-
Notifications
You must be signed in to change notification settings - Fork 4
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Security]: Files accessible without password via custom storage path (external storage) #8
Comments
Thank you for the bug report. It is noted. I may have identified the issue (see below). Initial assessment:On Android 10, external app specific dirs are not completely protected. From the look of it, you have selected an external storage dir (please confirm). Why Android 10 is not completely safe for using
|
Subject: Additional Information Regarding Bug Report Hello, Thank you for your detailed response. I have gathered the requested details regarding the issue.
Let me know if you need further details or steps to reproduce the issue. |
Thanks you. It indeed is the identified issue. Todo for meI shall
Suggestion for users on Android 10 (and below)Consider moving your files to the storage backend labeled |
Steps were taken to address this security issue. Which was in part a documentation issue. Thanks for the report and assistance in verifying the diagnosis! |
Steps to reproduce
Set up the application and create a private storage.
Use the custom path feature to set the storage path to /storage/emulated/0/Android/data/alt.nainapps.aer/files.
Navigate to the specified path using a file manager or another application.
Observe that files in this path can be accessed without entering the application password.
Expectations
What should happen:
Reality
What actually happens:
App version
Version 2024.10.31 (1730403000) Added on Nov 05, 2024
Android version
Android 10
The text was updated successfully, but these errors were encountered: