create account

iOS eSteem App | Without entering Pin Code open Submit Story form by devilonwheels

View this thread on: hive.blogpeakd.comecency.com
· @devilonwheels · (edited)
$12.21
iOS eSteem App | Without entering Pin Code open Submit Story form
I just started using eSteem more and more especially very handy when replying or posting comments. However, it is a bit slow and unresponsive at times in iOS but today I am going to share an issue that is kind of a security issue for me.

## What Happened As User Experience
-- 1. I was trying to access the Search feature of the app which is available under the context menu of the app on upper right hand corner. You can click on three dots "..." to open is and that's how it looks

![image.png](https://res.cloudinary.com/hpiynhbhq/image/upload/v1515203994/uezrcxqqdhwcsrdgzpbo.png)

-- 2. Suddenly I had to push my Home button on my iPhone to move to another app. I worked on the other item and opened the eSteem App and found the first issue, which is highlighted below. You can that the app asks me to enter Pin Code but still shows the context menu.

![image.png](https://res.cloudinary.com/hpiynhbhq/image/upload/v1515204228/olz65ois3j37z55hd6rx.png)

-- 3. The issue does not end there because as a security measure I had applied the Pin Code so that no one can use the app without entering the Pin Code that I enabled from settings option of the app. I have access to all four context menu options and most critical one is "**Submit a story**" button. The other three options aren't of that much severity as the context menu closes and action is applied in the app. 

-- 4.  However, if you tap/click the "**Submit a story**" button, you will get to your Submit story form without user entering the Pin Code
![image.png](https://res.cloudinary.com/hpiynhbhq/image/upload/v1515204626/ztgwafllyad1dswmz0xg.png)

## Expected Output
The context menu should not be visible if I have not entered the pin code and user should never be able to reach/open "Submit a story" form without entering the security Pin Code to open the  eSteem app

## Steps to Reproduce the Bug
-- 1. Open eSteem app on iPhone 6 with iOS 11.2.1
-- 2. Enter eSteem app security Pin Code to open your app. Make sure you have enabled the Pin Code under your eSteem -> Settings -> Security option.
-- 3. Click on the three dots "..." on upper right hand corner of the app to open the context menu. It will open the Context Menu with four options.
-- 4. Press the home button of your iPhone 6 to minimize/hide the eSteem app tocome to home screen of iPhone 6
-- 5. Open the eSteem app again. 
-- 6. **Issue 1**: The Context menu is visible with all 4 options with Pin Code pad below. User can select any option now.
-- 7.  **Issue 2**: While the first three options only closes the context menu and have effect inside the app. Clicking on "Submit a story" option opens up the Submit a story form and user will be able to submit the story without entering the security Pin Code. To me it is kind of a security issue that any one can have access to your phone while the eSteem app is minimized or hidden and if he opens the app in this condition, he can go ahead and submit a story without you knowing it.

Pictures / screenshots of the app are shared above. Let me know in case any other input is required to reproduce the issue.

