-
-
Notifications
You must be signed in to change notification settings - Fork 4.7k
Closed
Labels
0. Needs triagePending check for reproducibility or if it fits our roadmapPending check for reproducibility or if it fits our roadmapbugsecurity
Description
The steps to share a folder and and a password are automatic and this could lead to big security issue if associated to browser's autofill feature.
Steps to reproduce
- Save your login credentials in your browser
- Login
- Create a folder
- Share it and enter an email (put you email as a test)
- You should receive an email saying that your cloud shared a folder with you
- On yout cloud page, In the email field, the email has been replaced by your login
- Click the 3 dots to "protect with a password"
- You receive an email with you login password
Expected behaviour
Shouldn't send password without confirmation, button or else
Actual behaviour
Sends the login password because of the autofill feature of the browser
Server configuration
Operating system:
Linux debian
Web server:
Apache 2
Database:
Mysql
PHP version:
7.2
Nextcloud version: (see Nextcloud admin page)
13.0.2
Metadata
Metadata
Assignees
Labels
0. Needs triagePending check for reproducibility or if it fits our roadmapPending check for reproducibility or if it fits our roadmapbugsecurity