Skip to content

fix(security): bind Meet node server to localhost and restrict token file to owner read#19597

Merged
teknium1 merged 1 commit into
mainfrom
hermes/hermes-8c54fd4a
May 4, 2026
Merged

fix(security): bind Meet node server to localhost and restrict token file to owner read#19597
teknium1 merged 1 commit into
mainfrom
hermes/hermes-8c54fd4a

Conversation

@teknium1
Copy link
Copy Markdown
Contributor

@teknium1 teknium1 commented May 4, 2026

Salvage of #19382 onto current main.\n\n## Summary\nGoogle Meet plugin's Node RPC server defaulted to (all interfaces) and wrote its token file with world-readable permissions. Tighten both: default host is , token file is chmod 600.\n\n## Validation\nManual review; scope is documentation/frontend/no-test.\n\nOriginal PR: #19382

@teknium1 teknium1 merged commit 2c7d7a9 into main May 4, 2026
9 of 10 checks passed
@teknium1 teknium1 deleted the hermes/hermes-8c54fd4a branch May 4, 2026 08:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants