Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Share password with one time valid link #173

Closed
jpsarda opened this issue Jan 6, 2021 · 2 comments
Closed

Share password with one time valid link #173

jpsarda opened this issue Jan 6, 2021 · 2 comments

Comments

@jpsarda
Copy link

jpsarda commented Jan 6, 2021

Is there a way to share a password to someone else with a one time valid link ? That would be really awesome, that's the only thing I'm missing in this app.

[edit] I lied there is one thing I miss too, it's a shortcut to synchronize my changes.

@arnowelzel
Copy link
Collaborator

arnowelzel commented Jan 6, 2021

No - this is not possible.

Keeweb runs in your browser only, loads the Keepass database and decrypts it in memory after you have entered your password for it (this is also true for https://app.keeweb.info/ - the server there never gets your database and the app only runs in your browser).

Sharing anything from it would require the server to decrypt the datatabase and read the shared record so someone can read that information using a link. However this would fundamentally break security since the whole idea of Keeweb is not to open the database on the server.

Keeweb itself also does not provide such a feature, neither does any other Keepass implementation I know.

Edit: And to allow Keeweb to share something would at least also require having a public Nextcloud link to the database file.

With KeepassXC you can establish shared databases, however this requires to use the desktop or mobile application, see https://keepassxc.org/docs/KeePassXC_UserGuide.html#_database_sharing_with_keeshare. Theoretically you can use a public shared Nextcloud folder to keep the Keeshare files, however in my tests it turned out not to be very reliable. Maybe this has changed over the time.

Having a "share something using a one time valid link" is more a feature request for Nextcloud itself. This had been requested in the past, but not implemented yet because the idea behind a "one time link" makes not really sense to improve security: nextcloud/server#6841

The better way to share passwords is using a secure channel like Signal.

@jpsarda
Copy link
Author

jpsarda commented Jan 6, 2021

Thx very much.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants