nextcloud / nextcloud/notes-ios

Authentication fully broken since 4.4.0

Open
#142 17 comments 11 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
Swift
Stars
73
Forks
22
PR merge metrics
No merged PRs in 30d

Description

How to use GitHub
  • Please use the 👍 reaction to show that you are affected by the same issue.
  • Please don't comment if you have no relevant information to add. It's just extra noise for everyone subscribed to this issue.
  • Subscribe to receive notifications on status change and new comments.

Steps to reproduce
  1. Update to 4.4.0
  2. Try to use the app which fails
  3. Log off
  4. Try to log in again
Expected behaviour

Login is possible

Actual behaviour

After the update...
image
...no connection was possible:
image

I decided to log off. When trying to login, nothing works. Webauth fails completely, username and password ends at or after 2FA step with an empty authentication screen again. I managed to login once but then I was logged in regularly, the authentication of the app which is the target is not achieved. Nextcloud also complained about an unsupported browser. It's just a total mess.

Server configuration

Web server: Nginx

Database: Maria

PHP version: 8.3

Nextcloud version: Latest stable

List of activated apps
If you have access to your command line run e.g.:
sudo -u www-data php occ app:list
from within your Nextcloud installation folder
Nextcloud configuration
If you have access to your command line run e.g.:
sudo -u www-data php occ config:list system
from within your Nextcloud installation folder
Browser

Browser name: App!

Browser version: /

Operating system: Linux

Browser log
Insert your browser log here, this could for example include:
a) The javascript console log
b) The network log
c) ...

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No source file, test, or entry point is identified. First reproduce the failure after updating to 4.4.0, including username/password, 2FA, and WebAuth flows, and inspect the authentication behavior and available logs. Done means users can log in and authenticate the target app successfully after logging out.

Written by the indexing model from the issue text.

Assessment

Tech stack
swift
Domain
authentication, mobile
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.