owncloud / twofactor_totp

🔑 Second factor TOTP (Google Authenticator) provider for ownCloud
GNU Affero General Public License v3.0
9 stars 9 forks source link

TOTP not mendetory if browser plugin uses app passcode #276

Open dj4oC opened 1 year ago

dj4oC commented 1 year ago

-- transferd -- As a user I use TOTP on my local oC 10 installation.

I did follow https://owncloud.com/news/how-to-sync-passwords-with-buttercup/ to store my passwords in a buttercup database.

Additional I am using chrome browser extension of buttercup (https://chrome.google.com/webstore/detail/buttercup/heflipieckodmcppbnembejjmabajjjj?hl=en-GB)

To set up buttercup browser extension I need to create an app passcode to bypass by TOTP.

After restarting my computer, buttercup chrome extension opens with a tab asking for buttercup database master password to open buttercup database.

Next step: open a tab and go to oC web client. Unfortunately I will not been asked for my password and totp-token. Since this does not happen with deactivated browser extension I assume access is grated using buttercap app passcode. IMHO this is quite dangerous since TOTP is passed by.