Automattic / Automattic/simplenote-ios

[Widgets] Possible to see any note content with passcode active

Open
#1,445 5 comments 0 reactions 0 assignees View on GitHub
[feature] Widgets bug
Dominant language
Swift
Stars
2.1k
Forks
297
Avg merge
13h 25m
Merged PRs (30d)
6

Description

I'm not exactly sure this is a bug. By adding widgets, the user already takes a step back from their notes privacy.

### Expected
Again, it's hard to say it's definitely expected. This is something that wasn't an option before.

If the user has a passcode active, previously it meant that notes can't be viewed without knowing the password. Now it's possible with widgets.

### Observed
`Note` widget will allow to change the note selected for display without asking for passcode (first seconds are just showing the app has a passcode active):

https://user-images.githubusercontent.com/73365754/134319491-82b7fa69-f6d8-45cc-a034-a571e6d75f8d.MP4

### Reproduced
1. Activate passcode in the app
2. Add a `Note` widget
3. Kill the app to make sure passcode will be required from now on
4. You can change the note selected for display in `Note` widget (and see the note), which bypasses the need to enter a passcode to see the note.

Make|Model|iOS Version|App Version
-|-|-|-
iPhone|XR|14.7.1|4.45.0.0

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the reported behavior in the Note widget with the app passcode enabled, following the four steps in the issue. Compare what is displayed and selectable before and after the app requires the passcode; done means protected note content is not viewable or changeable through the widget without the passcode.

Written by the indexing model from the issue text.

Assessment

Tech stack
ios, swift
Domain
authentication, mobile-dev, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.