Anytype can update before entering pin code

WHAT IS THE BUG

It is possible to check for updates and update Anytype before the pin code is entered to access the user data.

HOW TO REPRODUCE IT

  1. Open Anytype but do no enter the pin code
  2. Open the menu > Anytype > Check for updates
  3. If an update is available, you can click Update and install the new version.

THE EXPECTED BEHAVIOR

I would expect like most OSes (not sure about applications that require a login) that you can only update AFTER authenticating/logging in.

SYSTEM INFORMATIONS

  • OS:
    Windows 11
  • Device:
    Dell XPS 15
  • Anytype Version:
    0.27.0

ADDITIONAL CONTEXT

I don’t see an immediate security risk of updating before entering the pin but it feels wrong…

1 Like

This issue has been added to our issue tracker and was received by the Development Team.

This issue has been fixed by the Development Team and will be included in an upcoming release.

@Angelo
It is still possible (0.31.1) to get into the settings of Anytype when the app is locked. Therefore it is possible to export the users data.

You’re right. It needs a new big report!

It needs to be huge!

1 Like

Why does it need to be big? :sweat_smile:
Isn’t it just “don’t allow anything until the pin is entered”?

1 Like

@Flip Sam is teasing me, it was a typo.

I meant that there needs to be a new *Bug Report submitted for 0.31.1, because the previous issue was closed in Linear.

2 Likes

:man_facepalming: time for weekend ^^

2 Likes

bugtime!

1 Like