Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Major Security Problem: Database A syncs in wrong Google Account B #80

Open
feelnrg opened this issue May 6, 2024 · 0 comments
Open

Comments

@feelnrg
Copy link

feelnrg commented May 6, 2024

Describe the bug
When working with multiple Keepass databases across different Google accounts, the plugin doesn't seem to adhere to the configured settings. I was surprised to find that Database B on Google A Drive. It's possible that the plugin is using the incorrect token. I'm uncertain why this issue occurs, but I've observed multiple instances where different databases are linked to the wrong accounts. These databases are utilized by various individuals and across different computers to sync with their respective accounts. Each database has a unique Google account configured and the first time Sync was made for this uniuque Account with the correct credentials. Despite Database B being configured for Google Account B, it appears to sync with Account A. I would recommend implementing a check before syncing the database to ensure that the account configured in the settings matches the token being used.

To Reproduce
Not possible to reproduce because I can not define, what is triggering the problem. But I have seen more then 3 different Databases in my own Google Account, which are not configured in the Sync settings. I can say that these Databases was opened at the same time (parallel) in Keepass Application.

Expected behavior
Sync Database A to Google Account A
Sync Database B to Google Account B
Check Accountname before Sync!

Screenshots
grafik

Please provide the following information:

  • OS, Win11 Version 10.0.22631 Build 22631
  • Firefox 125
  • Plugin Version [4.1.0]
  • KeePass Version [2.56] Portable
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant