I’m in instance like this it would be great if the client could explicitly not allow the nsecBunker to vice more permissions than it needs. Otherwise users are an accidental button click away from giving more permissions that would ever be needed!

Reply to this note

Please Login to reply.

Discussion

Yeah, that’s exactly what I’m saying:

You could authorize zapplepay to ONLY sign zap requests

All other signatures, encryption, decryption are rejected.

And the admin panel wouldn’t even show an approve all kinds event?

Doesn’t it normally allow you to approve a single kind or everything? Or does that everything request have to be defined by the client request?

Right now it does but you’ll be able to say “never” for other events 👍