Don't configure DonateUrl and NY externally at server-side #9870

Open
opened 2024-12-15 20:34:49 +00:00 by pastk · 0 comments
Member

There are two settings configured externally at the metaserver side:

  • "DonateUrl" - an url to the donation page (defaults to a language-specific https://organicmaps.app/donate/); if absent in the external config then in-app donation buttons are disabled (in the hamburger menu and is the about screen)
  • "NY" - new year time! displays the x-mas tree icon and controls donations buttons also

What are use cases for configuring the DonateUrl at server side?
It seems like an unnecessary security risk - if the metaserver gets compromised then an attacker could easily divert all donations.
A simple setting to switch donation buttons on/off should be enough.

Also not clear why the "NY" setting controls donations also?
The x-mas tree could be displayed based on the current date.
So this setting seems redundant.

There are two settings configured externally at the [metaserver](https://github.com/organicmaps/meta) side: - "DonateUrl" - an url to the donation page (defaults to a language-specific https://organicmaps.app/donate/); if absent in the external config then in-app donation buttons are disabled (in the hamburger menu and is the about screen) - "NY" - new year time! displays the x-mas tree icon and controls donations buttons also What are use cases for configuring the DonateUrl at server side? It seems like an unnecessary security risk - if the metaserver gets compromised then an attacker could easily divert all donations. A simple setting to switch donation buttons on/off should be enough. Also not clear why the "NY" setting controls donations also? The x-mas tree could be displayed based on the current date. So this setting seems redundant.
This repo is archived. You cannot comment on issues.
No labels
Accessibility
Accessibility
Address
Address
Android
Android
Android Auto
Android Auto
Android Automotive (AAOS)
Android Automotive (AAOS)
API
API
AppGallery
AppGallery
AppStore
AppStore
Battery and Performance
Battery and Performance
Blocker
Blocker
Bookmarks and Tracks
Bookmarks and Tracks
Borders
Borders
Bug
Bug
Build
Build
CarPlay
CarPlay
Classificator
Classificator
Community
Community
Core
Core
CrashReports
CrashReports
Cycling
Cycling
Desktop
Desktop
DevEx
DevEx
DevOps
DevOps
dev_sandbox
dev_sandbox
Directions
Directions
Documentation
Documentation
Downloader
Downloader
Drape
Drape
Driving
Driving
Duplicate
Duplicate
Editor
Editor
Elevation
Elevation
Enhancement
Enhancement
Epic
Epic
External Map Datasets
External Map Datasets
F-Droid
F-Droid
Fonts
Fonts
Frequently User Reported
Frequently User Reported
Fund
Fund
Generator
Generator
Good first issue
Good first issue
Google Play
Google Play
GPS
GPS
GSoC
GSoC
iCloud
iCloud
Icons
Icons
iOS
iOS
Legal
Legal
Linux Desktop
Linux Desktop
Linux packaging
Linux packaging
Linux Phone
Linux Phone
Mac OS
Mac OS
Map Data
Map Data
Metro
Metro
Navigation
Navigation
Need Feedback
Need Feedback
Night Mode
Night Mode
NLnet 2024-06-281
NLnet 2024-06-281
No Feature Parity
No Feature Parity
Opening Hours
Opening Hours
Outdoors
Outdoors
POI Info
POI Info
Privacy
Privacy
Public Transport
Public Transport
Raw Idea
Raw Idea
Refactoring
Refactoring
Regional
Regional
Regression
Regression
Releases
Releases
RoboTest
RoboTest
Route Planning
Route Planning
Routing
Routing
Ruler
Ruler
Search
Search
Security
Security
Styles
Styles
Tests
Tests
Track Recording
Track Recording
Translations
Translations
TTS
TTS
UI
UI
UX
UX
Walk Navigation
Walk Navigation
Watches
Watches
Web
Web
Wikipedia
Wikipedia
Windows
Windows
Won't fix
Won't fix
World Map
World Map
No milestone
No project
No assignees
1 participant
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: organicmaps/organicmaps-tmp#9870
No description provided.