Running documents
Security
The security properties a reader provides, and what IDOP does not promise.
The full model is on the security model page and in §17 of the specification. In short:
What a reader guarantees
- Validation before execution. Nothing runs until the whole package has passed every check. One failure refuses the file.
- Isolation. Document code runs in an opaque-origin sandbox with no network, no access to the reader’s storage, cookies or interface, and no access to other documents.
- Declared, granted network access. Only exact origins and methods declared in the manifest, only after consent.
- Credentials stay with the reader. Keys are injected on the reader’s side and never visible to the document.
- Explicit saves. The file changes only when the user saves, as a validated new revision.
What it does not guarantee
- Who made a document. Metadata is self-declared; there are no signatures in 1.0.
- That content is true. A document can display anything.
- That granted access is harmless. A document you allow to use a service can use it within the declared limits.
- That a shared file stays private. Anyone who can open a document can copy it.
Reporting a vulnerability
Write to security@idoplabs.com. See the security page for our disclosure policy.