-
Notifications
You must be signed in to change notification settings - Fork 8
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Autotype of credentials without permission #146
Comments
Hello there! |
Nope, I was logged in on Portainer for at least 15 min. and then created a backup which I wanted to be pw-protected. I would be fine with showing this example in a anydesk session. |
I just thought of something... could you maybe disable and re-enable the extension when you're logged in? I'd be curious to see if you get another credential request the moment you re-enable it :) |
Yep, got annother request.... |
BTW, this is what it looks like, I only log out, everything else happens without touching anything: 2022-12-04.14-40-32.mp4 |
The mooltipass logs me in automatically without confirmation too. I thought this was the expected behaviour in simple mode. Maybe i read this in the manual. I think it mentioned that confirmation is requested only in advanced mode. |
I wonder if this is due to the fact that with this website, the extension is somehow always submitting the password, and therefore the 5seconds buffer never times-out... |
Don't know if it's relevant, but force reload (Firefox Ctrl + F5) forces the extention to show a new request on the miniBLE |
is this still happening? this should have been fixed a while back |
Hey, sadly yes... Currently I'm using
and the problem persists. Feel free to ask if you need further details |
Expected behavior
Working on several websites the mooltipass detects credential fields and asks before entering credentials
Actual behavior
The mooltipass enters credentials without permission if unlocked
Step by step guide to reproduce the problem
Can't be given here, because most of the sites with this behavior are confidential.
(Based on Portainer CE or own web development of the company)
In Portainer this problem shows if on enables the password protection of the backup, in this moment the mooltipass enters the password saved for the user in this field
Firmware Version
AUX MCU version: 0.70
Main MCU version: 0.80
Bundle version: 8
Moolticute Version - If Involved
0.55.0
Operating System
Mention if you are using either:
platform independent (tested on Win7, Win 10 and Linux Mint
Mooltipass Extension
https://github.com/mooltipass/extension/issues
-> Read this, but since the mooltipass sends the credentials without asking, I guess it's a firmware problem
The text was updated successfully, but these errors were encountered: