mozilla-mobile / focus-android

⚠️ Firefox Focus (Android) moved to a new repository. It is now developed and maintained as part of: https://github.com/mozilla-mobile/firefox-android
https://github.com/mozilla-mobile/firefox-android
Mozilla Public License 2.0
2.11k stars 711 forks source link

Some fingerprint protection bugs #4466

Closed TomekS2 closed 2 years ago

TomekS2 commented 4 years ago
  1. When I try open link I can skip fingerprint check

This isn't occure when I open by share, only by link. When I click share everything is ok.

1. browser must be fingerprint protected
2. open any web site(eg. github.com)
3. minimalize browser
4. check if fingerprint protection exist
5. open LINK eg. click on link in contact app
6. now browser skip fingerprint protection

demonstrated here: https://mega.nz/#!23xRiYQI !snHur0ZYX5k0SxXijKHQblTIWVn2ntlZ0fa8rGow3JY

  1. some popups is visible from under fingerprint protection layer layer

I found 2 popups visible from under fingerprint protection layer and resend information popup don't disappear after click new sesion:

resend information and download poup

obraz obraz

and after new sesion

obraz

  1. settins screen is not protected properly

when I am on settings screen fingerprint protection doesn't occure after minimalization, but after return to browser view appear, but from settings I can disable fingerprint protection

https://mega.nz/#!ZGgGQAyL !rWzyb1wSzsNZd_4bOSGAW6G7tLzKhbqR6ndSKL-E5UI

  1. sound is playing when fingerprint protection is present

when i listening music and i minimalize browser and i return to browser i can hear sound from under protection

https://mega.nz/#!cChCWACK !2mlwpZGuwfE-mummAkBgbbiCHzjaflPnOjdgrC8-mmk

All tested on lastest f-droid firefox-klar relase (8.0.15) on android emulator version Q

lobontiumira commented 2 years ago

I can confirm some behaviors from this issue on the latest Focus Nightly build 99.0a1 (360630511 with GV 99.0a1-20220303094735) with Oppo Find X3 Lite (Android 11):

lobontiumira commented 2 years ago

Reproducible with Samsung Galaxy Note 8 (Android 9) on Beta 99.0.0-beta.1.

lobontiumira commented 2 years ago

I was able to reproduce the following on the Focus Beta 100.0.0-beta.1 with Samsung Galaxy Note 8 (Android 9):

lobontiumira commented 2 years ago

I was able to reproduce the following on the Focus Beta 103.0.0-beta.1 with Oppo Reno 6 (Android 12):

iorgamgabriel commented 2 years ago

@lobontiumira this should be retested FingerPrint behaviour was changes , now we have biometrics

lobontiumira commented 2 years ago

Tested on the latest Focus Nightly build 104.0a1 from 7/22 with Oppo Reno 6 (Android 12), and Samsung Galaxy Note 8 (Android 9). Indeed, the fingerprint behavior has been changed. The fingerprint protection cannot be skipped even when a page is shared from a different app. However, closing Focus, then opening Focus again, displays briefly the homepage - but #5068 is opened for this issue.

I'll close this ticket.