💾 Archived View for rawtext.club › ~sloum › geminilist › 001699.gmi captured on 2020-09-24 at 01:42:28. Gemini links have been rewritten to link to archived content

View Raw

More Information

-=-=-=-=-=-=-

<-- back to the mailing list

CSRF in Gemini

solderpunk solderpunk at SDF.ORG

Mon Jun 15 15:30:07 BST 2020

- - - - - - - - - - - - - - - - - - - 

On Mon, Jun 15, 2020 at 04:09:47PM +0200, Francesco Gazzetta wrote:

I'm starting this thread to brainstorm ideas about the last point.

Thanks for getting this conversation started!

It's perhaps a little bit tedious for users, but the simplest solution Ican think of for things like this is a convention that all requestswhich trigger side-effects (like comments, etc.) must be made with aclient certificate, because that will make it very clear to the userthat something is happening and no surprises are possible.

I strongly suspect that completely preventing this kind of thing will beimpossible if we simultaneously insist on a simple protocol and africtionless user experience - in which case, everybody knows which onewill be prioritised. :) But if we can somehow pull off both at oncethat will be best.

Cheers,Solderpunk