thunderbird / thunderbird/thunderbird-android

Improve experience with autofill services

Open
#3,646 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

type: enhancement
Dominant language
Kotlin
Stars
14k
Forks
2.8k
Avg merge
3d 3h
Merged PRs (30d)
57

Description

I have both K-9 Mail and Keepass2Android installed. After entering the Account Settings...Fetching mail...Incoming Server settings but not changing anything, I pressed the back button. At this point Keepass2Android offered to save my password. If I accept, the password is transferred into Keepass2Android to save.

The interface of K-9 Mail on the settings screen only shows dots in the password field. Also, the password may not be highlighted and copied using the normal Android interface. So, I assume that the intent is to not expose saved passwords.

Security bug: The password is exposed.

I do not think this is a problem with Keepass2Android since the purpose of that software as a password manager is to save passwords from other applications. Though, I would not expect it to be able to fetch previously entered passwords.

Expected behavior

Nothing. The password should not be exposed unless it is being freshly entered.

Actual behavior

The previously saved password was found by Keepass2Android.

Steps to reproduce
  1. Ensure that Keepass2Android (or potentially other password managers) are installed and properly configured
  2. Enter a K-9 server settings page that has a previously saved password
  3. Press the back button
Environment

K-9 Mail version: 5.600

Android version: 8.0.0

Account type (IMAP, POP3, WebDAV/Exchange): IMAP

Keepass2Android version: 1.05d

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing the issue on Android 8.0 with K-9 Mail 5.600 and Keepass2Android 1.05d, then inspect the account server-settings password field and the back-navigation behavior. Done means a previously saved password is not exposed to an autofill service, while a freshly entered password retains the expected behavior.

Written by the indexing model from the issue text.

Assessment

Tech stack
android, kotlin
Domain
mobile-dev, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.