-
Task
-
Resolution: Can't Do
-
Minor
-
None
-
None
-
40
-
False
-
None
-
False
-
Testable
-
?
-
RHELBU-2233 - Cockpit security enhancements
-
?
-
?
-
-
Develop a simple cockpit-like application built on a secure frame model, as a proof of concept for how we might do this in Cockpit. The goal would be to have a simple application build with a toplevel frame that's capable of logging in via websocket and routing messages between security-isolated frames.
If successful, this would become the technical underpinnings of the next major technological development in Cockpit, along with solving a longstanding and extremely visible security issue (no isolation between separate hosts in a Cockpit session —- every host can execute arbitrary code on every other host).