Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SPFx solutions as a spyware #1893

Merged
merged 6 commits into from
Aug 6, 2024
Merged

SPFx solutions as a spyware #1893

merged 6 commits into from
Aug 6, 2024

Conversation

kkazala
Copy link
Contributor

@kkazala kkazala commented Aug 5, 2024

Category

  • Content fix
  • New article
  • Example checked item (delete this line)

Contents of the Pull Request

SharePoint solutions may read all user's SharePoint data and user's auth token (2 lines of code for this one) and send it to external APIs without administrator's or user's consent.
It's impossible to disable it or control it in any way.

We are typically focusing on Microsoft Graph, but I feel like nobody realizes (or talks about) the risks associated with these solutions being practically full trust code. And as much as I love the PnP Samples, I would like more users, administrators, governance teams implement more robust security audits.
It's time we talk about it openly =)

@LuiseFreese LuiseFreese merged commit 813a2d8 into pnp:main Aug 6, 2024
2 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants