[sharebymail] Before password validation, clean pasted password with whitespace before/after and \
Nobody has claimed this yet.
- Dominant language
- PHP
- Stars
- 36.9k
- Forks
- 5.2k
- Avg merge
- 2d 3h
- Merged PRs (30d)
- 713
Description
How to use GitHub
- Please use the 👍 reaction to show that you are interested into the same feature.
- Please don't comment if you have no relevant information to add. It's just extra noise for everyone subscribed to this issue.
- Subscribe to receive notifications on status change and new comments.
Is your feature request related to a problem? Please describe.
Share by mail let user to share document with foreigner to get or send sensitive document protected by a password
Most of users copy/past password from the email they have received as it is faster and more convenient with automatic generated complex passwords.
However, the copy of selected text (password) leads most of the time to copy the invisible \n before or after, or a whitespace.
Describe the solution you'd like
The solution that could be applied is to erase \n and whitespace before/after of pasted text (password) just before to call the service.
Describe alternatives you've considered
No alternatives except to select again and again the text : most of people not succeding call back the nextcloud account owner for a new link thinking that the password in invalid.
Additional context
If the sender is familiar with nextcloud, most of the time the recipient (sometimes old peaple) are not at ease with computers
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by locating the share-by-mail password validation entry point in the Nextcloud server code and review how pasted passwords are passed to the service. The change is done when leading and trailing whitespace or newline characters are removed before validation, while the existing password flow continues to work.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- php
- Domain
- authentication
- Issue type
- Feature
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100