nextcloud / passman-webextension

Webextension for the Passman Nextcloud app. Also offers browser extension & Android app.
https://passman.cc
GNU Affero General Public License v3.0
115 stars 43 forks source link

Blank Master Password bypasses prompt #320

Open shinenelson opened 4 years ago

shinenelson commented 4 years ago
### Steps to reproduce 1. Install the Extension 2. Login to Passman vault 3. Set a Master Password 4. Click the lock icon to lock the extension 5. Click 'Unlock' button ### Expected behaviour

The extension should either report 'Invalid master password' or 'Empty passwords are not permitted'

Actual behaviour

The pop over overlay goes away. Though the extension is not unlocked. Passwords are not searchable at least. Nor does the extension get triggered on relevant website form fields.

Configuration

Operating system: Ubuntu 18.04.4 LTS

Browser: Firefox 75.0

Extensions that might cause interference: Highly doubt it, but I do have the extension for Nextcloud Passwords and LessPass

Passman version: 2.3.5

Extension version: 2.1.1

Nextcloud version: 18.0.0

Browser log

Other than [Passman extension] Stopping, vault key not set in the javascript console, nothing relevant.

--- Want to back this issue? **[Post a bounty on it!](https://www.bountysource.com/issues/90591874-blank-master-password-bypasses-prompt?utm_campaign=plugin&utm_content=tracker%2F52236699&utm_medium=issues&utm_source=github)** We accept bounties via [Bountysource](https://www.bountysource.com/?utm_campaign=plugin&utm_content=tracker%2F52236699&utm_medium=issues&utm_source=github).