Feature Request: Option to enforce PIN/Password instead of Biometrics for App-lock
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 55/100
- Tipo de issue
- Nueva funcionalidad
- Claridad
- Bastante claro
- Estado de actividad
- Tranquilo
- Área
- authentication, mobile-dev, security
Línea de trabajo
Comienza leyendo DeviceCredentialUtil.java y el flujo de configuración existente de App-lock. Comprueba cómo se invoca actualmente el aviso de KeyguardManager y, después, revisa la ruta solicitada de androidx.biometric.BiometricPrompt DEVICE_CREDENTIAL. La tarea estará completa cuando una opción de configuración de App-lock ofrezca el comportamiento predeterminado del sistema o un comportamiento solo con PIN/contraseña/patrón, y el modo restringido seleccionado omita la biometría.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Is your feature request related to a problem? Please describe.
Versions
Nextcloud v34.0.2 / Notes server app v6.0.1 / Notes for Android v34.0.0
Currently, when the "App-lock" feature is enabled, the app delegates authentication to the Android system via KeyguardManager (specifically in DeviceCredentialUtil.java). On most devices, if biometrics (fingerprint/face) are enrolled, the system prioritizes them. There is no in-app setting to restrict the authentication method to PIN/password only.
While Notes is not a password manager, users frequently store highly sensitive personal information, credentials, or private thoughts in their notes. From a privacy and security perspective, relying solely on biometrics can be a vulnerability. Biometrics are "something you are", which makes them susceptible to specific threat models, such as physical coercion (forced unlocking) or shared device environments (where a family member might have their fingerprint enrolled on the phone but shouldn't read your private notes).
PIN/Password security relies on "something you know", providing robust protection against these physical threats. Currently, the only workaround to achieve this is to completely delete all fingerprints from the Android system settings, which is highly inconvenient as it cripples the device's overall functionality.
Describe the solution you'd like
Add a setting under the App-lock configuration that allows the user to explicitly enforce the authentication method. For example:
System default (current behavior, allows biometrics)
PIN / Password / Pattern only (enforces device credential, strictly bypasses biometrics)
Note regarding issue #1188: I am aware that a previous request for a "separate locking mechanism" was declined. This proposal does not ask for a custom in-app PIN screen. It simply asks for a configuration flag to be passed to the existing system credential prompt to disable the biometric fallback.
Technical suggestion:
This could be cleanly implemented by migrating from the KeyguardManager to the modern androidx.biometric.BiometricPrompt. By using setAllowedAuthenticators(Authenticators.DEVICE_CREDENTIAL) without including BIOMETRIC_STRONG or BIOMETRIC_WEAK, the app will force the Android system to prompt for the device PIN/password/pattern, completely and intentionally bypassing any enrolled biometric sensors. This requires very minimal code changes in DeviceCredentialUtil.
Describe alternatives you've considered
Deleting all fingerprints/face data from Android system settings. This is unacceptable as a long-term solution because it affects the entire device and disables biometric unlock for all other apps and the system lock screen.
Additional context
Many privacy-focused note-taking apps offer this flexibility, recognizing that sensitive text data requires a higher threat-model defense than a standard phone screen lock. Implementing this will significantly boost the privacy posture of Nextcloud Notes for users who prefer "something you know" over "something you are".
- Lenguaje dominante
- Java
- Estrellas
- 1.1k
- Forks
- 168
- Merge medio
- 21 h 49 min
- PR fusionados (30 d)
- 29
Preparar el entorno
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de nextcloud/notes-android
-
enhancement
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
nextcloud/notes-android#3367 ·
Los mantenedores suelen responder en 1 día
-
0. Needs triage bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
nextcloud/notes-android#3353 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Sailfish OS native versionAbiertoenhancement
Dificultad 5/5 Más de una semana Aptitud para principiantes 20/100
nextcloud/notes-android#3360 · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
0. Needs triage bug
Dificultad 4/5 3-5 días Aptitud para principiantes 48/100
nextcloud/notes-android#3358 ·
Los mantenedores suelen responder en 1 día
-
Unable to mark as favoriteAbierto0. Needs triage bug
Dificultad 3/5 1-2 días Aptitud para principiantes 68/100
nextcloud/notes-android#3357 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
Todos los issues de nextcloud/notes-android
Issues similares
-
P2 testing
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
Los mantenedores suelen responder en 1 día
-
area/core kind/bug status/triage team/core-shared
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
checkstyle/checkstyle#21755 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
spring-projects/spring-integration#11495 ·
Los mantenedores suelen responder en 2 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
Los mantenedores suelen responder en 1 día