Important security issue

Avatar
  • updated
  • Under review

Hello, 

I'm on bOS client 4.8.16 and server 4.11.8

I have a frame with the following Security settings : 

Admin : False

Users Everyone

Hidden False

Locked True

When I try to access it, a screen requesting a pin code does appear. BUT you can get rid of id just by clicking the upper right cross (close window) and access the screen without entering the pin code !! That shouldn't be possible. 

ok, there is a workaround using different users and the Security / Users feature ; but that's not the way I'd like it to operate. 

Kind regards, 

François 

Avatar
Ricardo Pinto

Hello Francois,

I can also confirm the bug, tested right now.

You're right, the PIN protection should work and be enough for this simpler situations. I think I had some similar problem several years ago.

Nonetheless, please report as a ticket, as the regular posts may not be seen in a timely manner to be resolved.

Best regards

Avatar
ComfortClick Support
  • Under review

Hello,

the issue was noticed and immediately resolved with the next beta release, you can download the latest beta where this problem is already resolved. We're also planning on releasing a new stable release very soon with this problem resolved as well.

Apologies for any inconvenience.

Best regards.

Avatar
Francois Lesueur

Thank you for your reactivity.