Sync .obsidian configuration #65
Labels
No labels
area:docs
area:identity
area:ops
area:plugin
area:server
channel:community
channel:direct
channel:owned
channel:press
channel:social
e2ee-constrained
gate:at-ga
gate:pre-ga
marketing
parity
relay:absent
relay:planned
relay:requested
relay:supported
risk:additive
risk:contract
risk:none
usability
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
Nectenda/nectenda#65
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Part of #37.
What Relay does
Not shipped. Their issue #37 is open and labelled "tracking" with no ETA.
What we do today
Refused by design.
blob-policy.ts:30ignores any path with a dot-segment, andthe comment says why:
listFileswalks the vault index which already excludesthem, and the rule is stated explicitly "so that nobody later reaches for
adapter.list(), which does see them, and starts syncing the plugin's ownconfiguration".
Why this is riskier for us than for them
Syncing
.obsidianmeans syncing our owndata.json, which holds foldermappings and, where there is no OS credential store, secrets. A loop where the
plugin syncs its own configuration between devices is a footgun with sharp edges,
and
docs/security-model.mdalready notes any plugin can read what we store.If it is ever built it must be an explicit allowlist of config files — themes,
snippets, hotkeys — never the whole directory, and never our own.
Risk
risk:nonemechanically; a real security-model question.Moved to the Vikunja board as NEC-42: https://projectron.nerchure.com/tasks/42