-
-
Notifications
You must be signed in to change notification settings - Fork 1.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
KeePassHTTP: Invalid URLs in title/URL leads to false positives #1340
Comments
Here's a good news: the new browser plugin does not have this issue. |
Which version? |
v1.0.9 is still affected here. |
@rugk: Sorry if my comment was misleading. I was referring to @varjolintu's keepassxc-browser work. That plugin requires the latest git version of KeePassXC. AFAIK It's going to be included in KeePassXC 2.4.0, which is still on its way. UPDATE: Removal of KeePassHTTP is postponed to 2.4 (#1752) |
BTW it always seems to request that one entry (bad password) for all password fields, where it does not recognize/find a different passwords. Almost seems like this is a simple array iteration issue or so where it chooses |
Expected Behavior
The KeePassHTTP plugin returns matched entries only
Current Behavior
When the title or URL field in an entry contains an invalid URL, the entry is returned
Possible Solution
Reject invalid URLs in Service::matchUrlScheme() (untested)
Steps to Reproduce (for bugs)
https://example.com foobar
. Note that there's a space before foobarContext
This is a following up of #1017
Debug Info
KeePassXC - Version 2.2.4
Revision: ad8fca2
Libraries:
Operating system: Arch Linux
CPU architecture: x86_64
Kernel: linux 4.14.9-1-ARCH
Enabled extensions:
The text was updated successfully, but these errors were encountered: