← Back to team overview

desktop-packages team mailing list archive

[Bug 1392380] Re: OA gives out all tokens to any app

 

** Changed in: ubuntu-touch-meta (Ubuntu RTM)
       Status: Fix Released => New

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to signon in Ubuntu.
https://bugs.launchpad.net/bugs/1392380

Title:
  OA gives out all tokens to any app

Status in the base for Ubuntu mobile products:
  Confirmed
Status in signon package in Ubuntu:
  Fix Released
Status in signon source package in Utopic:
  Confirmed
Status in signon source package in Vivid:
  Fix Released
Status in signon package in Ubuntu RTM:
  In Progress
Status in ubuntu-touch-meta package in Ubuntu RTM:
  New

Bug description:
  The attached app will steal all your tokens. All it takes is the
  "accounts" permission in the apparmor file.

  Here's the code: https://pastebin.canonical.com/120398/

To manage notifications about this bug go to:
https://bugs.launchpad.net/canonical-devices-system-image/+bug/1392380/+subscriptions