Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

No verification asked in changing passcode #1233

Open
haran2248 opened this issue Feb 14, 2021 · 2 comments
Open

No verification asked in changing passcode #1233

haran2248 opened this issue Feb 14, 2021 · 2 comments

Comments

@haran2248
Copy link
Contributor

haran2248 commented Feb 14, 2021

Summary:

Summarize your issue here.

When the user tries to change the passcode the app should ask the user to enter the existing passcode to verify.

Steps to reproduce:
How can we reproduce again the issue?

Go to EditProfile and click Change Passcode

Expected behavior:

What did you expect the app to do?

The app should ask me to enter the existing passcode before changing the passcode to a new one
Observed behavior:

What did you see instead? Describe your issue in detail here.

The App doesnt ask me to verify the existing passcode so if a new user finds the app open he may change the passcode for his
advantage.

Device and Android version:

What make and model device (e.g., Samsung Galaxy S3) did you encounter this on? What Android
version (e.g., Android 4.0 Ice Cream Sandwich or Android 6.0 Marshmallow) are you running? Is it
the stock
version from the manufacturer or a custom ROM?

SM-M013F

Screenshots:

WhatsApp Image 2021-02-15 at 02 24 57

WhatsApp Image 2021-02-15 at 02 24 36

Can be created by pressing the Volume Down and Power Button at the same time on Android 4.0 and higher.

@Prashant830
Copy link
Contributor

let's suppose Any person forgotten their existing passcode and he wants to create a new passcode?? and he also logged in the app??
@devansh-299 please check it..

@devansh-299
Copy link
Collaborator

fix#1233:Password verification before changing password added #1234

No @Prashant830, adding another step of security before allowing user to make any changes to passcode or credentials makes sense. Coming to the scenario you put forward, ideally such cases should be handled via fallbacks like email/phone verification like we do for account passwords

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants