Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

False negative: AndroidInsecureLocalAuthentication.ql

Open
#21,526 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
55/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Quiet
Tech stack
java
Domain
security

Research direction

Start with Security/CWE/CWE-287/AndroidInsecureLocalAuthentication.ql and reproduce the reported Java examples, comparing direct parameter use with assignments, delegation, and calls through a helper. Done means the query reports insecure authentication handling consistently for the provided variants without false negatives.

Written by the indexing model from the issue text.

Description

question

Version
codeql 2.23.9

When I detect the code like this using Security/CWE/CWE-287/AndroidInsecureLocalAuthentication.ql, the problem is reported normally:

package scensct.core.pos;
import android.hardware.fingerprint.FingerprintManager;
public class PosCase1 extends FingerprintManager.AuthenticationCallback {
    @Override
    public void onAuthenticationSucceeded(FingerprintManager.AuthenticationResult result) { // [REPORTED LINE]
        // Parameter 'result' is declared but never accessed or referenced.
        // No cryptographic operation or any use of 'result'.
        System.out.println("Authentication succeeded.");
    }
}

However, when I insert a temporary variable, AndroidInsecureLocalAuthentication.ql is unable to detect the problem:

package scensct.var.pos;

import android.hardware.fingerprint.FingerprintManager;

public class PosCase1_Var3 extends FingerprintManager.AuthenticationCallback {
    @Override
    public void onAuthenticationSucceeded(FingerprintManager.AuthenticationResult result) {
        // Introduce a temporary variable that shadows but does not use result.
        Object ignored = result;
        // Still no cryptographic operation or actual usage.
        System.out.println("Authentication succeeded.");
        // The 'ignored' variable is never read.
    }
}

AndroidInsecureLocalAuthentication.ql scanning the following code also fails to detect the issue:

package scensct.var.pos;

import android.hardware.biometrics.BiometricPrompt;

public class PosCase2_Var1 extends BiometricPrompt.AuthenticationCallback {
    @Override
    public void onAuthenticationSucceeded(BiometricPrompt.AuthenticationResult result) {
        // Introduce a temporary variable that does not change the usage
        BiometricPrompt.AuthenticationResult res = result;
        super.onAuthenticationSucceeded(res);
    }
}

package scensct.var.pos;

import android.hardware.biometrics.BiometricPrompt;

public class PosCase2_Var4 extends BiometricPrompt.AuthenticationCallback {
    // Extract a private helper method that only passes the parameter
    private void callSuper(BiometricPrompt.AuthenticationResult r) {
        super.onAuthenticationSucceeded(r);
    }

    @Override
    public void onAuthenticationSucceeded(BiometricPrompt.AuthenticationResult result) {
        callSuper(result);
    }
}

package scensct.var.pos;

import android.hardware.biometrics.BiometricPrompt;

public class PosCase2_Var5 extends BiometricPrompt.AuthenticationCallback {
    @Override
    public void onAuthenticationSucceeded(BiometricPrompt.AuthenticationResult result) {
        // Add a redundant local variable and a no-op statement
        BiometricPrompt.AuthenticationResult authResult = result;
        int dummy = 0; // unrelated to result
        super.onAuthenticationSucceeded(authResult);
    }
}

Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 16h
Merged PRs (30d)
143

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from github/codeql

All issues in github/codeql

Similar issues

More Security issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.