Silvermoon logo

Configuration and security

Configuration

Silvermoon allows you to configure it via env variables.

Security

By default Silvermoon blocks usage of all these APIs:

But some of these APIs may be needed in applications, so we allow you to re-enable them via env variables.


SM_ENABLE_RISKY_OPEN="true" - Unblocks:

SM_ENABLE_VERY_RISKY_ADVANCED_FS="true" - Unblocks:

SM_ENABLE_RISKY_CODELOADING="true" - Unblocks:

SM_ENABLE_VERY_RISKY_SHELL="true" - Unblocks:

It’s a good practice not to enable these unless your app needs them. Otherwise leave them disabled.


Also, if you need to enable them, make sure you don’t take untrusted user input into them. Unless you are sure you have validated and cleaned it.

It is also a good practise to escape and clean all untrusted user input that you plan to display.

Whats next?