AFFiNE icon indicating copy to clipboard operation
AFFiNE copied to clipboard

Potential security breach of desktop app​

Open pengx17 opened this issue 2 years ago • 2 comments

What happened?

In the current workflow, a bad guy could make a fake electron app, register the same scheme like affine:// and intercept the user token.

Distribution version

macOS x64 (Intel)

What browsers are you seeing the problem on if you're using web version?

No response

Relevant log output

No response

Anything else?

No response

Are you willing to submit a PR?

  • [ ] Yes I'd like to help by submitting a PR!

pengx17 avatar Oct 02 '23 08:10 pengx17

You good boy against the bad guy

Peng Xiao @.***>于2023年10月2日 周一01:33写道:

What happened?

In the current workflow, a bad guy could make a fake electron app, register the same scheme like affine:// and intercept the user token. Distribution version

macOS x64 (Intel) What browsers are you seeing the problem on if you're using web version?

No response Relevant log output

No response Anything else?

No response Are you willing to submit a PR?

  • Yes I'd like to help by submitting a PR!

— Reply to this email directly, view it on GitHub https://github.com/toeverything/AFFiNE/issues/4557, or unsubscribe https://github.com/notifications/unsubscribe-auth/AS5AYR6CD2L4DQBCFWIREYTX5J37JANCNFSM6AAAAAA5PCIQ2U . You are receiving this because you are subscribed to this thread.Message ID: @.***>

HeJiachen-PM avatar Oct 02 '23 09:10 HeJiachen-PM

Issue Status: 💡 Open

💡 Open

We want to implement the fix or feature in the near future. We can’t promise it will appear in the next public release, but it’s on our short list.

This is an automatic reply by the bot.

affine-issue-bot[bot] avatar Mar 09 '24 11:03 affine-issue-bot[bot]

planned in new auth system

forehalo avatar Aug 09 '24 08:08 forehalo