Skip to content

Autofill and submit credentials with card removed #118

@ai212983

Description

@ai212983
  1. Go to some website with login form
  2. Add username/password to Mooltipass, enable autosubmit
  3. Refresh the page if necessary, observe auto-login
  4. Remove card from Mooltipass
  5. Logout from the website
  6. Probably redirected to login page, if not, navigate to login page.
  7. Observe auto-login with Mooltipass without card

Can not provide specific site, as its Artifactory on our internal network. Looks like a huge security problem to me. No way password should be in the system once card is not in the device.

N.B. Looks related to #52 and credentials caching

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions