The worm is spreading...
237 karma · joined March 2, 2013
The worm is spreading...
I did that a couple of weeks ago and received an acknowledgment "Another request on Trusted Publishing option. Assigning to Product for review and further action." so this is a bit encouraging.
At least Maven dependencies don't execute scripts on install, but Maven plugins could have a big blast radius.
[1]https://news.hydroquebec.com/en/press-releases/2172/hydro-qu...
[1] https://jreleaser.org/guide/latest/index.html#_acknowledgmen...
To us, it's very very far from the quoted 0.04% which is to me very high. I had to deal with it 5-6 times in the past 10 years but of course that number will vary depending on the usage of your app and I'm not gonna venture and put a percentage on it.
That's most likely dependant on how the IT department handled the deprovisioning/provisioning of users in our Google Workspace, I unfortunately don't have the details for that.
If the `sub` changes, it's because it's not necessarily the same person so have a flow ready for that. It could be an employee left and came back, a domain change, an IT error that lead to a reprovisioning of the user, etc.
I also fail to see how the proposed solution of having a 'A unique user ID that doesn’t change over time' is different from the `sub` claim. However, the new ID associated to the domain could make sense to enforce a strong 'Everyone from the @domain.com has access' statement.
[1] https://developers.google.com/identity/gsi/web/reference/js-...
Looking at the result from the API of one extension I had installed[2], it lists metadata associated to the developer. I've tried to use the `chrome.management.get(id)` Chrome API and it does not return this information, and there does not seem to be a way to get the content of the manifest.json programatically. Therefore, to do the job of the extension as it is, it does need an external source.
[1]: https://github.com/classvsoftware/under-new-management/blob/...
[2]: https://api.extensionboost.com/v1/developer?extension_ids=gh...
Using "Run to cursor" is my favorite less known feature in debugging, it's really useful.
- Pause button (onjcmd=y)
- Java Exception Breakpoints with caught/uncaught option (onthrow/onuncaught)
Is it something that you plan on doing and document? Or is there an easy way I can ssh into the device and figure out on my own?
TIA!
EDIT : well, 1 minute later you answered part of my question here : https://news.ycombinator.com/item?id=37645339. How about ssh-ing?
I use BW for my personal use with my SO and 1P at work. I hit some errors in 1P that were crypting, stuff like "Failed to add this record" with no details, no help button, I had to fire up the chrome console for the extension to find out it was a 401 to our 1P portal. Very poor experience, probably related to our SSO setup but still.
Never had any weird issue like this with BW and I love the autofill shortcut and the absence of a popup when I access a password field like 1P.
So yea, YMMV as usual but definitely not miles ahead.
I had to call once for some backordered item and was pleasantly surprised that someone just picked up the phone, no automated system, no wait time.