cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Want to learn some quick and useful tips to make your day easier? Check out how Calvin uses Replay to get feedback from other teams at Dropbox here.

Dropbox API Support & Feedback

Find help with the Dropbox API from other developers.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Dropbox Chooser Captcha Security Issues

Dropbox Chooser Captcha Security Issues

edev
Explorer | Level 3

My company is working on utilizing the Chooser in our web app. We have been experiencing a lot of intermittent issues with being able to view the login page in the the Chooser popup window. 

 

This is also specifically visible from your own demo on the following page:

https://www.dropbox.com/developers/chooser

 

From a user experience, when you activate the chooser who is not signed in, you are prompted with a page to sign in but the form may or may not disappear. We have tracked this down to the recaptcha having security issues. It appears you have been adding and then removing over the last couple of days so its difficult to depend on the Chooser at this time for us to release the app. 

 

Can you confirm this? What is the the status and plan to resolve this?

9 Replies 9

Greg-DB
Dropbox Staff
Thanks for the report! I'm not sure I fully follow this though. Can you share a set of screenshots or a screencast showing the issue so we can look into it? Thanks in advance!

edev
Explorer | Level 3

Im putting together screens now but while i do this you should be able to test yourself by using latest version of Chrome or FF and going to...

https://www.dropbox.com/developers/chooser

 

Make sure you are signed ou of dropbox...

 

In the demo section click on the "Choose from Dropbox" button.

 

Verify popup tries to prompt you a log in and thenit disappears. Check your console for errors.

Greg-DB
Dropbox Staff
Thanks! We'll try that out, but please do share the screenshots whenever you can so we can make sure we can reproduce exactly what you're seeing.

edev
Explorer | Level 3

Greg-DB
Dropbox Staff
Thanks! That's helpful. We'll look into it.

edev
Explorer | Level 3

Thank you for the immediate look into this.

Again, I will state that this has been intermittent over the last few days. Prior to that, I am uncertain as to how long this has been happening.

 

edev
Explorer | Level 3

Testing again on this issue and so far things seem to be working again, but I am also recognizing that no Captcha is in place on the chooser login at this time. 

 

So I would say its "working", but the actual captcha issue is not quite resolved. At least I would not expect it to be resolved until a captcha appears on the chooser login, and the login form itself does not disappear based on the security issue mentioned.

 

Greg - were you able to find out any information since your last post?

Greg-DB
Dropbox Staff

We were able to reproduce this, but I don't have an update from the team yet.

 

The captcha usually isn't shown anyway though, and is only displayed when possibly needed, as determined by our automated abuse system, so it's expected that you wouldn't reliably see the captcha/captcha issue.

Greg-DB
Dropbox Staff

This should be fixed. The captcha should be properly shown when necessary now. Please let me know if you're still seeing any issues.

Need more support?
Who's talking

Top contributors to this post

  • User avatar
    Greg-DB Dropbox Staff
  • User avatar
    edev Explorer | Level 3
What do Dropbox user levels mean?