Replies: 2 comments
-
|
Disabling outright would also remove another information leak, regarding a timing attack to work out whether there was a cache hit for a given domain or not. You could set the icon cache to time very low, but that won't actually clean up the expired cache entries I believe. |
Beta Was this translation helpful? Give feedback.
-
|
@mknj i suggest to use icon redirect then instead of local cached. Lines 132 to 143 in 08f0de7 Encrypting the filename only will not work, because you can still open the file, or read metadata. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
My Vaultwarden instance is used by some friends and i was surprised to find internal_server_name.miss entries of my friends employees in my icon_cache directory. There are also some other site entries that i really don't want to know about.
Would it be possible to disable the icon_cache completely or add an option to have an encrypted per user icon cache?
Beta Was this translation helpful? Give feedback.
All reactions