Dimillian / Dimillian/IceCubesApp
Bug: DeepL client secret is available in plain-text from the macOS app
Nobody has claimed this yet.
- Dominant language
- Swift
- Stars
- 7.1k
- Forks
- 720
- PR merge metrics
- No merged PRs in 30d
Description
Environment:
- OS: macOS 14.2.1 (23C71)
- IceCubesApp version: Version 1.9.18 (2199)
Description
IceCubesApp uses the file Secret.plist to store the Client-Secret used for DeepL API access but this file is bundled using the xml1 plist format which is human readable XML as shown in the following screenshot:
I know no-one likes to have to store client secrets in their application but in this case it would at least be worth to use the binary1 format to make the key less easy to extract.
All it would take is an XCode build step that runs plutil -convert binary1 Secret.plist.
No changes to the code or anything else required (in fact you can convert the current Secret.plist in the MAS version and it works all the same).
Related Issues
- none I could find
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the bundled Secret.plist in the IceCubesApp macOS build and review the Xcode build steps. Add the reported plutil conversion to binary1, then verify that the packaged app contains the binary plist and that DeepL API access still works.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- swift
- Domain
- build-system, security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 55/100