element-hq / element-hq/element-android

Required secure backup can be skipped

Open
#6,939 0 comments 0 reactions 0 assignees View on GitHub
A-E2EE-SAS-Verification O-Uncommon S-Major Security T-Defect Team: Crypto
Dominant language
Kotlin
Stars
3.7k
Forks
917
PR merge metrics
No merged PRs in 30d

Description

### Steps to reproduce

Backend with `secure_backup_required = true`

When verifying a device using the browser you can click on 'no' when asked to verifiy that 2 checkmarks exists. At that point the phone will show a message that the verification failed and that you can try again. If at that point you decide to kill the app and re-open you will not be prompted with a blocking verification request

1. Login and setup backup on the web
2. Login to the android app
3. Accept verification on the web
4. Scan the code on the phone
5. On the web when it asks if the checkmarks match I click no
6. On the phone the `verification failed` message will be displayed
7. Kill and reopen app

### Outcome

#### What did you expect?
Secure backup dialog to be shown again

#### What happened instead?
Secure backup dialog is not present anymore and you use app

### Your phone model

All

### Operating system version

All

### Application version and app store

1.4.26

### Homeserver

_No response_

### Will you send logs?

No

### Are you willing to provide a PR?

Yes

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.