Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

bad (no) treatment of wrong password #241

Open
lmamane opened this issue Jan 30, 2023 · 0 comments
Open

bad (no) treatment of wrong password #241

lmamane opened this issue Jan 30, 2023 · 0 comments

Comments

@lmamane
Copy link

lmamane commented Jan 30, 2023

Steps to reproduce

  1. Setup a new account in the Android Nextcloud SMS app
  2. put a wrong password

Expected behaviour

On setup, an error message. Let the user save this account only on second explicit confirmation after the error message, something like "force save with wrong password?"

On sync, an error notification and exponential back-off of retries.

Actual behaviour

The Android Nextcloud SMS app hammers the server with failed logins and gets the IP address "that colour that shall not be named publicly or a lighter shade of it"-listed at the server.

Server configuration

Nextcloud version: 19.0.13

PHP version: 7.3.31

Webserver: Apache

HTTPS: yes

Client configuration

Android version: 13 (LineageOS 20)

Android device: OnePlus 9 Pro

Nextcloud SMS app version: 2.0.5

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant