You can access Objects while app is locked

WHAT IS THE BUG

You can access Object Search while app is locked. You cannot open the Object, but the titles might be enough data to leak already :wink:

Edit: this also works for Export (leaking all data while app is locked) and import (potentially importing an exploit).

HOW TO REPRODUCE IT

  1. Open Anytype and wait for the app to ask for the pin
  2. Locate the systray icon of Anytype and right click on it
  3. Click “Search object”
    image
  4. See that you can see a list of recent Objects with the pin entry in the background

THE EXPECTED BEHAVIOR

You cannot use search while you are not “logged in” with your pin. Either hide the option in the context menu, or only show the pin and after verification show the search menu.

SYSTEM INFORMATIONS

  • OS:
    Windows 11
  • Device:
    Dell XPS 15
  • Anytype Version:
    0.29.1
1 Like

Sure, add to the tracker pls.

This report has been added to our issue tracker and received by the Development Team.

I’ve just removed the ability to open search from tray when pin is locked, so nothing happens when pin is locked right now. Making popup show after you have entered pin is too much effort for closing this hole imo.

2 Likes

This issue has been fixed by the Development Team and will be included in an upcoming release.

1 Like

This issue has been fixed by the Development Team and will be included in an upcoming release.