Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

App Passwords not displayed #6075

Closed
Trevelian opened this issue Aug 10, 2017 · 11 comments
Closed

App Passwords not displayed #6075

Trevelian opened this issue Aug 10, 2017 · 11 comments

Comments

@Trevelian
Copy link

Steps to reproduce

  1. Go to the Personal page of a user
  2. Scroll down and see no App Password entry but the old App Password still work
  3. Create a new one it also disapear

1094-689-max

Expected behaviour

See my App Password

Server configuration

Operating system:
Archlinux
Web server:
Apache
Database:
Mariadb
PHP version:
7.1
Nextcloud version: (see Nextcloud admin page)
12.0.1
Where did you install Nextcloud from:
from nextcloud.com

Login as admin user into your Nextcloud and access
http://example.com/index.php/settings/integrity/failed
paste the results here.

No errors have been found.

List of activated apps:

Enabled:
  - activity: 2.5.2
  - bruteforcesettings: 1.0.2
  - calendar: 1.5.3
  - comments: 1.2.0
  - contacts: 1.5.3
  - dav: 1.3.0
  - federatedfilesharing: 1.2.0
  - files: 1.7.2
  - files_pdfviewer: 1.1.1
  - files_sharing: 1.4.0
  - files_texteditor: 2.4.1
  - files_trashbin: 1.2.0
  - files_videoplayer: 1.1.0
  - gallery: 17.0.0
  - logreader: 2.0.0
  - lookup_server_connector: 1.0.0
  - mail: 0.6.4
  - news: 11.0.5
  - nextcloud_announcements: 1.1
  - notifications: 2.0.0
  - oauth2: 1.0.5
  - passman: 2.1.4
  - provisioning_api: 1.2.0
  - serverinfo: 1.2.0
  - systemtags: 1.2.0
  - theming: 1.3.0
  - twofactor_backupcodes: 1.1.1
  - twofactor_totp: 1.3.0
  - workflowengine: 1.2.0

Client configuration

Browser:
Firefox
Operating system:
Archlinux / W10

@eggithub
Copy link

Same issue here on my rpi3 and indeed passwords keep working. also persists in 12.0.2

@xXSTrikeXx
Copy link

I think it isn´t really a issue for nextcloud. Why should be there a expected behaviour to see app-passwords? That makes no sense, because a forgotten logout can easily hack your account. Why isn´t there a expected behaviour to revoke the old Pin and create a new one for the device? So noone can see any password, even generated, and noone can access to any data.

Making new Pin and revoke the old one over (...)
apps

apps2

I think it´s in developer minds, that noone can see any password and that the user revokes a password and gererates a new ones. Or do I missunderstand anything? 👍

@MorrisJobke
Copy link
Member

The idea of this is that the app password will be shown only during creation (as stated in the text above the fields as well ;))

If you forgot it: delete the old entry (to clean it up a bit) and create a new one instead.

Closing as non-issue.

@Trevelian
Copy link
Author

Trevelian commented Sep 4, 2017

@xXSTrikeXx @MorrisJobke The initial problem was that the previous app password are not visible, not just the password, everything, so its not possible to delete the old entry ...

Like you see on the first screenshot, its only a white space between "Create new app password" and "Activity" and we dont see all my 8 App Password that I want to delete...

@MorrisJobke
Copy link
Member

cc @ChristophWurst for this bug then

@ChristophWurst
Copy link
Member

@MorrisJobke I'm already on it, kind of: nextcloud/twofactor_totp#186 (comment)

I still cannot reproduce this here. All I know is that it's most certainly a UI issue as the server returns the correct list of tokens as JSON reponse.

@ChristophWurst
Copy link
Member

Can someone please try to disable all third party apps and check whether the problem persists?

@Trevelian
Copy link
Author

@ChristophWurst Hello, I just open my nextcloud to make the test and ... all seems ok...I have the feeling that its just a human mistake due to the evolution from NC11 with the dual menu "Sessions" and "App passwords" to a single one "Security" in NC12.

Sorry for this...

@j-ed
Copy link
Contributor

j-ed commented Sep 5, 2017

I think the problem is not really that the passwords itself are not shown, although the subject of this issue ticket states that, but the fact that you cannot see which app password entries have already been created in the past. The only thing which you can see is the chronology in which app passwords have been used.
As far as I remember such a list was shown in NC 11.x.

@ChristophWurst
Copy link
Member

but the fact that you cannot see which app password entries have already been created

Sure you can. They are listed together with browser sessions. We combined both views for NC12 with #5166

@AsavarTzeth
Copy link

AsavarTzeth commented Oct 12, 2017

I created an app password, but it is not visible in the browser session view on my installation. Is it only visible after having been used?

I might have entered the code incorrectly on my mobile device so it will most likely never be used. Does this mean I cannot revoke it?

Edit: Never mind it just appeared after some delay.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

7 participants