Skip to content

Work without "access your data for all websites" permission #157

@Zocker1999NET

Description

@Zocker1999NET

Describe the problem

I want to reduce the security impact from any hijacked add-on as good as possible, solely based on the principle of least privilege.

I do mainly two things with this add-on:

  • remote-control Kodi with the integrated remote (to play videos Kodi has already access to)
  • send concrete links to Kodi (right-click, send to Kodi)

With my current understanding (feel free to correct me), I see no reason for CastKodi to have the "access your data for all websites" permission, at least in my case.
(I assume this feature is required for the buttons in the top row & not for explicitly casting a link via right-click.)

Describe the solution you'd like

Allow using the add-on without this permission when the user acknowledges the reduced feature set.
I.e. make the following warning able to be skipped:

Image

Environment

  • Cast Kodi version: 7.13.0
  • Browser version: 142.0.1
  • Kodi version: N/A
  • Kodi add-on version (if appropriate): N/A

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions