nextcloud / nextcloud/passman

Fuzzing

Open
#321 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement Security
Dominant language
JavaScript
Stars
823
Forks
117
Avg merge
1d 21h
Merged PRs (30d)
8

Description

Feature request

User type: N/A

User level: N/A

Description

As I see you are having heavy issues with #319, could you please do some fuzzing to automatically test such problems? Or some unit tests? This is really the worst kind of issue, which should never happen with a password manager.
When your password manager destroys your passwords you're lost.

Benefit / value

Increases security (& reliability here), see https://fuzzing-project.org/
I'm not sure whether one can fuzz PHP, but maybe do it when it is possible.

Risk / caveats

none, only executed internal

Sponsorship

Are you a developer willing to implement this feature?: no

Can you sponsor the development of this feature or do you know someone who can?: no


Want to back this issue? Post a bounty on it! We accept bounties via Bountysource.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing issue #319 and the fuzzing-project reference; no files, tests, or entry points are named here. The scope needs clarification before work can begin, including whether the goal is PHP fuzzing, unit tests, or both, and which password-destruction behavior must be covered.

Written by the indexing model from the issue text.

Assessment

Tech stack
php
Domain
security, testing
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.