Don't authorize all apps

Bug #1467793 reported by Corentin Noël
10
This bug affects 2 people
Affects Status Importance Assigned to Milestone
Switchboard Online Accounts Plug
Fix Released
Critical
Corentin Noël

Bug Description

It is extremely unsecure to allow all apps to get the credential.
this should be changed (plugins/Methods/Generic-OAuth/OAuthProvider.vala) :
info.access_control_list_append (new Signon.SecurityContext.from_values ("*", "*"));

Corentin Noël (tintou)
Changed in switchboard-plug-onlineaccounts:
status: Confirmed → Fix Committed
assignee: nobody → Corentin Noël (tintou)
milestone: none → 0.2
Changed in switchboard-plug-onlineaccounts:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.