l-shihao / pe

0 stars 0 forks source link

Login Screen Motive in DG may overstate #5

Open l-shihao opened 2 years ago

l-shihao commented 2 years ago

The motive for this online login security feature is to protect the sensitive data, displayed in TeamContact 24/7 App, from undesirable exposure to unwanted and or public viewing.

If it says for the purpose of switching different users would be alright, but the addressbook.json file is plain text on the disk, don't see the login screen can offer any protection to the exposing of data.

image.png

nus-pe-bot commented 2 years ago

Team's Response

The documentation is correct. The purpose of this login screen is designed to prevent unwanted over the shoulder or public viewing only when the App is running without a user in attendance. For the securing of addressbook.json design, it is explained in the Securing the data file section of the UG.

Items for the Tester to Verify

:question: Issue response

Team chose [response.Rejected]

Reason for disagreement: [replace this with your explanation]