Skip to content

Ask for authentication before interacting with locked elements #535

@Augustakit

Description

@Augustakit

I discovered something very interesting: if someone wants to view my notes, and they try to open a note only to find that it requires unlocking, they can simply go to the "Security" settings and turn off the relevant options to easily access my notes. I don't think this is secure. I believe that in order to disable the Security settings, one should be required to enter a preliminary password. This password should support a combination of numbers, letters, and characters, using a format similar to two-factor authentication. This way, it would truly ensure confidentiality and prevent someone from viewing my notes while I'm asleep.

Image

2
.Moreover, I found that checking encrypted tags requires fingerprint verification, but deleting tags does not require any verification. If I simply add a tag to my note and the tag is locked, my note itself is not encrypted. However, if others want to view my locked note, they only need to delete the tag to see it. This is also insecure.

3.As for Chinese, there are two bugs.
① As shown in the image, when all notes are selected, only the first note has a blue background; the others are not displayed.
② When you remove tags from all notes, the notes that have been removed will still be displayed in the tags list.

Image

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Projects

Status
Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions