hegocre / hegocre/NextcloudPasswords

More advanced security

Open
#139 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Kotlin
Stars
83
Forks
7
Avg merge
1d 10h
Merged PRs (30d)
7

Description

Checklist
  • I have checked and there are no existing issues - open or closed - which request the same feature.
  • I have taken the time to fill in all the required details. I understand that the feature request will be dismissed otherwise.
  • This issue contains only one feature request.
Feature description

Add more optional advanced security features as (a) auto-logoff after a certain time and (b) use of two factors (fingerprint and code) to login.

Why do you want this feature?

Passwords include very sensitive data like access to your bank and email account.
(A) Just fingerprint to log in is not very secure but comfortable. On the other side, having a long code is secure, but uncomfortable. Easier would be if one can set up fingerprint AND a (short) code to login, or better, a passphrase.
(B) There should be an auto-logoff so that the app gets blocked after a certain time (and not only after the mobile phone logged off).
(C) If possible, certain passwords could be more secured like others. Bitwarden has such a functionality, where for certain passwords one has to enter the master passphrase again.

Additional information

Is there any mechanism that the app or mobile phone gets blocked after a certain number of false logins?

I hope I am not blind and one or some of these features are integrated already.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

The issue names no files, tests, or entry points. Start by reviewing the app's existing login, biometric authentication, session timeout, and password-lock behavior, then clarify which security feature is in scope. Done would require an agreed design and implementation criteria for the selected feature.

Written by the indexing model from the issue text.

Assessment

Tech stack
android, kotlin
Domain
authentication, mobile-dev, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.