beemdevelopment / Aegis

A free, secure and open source app for Android to manage your 2-step verification tokens.
https://getaegis.app
GNU General Public License v3.0
8.92k stars 375 forks source link

Reminder of manual passcode can be skipped #1396

Closed PsySc0rpi0n closed 3 months ago

PsySc0rpi0n commented 3 months ago

Version

3.0.1

Source

F-Droid

Vault encryption

Yes (with biometric unlock)

Device

Samsung Galaxy S7 Edge and Samsung Galaxy S21 5G

Android version

8.0.0 and 14

ROM

OEM

Steps to reproduce

When the app asks you to input the manual passcode as a way of the user not forget it, just hit cancel and then click the Biometric option again to bring the pop back.

What do you expect to happen?

Not to be possible to cancel or at least the app to insist in the passcode

What happens instead?

The Biometric pop up comes up after cancelling the manual input of the passcode

Log

No response

michaelschattgen commented 3 months ago

Thanks for your report. This is done intentionally as we don't want to lock out our users, especially in emergency cases where they need to get access to their vault as quick as possible. We've updated/revised this user experience multiple times and we figured there is no 'best' way. In the past we got a lot of emails and bug reports from people thinking the 'auto biometrics' feature was broken or glitching out because they were unaware of the password reminder. I'm all ears for a better solution but simply refraining the user from using biometrics won't do it.