marius-wieschollek / passwords

A simple, yet feature rich password manager for Nextcloud
GNU Affero General Public License v3.0
215 stars 45 forks source link

You can share passwords to disabled users #533

Closed majkinetor closed 2 years ago

majkinetor commented 2 years ago

One of those 2 users is disabled:

image

Furthermore, its impossible to see which user is which as nothing is shown. This doesnt happen in files, where user email is shown and you can click the avatar icon to show profile and other details:

image

Since I couldn't see which one to use, I shared password to both users and disabled one also got the email (which shouldn't be possible and is IMO serious security issue).