insertions(+), 4 deletions(-) create mode 100644 src/public/preload.js create mode 100644 src/public/thirdparty/widgetbot_html-embed.js diff --git a/src/index.js b/src/index.js index 66ce131..20ca116 100644 --- a/src/index.js +++ b/src/index.js @@ -9,7 +9,8 @@ function createWindow() { width: windowWidth, height: height, webPreferences: { - nodeIntegration: true + nodeIntegration: false, + preload: path.join(app.getAppPath(), 'public/preload.js') }, alwaysOnTop: true, frame: false, diff --git a/src/package.json b/src/package.json index 750b2f2..18f497b 100644 --- a/src/package.json +++ b/src/package.json @@ -1,6 +1,6 @@ { "name": "liveapp-mvp", - "version": "0.3.0", + "version": "0.3.1", "private": true, "description": "A frontend for the WidgetBot discord bot", "main": "index.js", diff --git a/src/public/index.html b/src/public/index.html index 6af7f0c..343ce88 100644 --- a/src/public/index.html +++ b/src/public/index.html @@ -3,6 +3,7 @@
+