Feature Request: Option to enforce PIN/Password instead of Biometrics for App-lock
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 55/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Tranquilla
- Ambito
- authentication, mobile-dev, security
Direzione di ricerca
Inizia leggendo DeviceCredentialUtil.java e il flusso di configurazione esistente di App-lock. Verifica come viene richiamato il prompt corrente di KeyguardManager, quindi esamina il percorso androidx.biometric.BiometricPrompt DEVICE_CREDENTIAL richiesto. Il lavoro è completato quando un’impostazione di App-lock offre il comportamento predefinito del sistema oppure un comportamento basato solo su PIN/password/sequenza, con la modalità limitata selezionata che bypassa i dati biometrici.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Is your feature request related to a problem? Please describe.
Versions
Nextcloud v34.0.2 / Notes server app v6.0.1 / Notes for Android v34.0.0
Currently, when the "App-lock" feature is enabled, the app delegates authentication to the Android system via KeyguardManager (specifically in DeviceCredentialUtil.java). On most devices, if biometrics (fingerprint/face) are enrolled, the system prioritizes them. There is no in-app setting to restrict the authentication method to PIN/password only.
While Notes is not a password manager, users frequently store highly sensitive personal information, credentials, or private thoughts in their notes. From a privacy and security perspective, relying solely on biometrics can be a vulnerability. Biometrics are "something you are", which makes them susceptible to specific threat models, such as physical coercion (forced unlocking) or shared device environments (where a family member might have their fingerprint enrolled on the phone but shouldn't read your private notes).
PIN/Password security relies on "something you know", providing robust protection against these physical threats. Currently, the only workaround to achieve this is to completely delete all fingerprints from the Android system settings, which is highly inconvenient as it cripples the device's overall functionality.
Describe the solution you'd like
Add a setting under the App-lock configuration that allows the user to explicitly enforce the authentication method. For example:
System default (current behavior, allows biometrics)
PIN / Password / Pattern only (enforces device credential, strictly bypasses biometrics)
Note regarding issue #1188: I am aware that a previous request for a "separate locking mechanism" was declined. This proposal does not ask for a custom in-app PIN screen. It simply asks for a configuration flag to be passed to the existing system credential prompt to disable the biometric fallback.
Technical suggestion:
This could be cleanly implemented by migrating from the KeyguardManager to the modern androidx.biometric.BiometricPrompt. By using setAllowedAuthenticators(Authenticators.DEVICE_CREDENTIAL) without including BIOMETRIC_STRONG or BIOMETRIC_WEAK, the app will force the Android system to prompt for the device PIN/password/pattern, completely and intentionally bypassing any enrolled biometric sensors. This requires very minimal code changes in DeviceCredentialUtil.
Describe alternatives you've considered
Deleting all fingerprints/face data from Android system settings. This is unacceptable as a long-term solution because it affects the entire device and disables biometric unlock for all other apps and the system lock screen.
Additional context
Many privacy-focused note-taking apps offer this flexibility, recognizing that sensitive text data requires a higher threat-model defense than a standard phone screen lock. Implementing this will significantly boost the privacy posture of Nextcloud Notes for users who prefer "something you know" over "something you are".
- Lingua principale
- Java
- Stelle
- 1.1k
- Fork
- 168
- Merge medio
- 20h 11m
- PR unite (30g)
- 28
Preparare l'ambiente
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di nextcloud/notes-android
-
enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
nextcloud/notes-android#3367 ·
I maintainer di solito rispondono entro 1 giorno
-
0. Needs triage bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
nextcloud/notes-android#3353 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Sailfish OS native versionApertaenhancement
Difficoltà 5/5 Più di una settimana Idoneità per principianti 20/100
nextcloud/notes-android#3360 · 1 reazione ·
I maintainer di solito rispondono entro 1 giorno
-
0. Needs triage bug
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
nextcloud/notes-android#3358 ·
I maintainer di solito rispondono entro 1 giorno
-
Unable to mark as favoriteAperta0. Needs triage bug
Difficoltà 3/5 1-2 giorni Idoneità per principianti 68/100
nextcloud/notes-android#3357 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di nextcloud/notes-android
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
redhat-developer/intellij-quarkus#1626 ·
-
Type/Bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
wso2/product-integrator-mi#5061 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
quarkiverse/quarkus-roq#1277 ·
I maintainer di solito rispondono entro 1 giorno
-
Typos in page footerAperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
apache/logging-site#48 ·
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
apache/maven-surefire#3496 · 3 commenti ·
I maintainer di solito rispondono entro 1 giorno