### Environment Details
Phone:  iPhone 6
Operating System: iOS 11.2.1

<br /><hr/><em>Posted on <a href="https://utopian.io/utopian-io/@devilonwheels/ios-esteem-app-or-without-entering-pin-code-open-submit-story-form">Utopian.io -  Rewarding Open Source Contributors</a></em><hr/>
👍  , , , , , , ,
properties (23)
authordevilonwheels
permlinkios-esteem-app-or-without-entering-pin-code-open-submit-story-form
categoryutopian-io
json_metadata{"community":"utopian","app":"utopian/1.0.0","format":"markdown","repository":{"id":63218416,"name":"esteem","full_name":"eSteemApp/esteem","html_url":"https://github.com/eSteemApp/esteem","fork":false,"owner":{"login":"eSteemApp"}},"pullRequests":[],"platform":"github","type":"bug-hunting","tags":["utopian-io","esteem","bug","steemitdev","devilonwheels"],"users":["devilonwheels"],"links":["https://res.cloudinary.com/hpiynhbhq/image/upload/v1515203994/uezrcxqqdhwcsrdgzpbo.png","https://res.cloudinary.com/hpiynhbhq/image/upload/v1515204228/olz65ois3j37z55hd6rx.png","https://res.cloudinary.com/hpiynhbhq/image/upload/v1515204626/ztgwafllyad1dswmz0xg.png"],"image":["https://res.cloudinary.com/hpiynhbhq/image/upload/v1515203994/uezrcxqqdhwcsrdgzpbo.png","https://res.cloudinary.com/hpiynhbhq/image/upload/v1515204228/olz65ois3j37z55hd6rx.png","https://res.cloudinary.com/hpiynhbhq/image/upload/v1515204626/ztgwafllyad1dswmz0xg.png"],"moderator":{"account":"thegoldenphoenix","pending":false,"reviewed":true,"flagged":false}}
created2018-01-06 02:27:00
last_update2018-01-10 21:58:27
depth0
children12
last_payout2018-01-13 02:27:00
cashout_time1969-12-31 23:59:59
total_payout_value8.709 HBD
curator_payout_value3.501 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length3,383
author_reputation1,586,138,858,119
root_title"iOS eSteem App | Without entering Pin Code open Submit Story form"
beneficiaries
0.
accountutopian.pay
weight2,500
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id27,421,195
net_rshares1,565,720,996,617
author_curate_reward""
vote details (8)
@thegoldenphoenix · (edited)
Your contribution cannot be approved yet. See the [Utopian Rules](https://utopian.io/rules). 
your contribution  is very similar to this one 
https://utopian.io/utopian-io/@thegoldenphoenix/esteemapp-a-serious-security-bug
You can contact us on [Discord](https://discord.gg/UCvqCsx).
**[[utopian-moderator]](https://utopian.io/moderators)**
properties (22)
authorthegoldenphoenix
permlinkre-devilonwheels-ios-esteem-app-or-without-entering-pin-code-open-submit-story-form-20180108t235943253z
categoryutopian-io
json_metadata{"tags":["utopian-io"],"community":"utopian","app":"utopian/1.0.0"}
created2018-01-08 23:59:45
last_update2018-01-09 22:09:18
depth1
children3
last_payout2018-01-15 23:59:45
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length340
author_reputation10,798,378,750,231
root_title"iOS eSteem App | Without entering Pin Code open Submit Story form"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id28,116,917
net_rshares0
@devilonwheels ·
@thegoldenphoenix, with due respect, the contribution you are suggesting is for different app and different behaviour while this is a bug in eSteem Mobile app not Steemiz Post Reward.
properties (22)
authordevilonwheels
permlinkre-thegoldenphoenix-re-devilonwheels-ios-esteem-app-or-without-entering-pin-code-open-submit-story-form-20180109t003158146z
categoryutopian-io
json_metadata{"tags":["utopian-io"],"community":"utopian","app":"utopian/1.0.0"}
created2018-01-09 00:31:57
last_update2018-01-09 00:31:57
depth2
children2
last_payout2018-01-16 00:31:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length183
author_reputation1,586,138,858,119
root_title"iOS eSteem App | Without entering Pin Code open Submit Story form"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id28,122,457
net_rshares0
@thegoldenphoenix ·
wrong link sorry for that @devilonwheels  this is the correct link 
https://utopian.io/utopian-io/@thegoldenphoenix/esteemapp-a-serious-security-bug 
properties (22)
authorthegoldenphoenix
permlinkre-devilonwheels-re-thegoldenphoenix-re-devilonwheels-ios-esteem-app-or-without-entering-pin-code-open-submit-story-form-20180109t221055481z
categoryutopian-io
json_metadata{"tags":["utopian-io"],"community":"utopian","app":"utopian/1.0.0"}
created2018-01-09 22:10:57
last_update2018-01-09 22:10:57
depth3
children1
last_payout2018-01-16 22:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length149
author_reputation10,798,378,750,231
root_title"iOS eSteem App | Without entering Pin Code open Submit Story form"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id28,347,894
net_rshares0
@thegoldenphoenix ·
$0.06
you have well  explained your point of view your contribution is approved.
You can contact us on [Discord](https://discord.gg/UCvqCsx).
**[[utopian-moderator]](https://utopian.io/moderators)**
👍  
properties (23)
authorthegoldenphoenix
permlinkre-devilonwheels-ios-esteem-app-or-without-entering-pin-code-open-submit-story-form-20180110t220531918z
categoryutopian-io
json_metadata{"tags":["utopian-io"],"community":"utopian","app":"utopian/1.0.0"}
created2018-01-10 22:05:33
last_update2018-01-10 22:05:33
depth1
children4
last_payout2018-01-17 22:05:33
cashout_time1969-12-31 23:59:59
total_payout_value0.043 HBD
curator_payout_value0.014 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length192
author_reputation10,798,378,750,231
root_title"iOS eSteem App | Without entering Pin Code open Submit Story form"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id28,599,563
net_rshares6,877,329,244
author_curate_reward""
vote details (1)
@devilonwheels ·
Thanks a lot !! I appreciate you understanding it and approval of it. I will keep up the efforts to improve further.
👍  
properties (23)
authordevilonwheels
permlinkre-thegoldenphoenix-re-devilonwheels-ios-esteem-app-or-without-entering-pin-code-open-submit-story-form-20180110t235653966z
categoryutopian-io
