# \#security

**URL:** https://discourse.threejs.org/tag/security/9.md

[Latest](https://discourse.threejs.org/latest.md) · [Categories](https://discourse.threejs.org/categories.md) · [Tags](https://discourse.threejs.org/tags.md)

---

## [On-Call Drive - neon-city security driving game in Three.js](https://discourse.threejs.org/t/on-call-drive-neon-city-security-driving-game-in-three-js/93865)

<div class="topic-metadata">

**Author:** [@securitycipher](https://discourse.threejs.org/u/securitycipher)\
**Replies:** 0\
**Last updated:** [August 28, 2026, 7:11pm UTC](https://discourse.threejs.org/t/on-call-drive-neon-city-security-driving-game-in-three-js/93865 "2026-08-28T19:11:10Z")

</div>

On-Call Drive is a browser driving game where you play as the on-call security engineer. You cruise a neon synthwave city in third person, follow the minimap to job beacons, press E to jack into a terminal, and clear sho…

---

## [Is there a way to not allow the user to publicly download the 3d model and texture files that i'm showing?](https://discourse.threejs.org/t/is-there-a-way-to-not-allow-the-user-to-publicly-download-the-3d-model-and-texture-files-that-im-showing/434)

<div class="topic-metadata">

**Author:** [@atylerrice](https://discourse.threejs.org/u/atylerrice)\
**Replies:** 20\
**Last updated:** [August 4, 2024, 5:44am UTC](https://discourse.threejs.org/t/is-there-a-way-to-not-allow-the-user-to-publicly-download-the-3d-model-and-texture-files-that-im-showing/434 "2024-08-04T05:44:44Z")

</div>

I’m building a marketplace for 3d assets and I need to have a 3d viewer that allows the user to view the 3d models before downloading, but I need the files to still be protected to where they can’t be downloaded.

---

## [How do I protect exposed webGL buffers?](https://discourse.threejs.org/t/how-do-i-protect-exposed-webgl-buffers/446)

<div class="topic-metadata">

**Author:** [@INF1N1T](https://discourse.threejs.org/u/INF1N1T)\
**Replies:** 9\
**Last updated:** [February 28, 2024, 5:44am UTC](https://discourse.threejs.org/t/how-do-i-protect-exposed-webgl-buffers/446 "2024-02-28T05:44:42Z")

</div>

This question continues the security discussion from Let’s say, you have protected your files from being directly downloaded (by encryption or another technic), there is still the possibility for someone to get the obj…

---

## [STL file loader - Security](https://discourse.threejs.org/t/stl-file-loader-security/16406)

<div class="topic-metadata">

**Author:** [@fidel62](https://discourse.threejs.org/u/fidel62)\
**Replies:** 4\
**Last updated:** [February 12, 2024, 4:31am UTC](https://discourse.threejs.org/t/stl-file-loader-security/16406 "2024-02-12T04:31:57Z")

</div>

I have a website where I use STL loader. There is any way how somebody can download the STL file?? If there is a way can I put any kind of security.? Please help

---

## [Looking for a way to edit a GLB file as a string in runtime](https://discourse.threejs.org/t/looking-for-a-way-to-edit-a-glb-file-as-a-string-in-runtime/37745)

<div class="topic-metadata">

**Author:** [@Suraj\_VIBROMECH](https://discourse.threejs.org/u/Suraj_VIBROMECH)\
**Replies:** 29\
**Last updated:** [May 9, 2022, 9:57am UTC](https://discourse.threejs.org/t/looking-for-a-way-to-edit-a-glb-file-as-a-string-in-runtime/37745 "2022-05-09T09:57:29Z")

</div>

Good Day, I have a usecase where I have edited a GLB model using a hex editor. I have added some ciphers into the file and Saved it. In Threejs code, I am looking for a way to decode the cipher by performing a edit on …

---

## [How to set Content Security Policy for useGLTFs](https://discourse.threejs.org/t/how-to-set-content-security-policy-for-usegltfs/51398)

<div class="topic-metadata">

**Author:** [@Ling\_Tao](https://discourse.threejs.org/u/Ling_Tao)\
**Replies:** 10\
**Last updated:** [September 12, 2023, 2:50pm UTC](https://discourse.threejs.org/t/how-to-set-content-security-policy-for-usegltfs/51398 "2023-09-12T14:50:25Z")

</div>

Hi guys, I want to load a 3d model from aws S3 bucket using useGLTF, it is working well when I run it in local. The code I use is: const url = \`api/v1/test/models/${name}\`; const { nodes, materials } = useGLTF(url)…

---

## [How import map can be safe?](https://discourse.threejs.org/t/how-import-map-can-be-safe/46534)

<div class="topic-metadata">

**Author:** [@8Observer8](https://discourse.threejs.org/u/8Observer8)\
**Replies:** 5\
**Last updated:** [January 5, 2023, 12:14pm UTC](https://discourse.threejs.org/t/how-import-map-can-be-safe/46534 "2023-01-05T12:14:16Z")

</div>

You suggest using import maps here: three.js docs I have an interesting question from QTX on Discord: I wonder how import map can be safe? After all if we have js file in node.modules we still have copy of our desired…

---

## [If I show a model, is it possible that a malicious client edits the js and loads a model that I don't want to show?](https://discourse.threejs.org/t/if-i-show-a-model-is-it-possible-that-a-malicious-client-edits-the-js-and-loads-a-model-that-i-dont-want-to-show/41312)

<div class="topic-metadata">

**Author:** [@Francisco\_Tacoronte](https://discourse.threejs.org/u/Francisco_Tacoronte)\
**Replies:** 1\
**Last updated:** [August 11, 2022, 10:38pm UTC](https://discourse.threejs.org/t/if-i-show-a-model-is-it-possible-that-a-malicious-client-edits-the-js-and-loads-a-model-that-i-dont-want-to-show/41312 "2022-08-11T22:38:40Z")

</div>

I am creating a web page where each user can view their models. I save all the models in the same folder page and depending on the user I load one model or another. By editing the code, could a client load the model of a…

---

## [Secure sanitize GLSL user input?](https://discourse.threejs.org/t/secure-sanitize-glsl-user-input/38583)

<div class="topic-metadata">

**Author:** [@Fennec](https://discourse.threejs.org/u/Fennec)\
**Replies:** 2\
**Last updated:** [May 27, 2022, 5:17pm UTC](https://discourse.threejs.org/t/secure-sanitize-glsl-user-input/38583 "2022-05-27T17:17:20Z")

</div>

When dealing with forms and data storage/redistribution the general motto is “Never trust user data”, I can easily find ways to sanitize HTML/CSS even how to deal with files (images, videos, PDF …) before storage and I w…

---

## [Restrict model to download through network tab](https://discourse.threejs.org/t/restrict-model-to-download-through-network-tab/30652)

<div class="topic-metadata">

**Author:** [@RAUMIK\_RANA](https://discourse.threejs.org/u/RAUMIK_RANA)\
**Replies:** 3\
**Last updated:** [October 11, 2021, 12:07am UTC](https://discourse.threejs.org/t/restrict-model-to-download-through-network-tab/30652 "2021-10-11T00:07:07Z")

</div>

I want to restrict model to download from network tab from developer menu as shown in video

---

## [Denial of service vulnerability?](https://discourse.threejs.org/t/denial-of-service-vulnerability/24004)

<div class="topic-metadata">

**Author:** [@marquizzo](https://discourse.threejs.org/u/marquizzo)\
**Replies:** 2\
**Last updated:** [March 3, 2021, 8:42pm UTC](https://discourse.threejs.org/t/denial-of-service-vulnerability/24004 "2021-03-03T20:42:06Z")

</div>

I got a notification on a few of my older repos that three.js has a Denial of Service vulnerability. What does this mean? Does this put my sites at risk of a DDoS attack? I see that it was fixed in Jan so I can fix it by…

---

## [Advices to encrypt buffers?](https://discourse.threejs.org/t/advices-to-encrypt-buffers/21761)

<div class="topic-metadata">

**Author:** [@felixmariotto](https://discourse.threejs.org/u/felixmariotto)\
**Replies:** 10\
**Last updated:** [December 21, 2020, 10:17pm UTC](https://discourse.threejs.org/t/advices-to-encrypt-buffers/21761 "2020-12-21T22:17:34Z")

</div>

Hi folks, I’m looking for a solution to obfuscate geometry data as much as possible. First off I precise that I’m not looking for a perfect solution, as I know it does not exist. I’m only looking for methods of making …

---

## [TextureLoader doesn't work on iphone only (security ?)](https://discourse.threejs.org/t/textureloader-doesnt-work-on-iphone-only-security/18614)

<div class="topic-metadata">

**Author:** [@antelius](https://discourse.threejs.org/u/antelius)\
**Replies:** 2\
**Last updated:** [September 11, 2020, 6:24pm UTC](https://discourse.threejs.org/t/textureloader-doesnt-work-on-iphone-only-security/18614 "2020-09-11T18:24:45Z")

</div>

Hi all, i work on a web app with shiro as securitye. The behavior is simple. The app ask a user/pwd on load the first page and after, it work for all file and image during the session. Now, i want to include three js pa…

---

## [How To Prevent Ripping](https://discourse.threejs.org/t/how-to-prevent-ripping/12473)

<div class="topic-metadata">

**Author:** [@Tacticious](https://discourse.threejs.org/u/Tacticious)\
**Replies:** 6\
**Last updated:** [February 2, 2020, 6:26pm UTC](https://discourse.threejs.org/t/how-to-prevent-ripping/12473 "2020-02-02T18:26:25Z")

</div>

I apologize if this is a stupid question. I’ve only recently stumbled upon Three.js – props btw, this is an amazing project. I’ve got a client who is curious about making an animation viewer. I’m wondering how others ha…

---

## [Is it possible for people to download or take my 3d models without my consent?](https://discourse.threejs.org/t/is-it-possible-for-people-to-download-or-take-my-3d-models-without-my-consent/10716)

<div class="topic-metadata">

**Author:** [@CesarMR](https://discourse.threejs.org/u/CesarMR)\
**Replies:** 2\
**Last updated:** [November 9, 2019, 6:27am UTC](https://discourse.threejs.org/t/is-it-possible-for-people-to-download-or-take-my-3d-models-without-my-consent/10716 "2019-11-09T06:27:08Z")

</div>

Hi everyone, basic question, I was wondering if putting 3D models and geometries could make the models to be downloaded or copied (without consent)?
