Announcements

Help Wizard

Step 1

NEXT STEP

Forcing spotify to use in-app login

Forcing spotify to use in-app login

I am trying to write a SELinux policy for spotify where I encountered a problem: for Spotify to use browser-login Spotify will have to have self:capability sys_admin, which is, clearly, a terrible permission to grant. But Spotify is forcing me to use browser-login. How do I force Spotify client to resort back to in-app login?

Reply
2 Replies

Also in another post the dev mentioned that browser-login is a security feature - literally how?? Like why would logging in through a webbrowser and callback enhance security? From my point of view that just make it worst cause there is a larger attack surface and logging through browser require a HECK ton more permissions, including allowing spotify to access the browsers' files, ptrace attach and the worst of all: sys_admin capability.

When I say a "heck bunch more permissions” I MEAN IT

winslowsem_0-1704540498165.png

 

Suggested posts

Let's introduce ourselves!

Hey there you,   Yeah, you! 😁   Welcome - we're glad you joined the Spotify Community!   While you here, let's have a fun game and get…

ModeratorStaff / Moderator/ 4 years ago  in Social & Random