Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

feat(android): add optional private comparison for secure input

オープン
#2,289 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
5/5
見積もり時間
1週間以上
初心者へのやさしさ
35/100
issue の種類
機能追加
明瞭さ
おおむね明確
活発さ
活発
技術スタック
android

調査の方向性

既存の Android IME helper と共有の tool contract から始め、現在の capability discovery、input ownership、session cleanup の仕組みを確認します。getExtractedText を使用して、API 36 のネイティブな EditText と診断用 IME probe を再現し、その後、完全で新しい evidence と secret-safe な failure handling に関する acceptance checks を確認します。完了の条件は、bounded な比較結果によって有効な match と mismatch を区別でき、不確実または未対応のパスがプラットフォーム間で unknown のまま維持されることです。

索引モデルが issue の本文から書いたものです。

説明

needs-triage

Add optional native private input comparison for secure fields

Android secure fields can expose masked accessibility text even after a successful
fill. Preserving password, hint, selection and mask metadata improves evidence,
but metadata alone cannot prove the exact value was entered. The existing Android
IME helper commits and clears input; it does not currently provide private
readback/comparison evidence.

Reproduction and bounded evidence

A disposable API 36 emulator ran a native synthetic EditText fixture and a
diagnostic IME in separate application processes. After public agent-device fill
with synthetic 2468, the secure node reported password:true and accessibility
mask_only text of length 4. The IME's InputConnection extracted text reported
length 4 and equality true against that fixed synthetic expectation. Filling a
different same-length synthetic value, 1357, produced length 4 and equality false.
The observed extraction had startOffset 0 and partialStartOffset/partialEndOffset
-1. Retrieved text was compared in-process and never printed.

This establishes a narrow native feasibility result on that fixture and device.
It does not establish support for every app, WebView, custom editor, Android
version, or another platform.

The fixture uses EditText with TYPE_CLASS_NUMBER | TYPE_NUMBER_VARIATION_PASSWORD
and PasswordTransformationMethod.getInstance(). The separate diagnostic IME
calls getCurrentInputConnection().getExtractedText(request, 0) and compares
extracted.text to the fixed synthetic expectation in-process. This is a probe,
not the proposed production protocol: fragment equality alone cannot establish
complete, target-bound field equality.

Proposed capability

Add an optional private comparison operation through the existing Android IME
helper, returning a structured match, mismatch, or unknown result. Keep raw
field text inside the native helper. This should supplement fill evidence without
making accessibility masks an exact-value assertion.

The operation should require:

  • A stable target binding: device/session, app package, editor field identity,
    focused target, and input-connection generation. Bind the expectation and reply
    to a fresh nonce; reject focus or generation changes during capture/comparison.
  • Fresh, complete value evidence after the action. Check extraction offsets and
    partial-update markers, and prove completeness within bounded reads. A cursor
    fragment, stale extraction, truncation, or unavailable completeness signal must
    yield unknown, even if a returned fragment matches.
  • Bounded read sizes, request duration, and retries. Unsupported/refused/null
    connections, unsupported editors, timeouts, and uncertain ownership return
    explicit unknown/unsupported reasons rather than success or empty-value claims.
  • Explicit opt-in capability and permission gates for the helper/IME, with target
    ownership checks. Preserve existing guards against typing into the IME itself.
    Restore prior IME configuration when a session ends or fails.
  • Secret privacy throughout transport, logs, errors, traces, and artifacts. Do not
    serialize raw retrieved values or expected secrets into evidence. Return only
    the comparison result and minimal non-sensitive provenance needed to validate
    freshness; do not expose lengths by default unless separately justified.

Expose this as a platform capability through the shared tool contract: callers
must be able to discover support and handle unknown consistently on Android, iOS,
and web. Do not imply an Android IME implementation automatically supplies iOS or
web parity. Unsupported platforms should retain truthful evidence limitations.

Acceptance checks

  • Correct and wrong same-length synthetic inputs yield distinct comparison
    outcomes on a genuinely masked native field.
  • Empty values, selection/cursor movement, focus switches, editor recreation,
    stale sessions, partial extraction, truncation, and refusal cannot produce a
    false match.
  • The helper remains a separate process and preserves existing input-owner gates.
  • Automated log/trace/error inspection finds neither expected nor observed secret
    values, including failure paths.
  • Unsupported editor/platform paths return unknown and cannot upgrade a
    checkpoint to exact-value success.

This issue proposes a capability boundary and validation work, not a production
ready implementation or universal support claim. A metadata-only change remains
useful independently but does not close the exact-comparison gap.

主要言語
TypeScript
スター
4.9k
フォーク
328
平均マージ
12時間 16分
マージ済み PR(30日)
538

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

callstack/agent-device のほかの issue

callstack/agent-device の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。