laurent22 / joplin

Joplin - the privacy-focused note taking app with sync capabilities for Windows, macOS, Linux, Android and iOS.
https://joplinapp.org
Other
45k stars 4.89k forks source link

Security, Android: Authenticating with internal Webview when connecting to OneDrive #4578

Closed ghost closed 3 years ago

ghost commented 3 years ago

Currently Joplin for Android uses an internal webview to log in to OneDrive. This is undesirable for security reasons. https://auth0.com/blog/oauth-2-best-practices-for-native-apps/

You should open an external browser and manually copy-paste the code displayed after authentication into the Joplin app.

Environment

Joplin version: 1.7.5 Platform: Android

ghost commented 3 years ago

By using an external browser, the user can check the URL. This is useful as an anti-phishing measure.

stale[bot] commented 3 years ago

Hey there, it looks like there has been no activity on this issue recently. Has the issue been fixed, or does it still require the community's attention? This issue may be closed if no further activity occurs. You may comment on the issue and I will leave it open. Thank you for your contributions.

ghost commented 3 years ago

This issue has not been resolved.

stale[bot] commented 3 years ago

Hey there, it looks like there has been no activity on this issue recently. Has the issue been fixed, or does it still require the community's attention? This issue may be closed if no further activity occurs. You may comment on the issue and I will leave it open. Thank you for your contributions.

stale[bot] commented 3 years ago

Closing this issue after a prolonged period of inactivity. If this issue is still present in the latest release, please feel free to create a new issue with up-to-date information.