Skip to content

Conversation

@digitarald
Copy link
Contributor

Updates the network documentation to clarify that only the specific vscode.dev/redirect endpoint is used as a fallback for authentication flows, rather than the entire vscode.dev domain.

This addresses security concerns from customers who were worried about allowing the entire vscode.dev domain (which has access to local file systems and extensions).

Fixes https://github.com/microsoft/vscode-internalbacklog/issues/6244

Tyriar
Tyriar previously approved these changes Nov 8, 2025
@Tyriar Tyriar dismissed their stale review November 8, 2025 05:26

Tyler left a relevant comment

Copy link
Member

@bpasero bpasero left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah Tyler left a comment.

@ntrogh ntrogh merged commit 5a7d20f into main Nov 10, 2025
4 checks passed
@ntrogh ntrogh deleted the docs/clarify-vscode-dev-auth-fallback branch November 10, 2025 08:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants