← Back to team overview

touch-packages team mailing list archive

[Bug 1392380] Re: OA gives out all tokens to any app

 

Adding rtm14 ota-1 touch-2014-11-27. This needs to be fixed for RTM
branch when bug #1376445 is fixed, but bug #1376445 is targeted for
ota-1.

** Also affects: signon (Ubuntu Utopic)
   Importance: Undecided
       Status: New

** Also affects: signon (Ubuntu Vivid)
   Importance: Critical
     Assignee: Alberto Mardegan (mardy)
       Status: Confirmed

** Changed in: signon (Ubuntu Utopic)
       Status: New => Confirmed

** Changed in: signon (Ubuntu Utopic)
   Importance: Undecided => Critical

** Also affects: signon (Ubuntu RTM)
   Importance: Undecided
       Status: New

** Tags added: ota-1 rtm14 touch-2014-11-27

-- 
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to signon in Ubuntu.
https://bugs.launchpad.net/bugs/1392380

Title:
  OA gives out all tokens to any app

Status in “signon” package in Ubuntu:
  Confirmed
Status in “signon” source package in Utopic:
  Confirmed
Status in “signon” source package in Vivid:
  Confirmed
Status in “signon” package in Ubuntu RTM:
  New

Bug description:
  The attached app will steal all your tokens. All it takes is the
  "accounts" permission in the apparmor file.

  Here's the code: https://pastebin.canonical.com/120398/

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/signon/+bug/1392380/+subscriptions