Bug#981520: minigalaxy: Shows a browser login window without any proof of origin (no URL, no HTTPS indicator, no chance to review SSL certificate, etc.)

2021-02-03 Thread Stephen Kitt
Hi Axel, Le 03/02/2021 02:09, Axel Beckert a écrit : Hi Stephen and Stephan, Stephen Kitt wrote: On Tue, 02 Feb 2021 11:02:58 +, Stephan Lachnit wrote: > > On startup it shows a login window which looks suspiciously like a GOG > > login window in a web browser, but without without any

Bug#981520: minigalaxy: Shows a browser login window without any proof of origin (no URL, no HTTPS indicator, no chance to review SSL certificate, etc.)

2021-02-02 Thread Axel Beckert
Hi Stephen and Stephan, (JFYI: I only got Stephen's mail.) Stephen Kitt wrote: > On Tue, 02 Feb 2021 11:02:58 +, Stephan Lachnit > wrote: > > > On startup it shows a login window which looks suspiciously like a GOG > > > login window in a web browser, but without without any possibility to

Bug#981520: minigalaxy: Shows a browser login window without any proof of origin (no URL, no HTTPS indicator, no chance to review SSL certificate, etc.)

2021-02-02 Thread Stephen Kitt
Hi Axel, On Tue, 02 Feb 2021 11:02:58 +, Stephan Lachnit wrote: > > On startup it shows a login window which looks suspiciously like a GOG > > login window in a web browser, but without without any possibility to > > check its origin: It has no location bar, i.e. shows no URL, it doesn't > >

Bug#981520: minigalaxy: Shows a browser login window without any proof of origin (no URL, no HTTPS indicator, no chance to review SSL certificate, etc.)

2021-02-02 Thread Stephan Lachnit
Control: severity -1 wishlist Control: forwarded -1 https://github.com/sharkwouter/minigalaxy/issues/282 Control: tags -1 upstream Hi, thanks for your bug report. I've taken a look into it and I reduced the severity for a couple of reasons. > On startup it shows a login window which looks

Bug#981520: minigalaxy: Shows a browser login window without any proof of origin (no URL, no HTTPS indicator, no chance to review SSL certificate, etc.)

2021-01-31 Thread Axel Beckert
Package: minigalaxy Version: 1.0.1-1 Severity: grave Tags: security Justification: introduces a security hole allowing access to the accounts of users who use the package Hi, thanks for packaging minigalaxy. Unfortunately it's unusable as you can't conscientiously login to GOG: On startup it