Feature Request: Option to enforce PIN/Password instead of Biometrics for App-lock
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 55/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Ít trao đổi
- Lĩnh vực
- authentication, mobile-dev, security
Hướng nghiên cứu
Bắt đầu bằng cách đọc DeviceCredentialUtil.java và luồng cấu hình App-lock hiện có. Kiểm tra cách lời nhắc KeyguardManager hiện tại được gọi, sau đó xem xét đường dẫn androidx.biometric.BiometricPrompt DEVICE_CREDENTIAL được yêu cầu. Hoàn thành khi một tùy chọn cài đặt App-lock cung cấp hành vi mặc định của hệ thống hoặc hành vi chỉ dùng PIN/mật khẩu/mẫu hình, trong đó chế độ hạn chế được chọn sẽ bỏ qua xác thực sinh trắc học.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Is your feature request related to a problem? Please describe.
Versions
Nextcloud v34.0.2 / Notes server app v6.0.1 / Notes for Android v34.0.0
Currently, when the "App-lock" feature is enabled, the app delegates authentication to the Android system via KeyguardManager (specifically in DeviceCredentialUtil.java). On most devices, if biometrics (fingerprint/face) are enrolled, the system prioritizes them. There is no in-app setting to restrict the authentication method to PIN/password only.
While Notes is not a password manager, users frequently store highly sensitive personal information, credentials, or private thoughts in their notes. From a privacy and security perspective, relying solely on biometrics can be a vulnerability. Biometrics are "something you are", which makes them susceptible to specific threat models, such as physical coercion (forced unlocking) or shared device environments (where a family member might have their fingerprint enrolled on the phone but shouldn't read your private notes).
PIN/Password security relies on "something you know", providing robust protection against these physical threats. Currently, the only workaround to achieve this is to completely delete all fingerprints from the Android system settings, which is highly inconvenient as it cripples the device's overall functionality.
Describe the solution you'd like
Add a setting under the App-lock configuration that allows the user to explicitly enforce the authentication method. For example:
System default (current behavior, allows biometrics)
PIN / Password / Pattern only (enforces device credential, strictly bypasses biometrics)
Note regarding issue #1188: I am aware that a previous request for a "separate locking mechanism" was declined. This proposal does not ask for a custom in-app PIN screen. It simply asks for a configuration flag to be passed to the existing system credential prompt to disable the biometric fallback.
Technical suggestion:
This could be cleanly implemented by migrating from the KeyguardManager to the modern androidx.biometric.BiometricPrompt. By using setAllowedAuthenticators(Authenticators.DEVICE_CREDENTIAL) without including BIOMETRIC_STRONG or BIOMETRIC_WEAK, the app will force the Android system to prompt for the device PIN/password/pattern, completely and intentionally bypassing any enrolled biometric sensors. This requires very minimal code changes in DeviceCredentialUtil.
Describe alternatives you've considered
Deleting all fingerprints/face data from Android system settings. This is unacceptable as a long-term solution because it affects the entire device and disables biometric unlock for all other apps and the system lock screen.
Additional context
Many privacy-focused note-taking apps offer this flexibility, recognizing that sensitive text data requires a higher threat-model defense than a standard phone screen lock. Implementing this will significantly boost the privacy posture of Nextcloud Notes for users who prefer "something you know" over "something you are".
- Ngôn ngữ chính
- Java
- Star
- 1.1k
- Fork
- 168
- Merge trung bình
- 21 giờ 49 phút
- Pull request đã merge (30 ngày)
- 29
Chuẩn bị môi trường
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của nextcloud/notes-android
-
enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
nextcloud/notes-android#3367 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
0. Needs triage bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
nextcloud/notes-android#3353 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Sailfish OS native versionĐang mởenhancement
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 20/100
nextcloud/notes-android#3360 · 1 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày
-
0. Needs triage bug
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
nextcloud/notes-android#3358 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Unable to mark as favoriteĐang mở0. Needs triage bug
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 68/100
nextcloud/notes-android#3357 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của nextcloud/notes-android
Issue tương tự
-
P2 testing
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
Maintainer thường phản hồi trong vòng 1 ngày
-
area/core kind/bug status/triage team/core-shared
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
checkstyle/checkstyle#21755 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
spring-projects/spring-integration#11495 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
Maintainer thường phản hồi trong vòng 1 ngày