nextcloud / nextcloud/server

[sharebymail] Before password validation, clean pasted password with whitespace before/after and \

Open
#24,141 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

1. to develop enhancement feature: emails feature: sharing good first issue needs review
Dominant language
PHP
Stars
36.9k
Forks
5.2k
Avg merge
2d 3h
Merged PRs (30d)
713

Description

How to use GitHub
  • Please use the 👍 reaction to show that you are interested into the same feature.
  • Please don't comment if you have no relevant information to add. It's just extra noise for everyone subscribed to this issue.
  • Subscribe to receive notifications on status change and new comments.

Is your feature request related to a problem? Please describe.
Share by mail let user to share document with foreigner to get or send sensitive document protected by a password

Most of users copy/past password from the email they have received as it is faster and more convenient with automatic generated complex passwords.

However, the copy of selected text (password) leads most of the time to copy the invisible \n before or after, or a whitespace.

Describe the solution you'd like
The solution that could be applied is to erase \n and whitespace before/after of pasted text (password) just before to call the service.

Describe alternatives you've considered
No alternatives except to select again and again the text : most of people not succeding call back the nextcloud account owner for a new link thinking that the password in invalid.

Additional context
If the sender is familiar with nextcloud, most of the time the recipient (sometimes old peaple) are not at ease with computers

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the share-by-mail password validation entry point in the Nextcloud server code and review how pasted passwords are passed to the service. The change is done when leading and trailing whitespace or newline characters are removed before validation, while the existing password flow continues to work.

Written by the indexing model from the issue text.

Assessment

Tech stack
php
Domain
authentication
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.