passman-webextension icon indicating copy to clipboard operation
passman-webextension copied to clipboard

Server credentials ignored for Nextcloud instances with active login sessions

Open brainchild0 opened this issue 2 years ago • 0 comments

The mechanism for connecting to a Nextcloud instance and account is rather clumsy.

The extension collects login information, including the passowrd, but only needs them if the user has no login session for the Nextcloud instance in the browser. If a session exists, the the extension ignores the credentials. Presumably, a failure may occur later if the credentials are invalid, since they were never verified against the user account of the server.

Even though the function of the extension is storing passwords, ideally the extension would never directly collect the password for a Nextcloud user account, instead using an existing session from the browser.

brainchild0 avatar Aug 24 '23 05:08 brainchild0