Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Feature Request: Option to enforce PIN/Password instead of Biometrics for App-lock

オープン
#3,288 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
55/100
issue の種類
機能追加
明瞭さ
おおむね明確
活発さ
静か
技術スタック
android, java

調査の方向性

まず DeviceCredentialUtil.java と既存の App-lock 設定フローを読みます。現在の KeyguardManager プロンプトがどのように呼び出されているかを確認し、続いて要求されている androidx.biometric.BiometricPrompt DEVICE_CREDENTIAL パスを確認します。App-lock 設定で、システムのデフォルト動作、または PIN/パスワード/パターンのみの動作を選択でき、選択した制限モードで生体認証をバイパスできれば完了です。

索引モデルが issue の本文から書いたものです。

説明

enhancement
Is your feature request related to a problem? Please describe.

Versions
Nextcloud v34.0.2 / Notes server app v6.0.1 / Notes for Android v34.0.0

Currently, when the "App-lock" feature is enabled, the app delegates authentication to the Android system via KeyguardManager (specifically in DeviceCredentialUtil.java). On most devices, if biometrics (fingerprint/face) are enrolled, the system prioritizes them. There is no in-app setting to restrict the authentication method to PIN/password only.

While Notes is not a password manager, users frequently store highly sensitive personal information, credentials, or private thoughts in their notes. From a privacy and security perspective, relying solely on biometrics can be a vulnerability. Biometrics are "something you are", which makes them susceptible to specific threat models, such as physical coercion (forced unlocking) or shared device environments (where a family member might have their fingerprint enrolled on the phone but shouldn't read your private notes).

PIN/Password security relies on "something you know", providing robust protection against these physical threats. Currently, the only workaround to achieve this is to completely delete all fingerprints from the Android system settings, which is highly inconvenient as it cripples the device's overall functionality.

Describe the solution you'd like

Add a setting under the App-lock configuration that allows the user to explicitly enforce the authentication method. For example:

 System default (current behavior, allows biometrics)
 PIN / Password / Pattern only (enforces device credential, strictly bypasses biometrics)

Note regarding issue #1188: I am aware that a previous request for a "separate locking mechanism" was declined. This proposal does not ask for a custom in-app PIN screen. It simply asks for a configuration flag to be passed to the existing system credential prompt to disable the biometric fallback.

Technical suggestion:
This could be cleanly implemented by migrating from the KeyguardManager to the modern androidx.biometric.BiometricPrompt. By using setAllowedAuthenticators(Authenticators.DEVICE_CREDENTIAL) without including BIOMETRIC_STRONG or BIOMETRIC_WEAK, the app will force the Android system to prompt for the device PIN/password/pattern, completely and intentionally bypassing any enrolled biometric sensors. This requires very minimal code changes in DeviceCredentialUtil.

Describe alternatives you've considered

Deleting all fingerprints/face data from Android system settings. This is unacceptable as a long-term solution because it affects the entire device and disables biometric unlock for all other apps and the system lock screen.

Additional context

Many privacy-focused note-taking apps offer this flexibility, recognizing that sensitive text data requires a higher threat-model defense than a standard phone screen lock. Implementing this will significantly boost the privacy posture of Nextcloud Notes for users who prefer "something you know" over "something you are".

主要言語
Java
スター
1.1k
フォーク
168
平均マージ
20時間 11分
マージ済み PR(30日)
28

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

nextcloud/notes-android のほかの issue

nextcloud/notes-android の issue をすべて見る

似ている issue

Java の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。