guardianproject / guardianproject/haven
Remote access .onion service not showing any event details / media (pictures, videos, sounds)
- Dominant language
- Java
- Stars
- 6.8k
- Forks
- 752
- PR merge metrics
- No merged PRs in 30d
Description
I strongly assume there's something wrong with the remote access, as I'm not seeing any of the pictures / videos / sound recordings from the app. I mostly see empty pages. Is this just not implemented, yet? I couldn't find any documentation that would show what it's supposed to look like.
Basic HW/SW info:
- Nexus 5 Hammerhead (https://wiki.lineageos.org/devices/hammerhead)
- DivestOS 16 (https://divestos.org/index.php?page=devices&base=LineageOS)
- Latest Orbot and Haven from FDroid (can look up version numbers if needed)
- V3 Onion service (created in Orbot and then Onion URL/port pasted into Haven ... Haven auto-generated a V2 Onion, which is deprecated)
What the website says:
> **Remote Access**
> All event logs and captured media can be remotely accessed through a Tor Onion Service. Haven must be configured as an Onion Service and requires the device to also have Orbot: Tor for Android installed and running.
What I see when I access the Hidden Service:

I tried setting the security level to "Standard" (lowest level) in TorBrowser and enabled JS manually, but that didn't change anything. The content that's served just doesn't include anything of substance:

```html
Haven
Events
Jul 14, 2021 19:20:14
29 triggered events
Jul 15, 2021 16:16:43
62 triggered events
Jul 15, 2021 17:30:54
277 triggered events
Jul 18, 2021 00:41:36
12 triggered events
```
After clicking the first entry:

```html
Haven
Event: Jul 14, 2021 19:20:14
```
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reproducing the Remote Access flow through the configured Onion Service and compare the Events page with the event detail page. Check whether event details and captured media are served for the reported event entries. Done means the remote pages expose the expected event information and pictures, videos, or sounds when available.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- android, java
- Domain
- mobile-dev, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 30/100