Skip to content

Autofill and submit credentials with card removed #118

@ai212983

Description

@ai212983
  1. Go to some website with login form
  2. Add username/password to Mooltipass, enable autosubmit
  3. Refresh the page if necessary, observe auto-login
  4. Remove card from Mooltipass
  5. Logout from the website
  6. Probably redirected to login page, if not, navigate to login page.
  7. Observe auto-login with Mooltipass without card

Can not provide specific site, as its Artifactory on our internal network. Looks like a huge security problem to me. No way password should be in the system once card is not in the device.

N.B. Looks related to #52 and credentials caching

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions