new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

Electron · API · all subjects

app/security

17 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

app.isSecureKeyboardEntryEnabled() method macOS

Returns a boolean indicating whether Secure Keyboard Entry is enabled. By default this API returns false.

app.setSecureKeyboardEntryEnabled(enabled) method macOS

The app.setSecureKeyboardEntryEnabled(enabled) method accepts a boolean parameter to enable or disable Secure Keyboard Entry. When enabled, important information such as passwords and sensitive data can be prevented from being intercepted by other processes. Enable Secure Keyboard Entry only when needed and disable it when no longer needed.

app.setClientCertRequestPasswordHandler(handler) method Linux

The app.setClientCertRequestPasswordHandler(handler) method is available on Linux and accepts a handler function. The handler is called when a password is needed to unlock a client certificate for a hostname. The handler receives a clientCertRequestParams object with properties: hostname (string, the hostname of the site requiring a client certificate), tokenName (string, the token or slot name of the cryptographic device), isRetry (boolean, whether there have been previous failed attempts at prompting the password). The handler returns Promise<string> that resolves with the password.

app.setClientCertRequestPasswordHandler() example with password prompt

Example code showing how to set a client cert request password handler: const { app } = require('electron') async function passwordPromptUI (text) { return new Promise((resolve, reject) => { // display UI to prompt user for password // ... resolve('the password') }) } app.setClientCertRequestPasswordHandler(async ({ hostname, tokenName, isRetry }) => { const text = `Please sign in to ${tokenName} to authenticate to ${hostname} with your certificate` const password = await passwordPromptUI(text) return password })

ClipboardItem cannot be subclassed

Electron's built-in ClipboardItem class cannot be subclassed in user code.

ClipboardItem security warning on untrusted data

Do not construct a ClipboardItem directly from an untrusted object, such as a payload received from a renderer over IPC. MIME keys are a capability surface: 'text/uri-list' places real file references on the OS clipboard allowing files to be pasted into other applications, and 'electron application/osclipboard;format=...' and 'web'-prefixed formats write raw platform data. Validate and allowlist the MIME types and the shape of each payload before building a ClipboardItem from data you did not author.

CertificatePrincipal object structure

The CertificatePrincipal object has the following fields: commonName (string), organizations (string[]), organizationUnits (string[]), locality (string), state (string), and country (string). Each field represents a component of a certificate principal.

Certificate Object structure and properties

The Certificate Object has the following properties: data (string, PEM encoded data), issuer (CertificatePrincipal, issuer principal), issuerName (string, issuer's Common Name), issuerCert (Certificate, issuer certificate if not self-signed), subject (CertificatePrincipal, subject principal), subjectName (string, subject's Common Name), serialNumber (string, hex value represented as string), validStart (number, start date of the certificate being valid in seconds), validExpiry (number, end date of the certificate being valid in seconds), and fingerprint (string, fingerprint of the certificate).

CustomScheme Object structure

The CustomScheme Object contains a scheme property (string) and an optional privileges object. The scheme property specifies custom schemes to be registered with options.

CustomScheme privileges properties

The privileges object in CustomScheme contains the following optional boolean properties, all defaulting to false unless otherwise specified: standard (default false), secure (default false), bypassCSP (default false), allowServiceWorkers (default false), supportFetchAPI (default false), corsEnabled (default false), stream (default false), codeCache (default false, and only works when standard is also set to true), and allowExtensions (default false, allows Chrome extensions on pages served over this protocol).

FilesystemPermissionRequest object structure

FilesystemPermissionRequest extends PermissionRequest and contains the following optional properties: filePath (string) - the path of the fileSystem request; isDirectory (boolean) - whether the fileSystem request is a directory; fileAccessType (string) - the access type of the fileSystem request, which can be either 'writable' or 'readable'.

WebPreferences webSecurity option

The webSecurity boolean option (optional) controls whether the same-origin policy is enforced. When set to false, it disables the same-origin policy and sets allowRunningInsecureContent to true if that option has not been explicitly set by the user. The default is true.

WebPreferences allowRunningInsecureContent option

The allowRunningInsecureContent boolean option (optional) allows an HTTPS page to run JavaScript, CSS or plugins from HTTP URLs. The default is false.

WebPreferences contextIsolation option

The contextIsolation boolean option (optional) controls whether Electron APIs and the specified preload script run in a separate JavaScript context. The default is true. When enabled, the preload script context has access only to its own dedicated document and window globals, and its own set of JavaScript builtins (Array, Object, JSON, etc.), which are invisible to loaded content. The Electron API is only available in the preload script, not the loaded page. This option uses the same technique as Chrome Content Scripts and should be used when loading potentially untrusted remote content.

webUtils context isolation requirement

If you want to call the webUtils API from a renderer process with context isolation enabled, you must place the API call in your preload script and expose it using the contextBridge API.

webview disablewebsecurity attribute

The disablewebsecurity attribute is a boolean. When this attribute is present, the guest page will have web security disabled. Web security is enabled by default. This value can only be modified before the first navigation.

Content Security Policy in Electron HTML

A basic Electron web page should include Content-Security-Policy meta tags. Example: <meta http-equiv="Content-Security-Policy" content="default-src 'self'; script-src 'self'"> to restrict script execution to self-hosted scripts.

Give your agent this brain