json_metadata{"tags":["utopian-io"],"community":"utopian","app":"utopian/1.0.0"}
created2018-01-10 23:56:54
last_update2018-01-10 23:56:54
depth2
children3
last_payout2018-01-17 23:56:54
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length116
author_reputation1,586,138,858,119
root_title"iOS eSteem App | Without entering Pin Code open Submit Story form"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id28,617,855
net_rshares2,404,814,850
author_curate_reward""
vote details (1)
@eatsrewards ·
$0.93
Enjoy the vote and reward!
👍  , ,
properties (23)
authoreatsrewards
permlinkeatsrewards-re-devilonwheelsre-thegoldenphoenix-re-devilonwheels-ios-esteem-app-or-without-entering-pin-code-open-submit-story-form-20180110t235653966z
categoryutopian-io
json_metadata""
created2018-01-11 00:31:33
last_update2018-01-11 00:31:33
depth3
children1
last_payout2018-01-18 00:31:33
cashout_time1969-12-31 23:59:59
total_payout_value0.929 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length26
author_reputation6,338,926,820,750
root_title"iOS eSteem App | Without entering Pin Code open Submit Story form"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id28,623,436
net_rshares102,041,796,815
author_curate_reward""
vote details (3)
@goel.tarun ·
Good One Dheeraj :)
properties (22)
authorgoel.tarun
permlinkre-devilonwheels-re-thegoldenphoenix-re-devilonwheels-ios-esteem-app-or-without-entering-pin-code-open-submit-story-form-20180112t130303162z
categoryutopian-io
json_metadata{"tags":["utopian-io"],"app":"steemit/0.1"}
created2018-01-12 13:03:09
last_update2018-01-12 13:03:09
depth3
children0
last_payout2018-01-19 13:03:09
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length19
author_reputation12,095,155,003,362
root_title"iOS eSteem App | Without entering Pin Code open Submit Story form"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id28,998,807
net_rshares0
@thenomadictales ·
i don't have a password so can't comment on security thing however this slow and going unresponsive is quite irritating. M on move most of the times so using app extensively and would be great if these issues gets fixed.
properties (22)
authorthenomadictales
permlinkre-devilonwheels-ios-esteem-app-or-without-entering-pin-code-open-submit-story-form-20180106t041734941z
categoryutopian-io
json_metadata{"tags":["utopian-io"],"app":"steemit/0.1"}
created2018-01-06 04:17:09
last_update2018-01-06 04:17:09
depth1
children1
last_payout2018-01-13 04:17:09
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length220
author_reputation3,117,654,789,376
root_title"iOS eSteem App | Without entering Pin Code open Submit Story form"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id27,438,311
net_rshares0
@devilonwheels ·
$0.03
Yeah Sanchit, it indeed is and well I am sure that @good-karma would be working very hard to  get it right. I saw one post where lots of updates are going to be coming our way in 2018 with even new UI. Looking forward for it to get stabilize and more robust.
👍  
properties (23)
authordevilonwheels
permlinkre-thenomadictales-re-devilonwheels-ios-esteem-app-or-without-entering-pin-code-open-submit-story-form-20180106t050604542z
categoryutopian-io
json_metadata{"tags":["utopian-io"],"community":"utopian","app":"utopian/1.0.0"}
created2018-01-06 05:06:03
last_update2018-01-06 05:06:03
depth2
children0
last_payout2018-01-13 05:06:03
cashout_time1969-12-31 23:59:59
total_payout_value0.025 HBD
curator_payout_value0.005 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length258
author_reputation1,586,138,858,119
root_title"iOS eSteem App | Without entering Pin Code open Submit Story form"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id27,445,243
net_rshares3,565,109,134
author_curate_reward""
vote details (1)
@utopian-io ·
### Hey @devilonwheels I am @utopian-io. I have just upvoted you!
#### Achievements
- You have less than 500 followers. Just gave you a gift to help you succeed!
- This is your first accepted contribution here in Utopian. Welcome!
#### Suggestions
- Contribute more often to get higher and higher rewards. I wish to see you often!
- Work on your followers to increase the votes/rewards. I follow what humans do and my vote is mainly based on that. Good luck!
#### Get Noticed!
- Did you know project owners can manually vote with their own voting power or by voting power delegated to their projects? Ask the project owner to review your contributions!
#### Community-Driven Witness!
I am the first and only Steem Community-Driven Witness. <a href="https://discord.gg/zTrEMqB">Participate on Discord</a>. Lets GROW TOGETHER!
- <a href="https://v2.steemconnect.com/sign/account-witness-vote?witness=utopian-io&approve=1">Vote for my Witness With SteemConnect</a>
- <a href="https://v2.steemconnect.com/sign/account-witness-proxy?proxy=utopian-io&approve=1">Proxy vote to Utopian Witness with SteemConnect</a>
- Or vote/proxy on <a href="https://steemit.com/~witnesses">Steemit Witnesses</a>

[![mooncryption-utopian-witness-gif](https://steemitimages.com/DQmYPUuQRptAqNBCQRwQjKWAqWU3zJkL3RXVUtEKVury8up/mooncryption-s-utopian-io-witness-gif.gif)](https://steemit.com/~witnesses)

**Up-vote this comment to grow my power and help Open Source contributions like this one. Want to chat? Join me on Discord https://discord.gg/Pc8HG9x**
properties (22)
authorutopian-io
permlinkre-devilonwheels-ios-esteem-app-or-without-entering-pin-code-open-submit-story-form-20180112t125106560z
categoryutopian-io
json_metadata{"tags":["utopian-io"],"community":"utopian","app":"utopian/1.0.0"}
created2018-01-12 12:51:06
last_update2018-01-12 12:51:06
depth1
children0
last_payout2018-01-19 12:51:06
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length1,530
author_reputation152,955,367,999,756
root_title"iOS eSteem App | Without entering Pin Code open Submit Story form"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id28,996,480
net_rshares0