Bug-hunting|| SteemApp v2.1.1 can be log in with wrong username.

Project Information

Expected behavior

The app should not let user log in with wrong username and user's own private posting key.

Actual behavior

User can log in with their private posting key and wrong username of other steemit accounts.

How to reproduce

  • Fresh start SteemApp v2.1.1 and click on the first box and write any steemit username you want example "steemapp".
  • Go to your steemit wallet and then click on permission and click on "show private key" of posting.
  • Copy the private posting key and paste it on SteemApp posting key box or just scan the QR code by clicking on the camera icon of SteemApp.
  • After pasting private posting key click log in.
  • Note that after clicking on log in user still able to log in with that wrong username.
  • App version: SteemApp v2.1.1
  • Operating system: Android 7.0

Recording Of The Bug

GitHub Account

H2
H3
H4
3 columns
2 columns
1 column
Join the conversation now