-
-
Notifications
You must be signed in to change notification settings - Fork 372
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add widgets for home screen #1193
Comments
How should the login with pin or biometrics work with a widget? |
This seems like a major security vulnerability, no? Unless the widget just has the name of the app and no token, and clicking it opens the app straight to that entry to either reveal, or copy, or both. But if you don't open the app, you wouldn't be able to enforce the password protection. And just constantly having your OTP on your home screen doesn't seem like a great idea. |
I don't think so, there are other apps capable of doing this, if you agree to create a widget you are aware that they will always be shown. If you click on the widget it opens the app but obviously it asks you for your fingerprint if the protection is active. |
Regardless, why work to add a feature that could be a very blatant security flaw? Even if the user fully understands the risk, that doesn't eliminate the risk. The only way I could imagine it being done securely is if it opens the app straight to the selected token (which would allow for the proper authentication), but at that point it's not far from a home screen shortcut. |
It's a free choice, anyway what are you talking about when you say "very blatant security flaw" ? |
The only way I could see this work is to have a "hidden" code as a widget on your launcher which will show the biometrics prompt whenever you click it. After that the code will be visible in the home screen. If this feature gets implemented this is the only way I can see it happening. |
Add widgets feature which show an X (settable) number of otps without opening the app.
The text was updated successfully, but these errors were encountered: