So yeah, um, this is not okay. It is not discoverable and could easily leak sensitive information. Auth credentials even, seriously? Also Chrome does this too. And it is preserved across `mv` to another filesystem.https://twitter.com/gynvael/status/1077671412847046657 …
-
-
This Tweet is unavailable.
-
To be fair, this varies *very* widely depending on the project and the bug :-)
End of conversation
-
-
-
Would it be worth it to write a script for recursively purging this information from files in your fs? Clean out any artifacts that may have persisted?
-
Yup, already thought of that. I'm going to wait to see what ends up being done upstream first.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
$ getfattr -d -m - test
user.xdg.origin.url="https://user:passwd@gynvael.coldwind.pl/"