thunderbird / thunderbird/thunderbird-android

Consider making the QR code format an URL that some QR code scanners might directly open in Thunderbird

Open
#8,291 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

type: enhancement
Dominant language
Kotlin
Stars
14k
Forks
2.8k
Avg merge
3d 3h
Merged PRs (30d)
57

Description

Checklist
  • I have used the search function to see if someone else has already submitted the same bug report.
  • I will describe the problem with as much detail as possible.
App version

8.0b2

Where did you get the app from?

Google Play

Android version

14

Device model

Galaxy Tab a9+

Steps to reproduce
  1. Generate QR code in TB desktop. (make sure "include all accounts passwords" option is checked")
  2. Scan the QR code with device's Camera app.
  3. Open generated QR code with either K9 or Gmail app.
Expected behavior

I would expect that opening with any other applications (other than TB) should not be possible.

Actual behavior

Opening the generated QR code with either K9 or Gmail apps render the users information(passwords included) to be visible in a new mail template.
This issue is related to https://github.com/thunderbird/thunderbird-android/issues/8290

Logs

https://github.com/user-attachments/assets/7975f372-a24c-49a8-9ba1-3e46c747a475

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing related issue #8290 and reproducing the listed flow: generate the QR code in Thunderbird desktop with all account passwords included, scan it on Android, and open it in K-9 or Gmail. Done should prevent the generated account information and passwords from being exposed when another application handles the scanned content, with the behavior verified on the reported Android setup.

Written by the indexing model from the issue text.

Assessment

Tech stack
android, kotlin
Domain
mobile, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.