Tuesday, May 30, 2017

Halide iOS app - app crashes if you turn on the flash feature on an iPad Mini

Halide app (version 1.0)
Date: 05/31/2017

Description:

The Halide app for iOS will crash on the iPad Mini after you toggle on the flash feature and then snap a photograph.

Please see the attached screenshots. Here's the crash dump.

Steps to reproduce:

1. Download and launch the app on an iPad Mini
2. Swipe down to display the flash option
3. Toggle on the flash
4. Take a photo

Result: On an iPad Mini, the Halide app will crash after the user toggles on the flash option and snaps a photograph

Expected: On an iPad Mini, the Halide app should not crash after the user toggles on the flash option and then snaps a photograph



Download the app.


Toggle the flash option.
Snap a photo.

Tuesday, May 16, 2017

ZerAppa iOS apps – Twitter sign-in requires “full access to Direct Messages”

Numerous ZerAppa apps
Date: 05/16/2017

Description:

Looks as if many (perhaps all) apps released by ZerAppa require “full access to Direct Messages” if you want to use your Twitter credentials to create a new account inside of the app.

That’s asking for a permission that very few apps ask for. It’s also something that large corporations have routinely had to apologize for - namely, trying to trick users into granting them access.

This should be changed, and small restaurants, bars or exercise places shouldn’t be giving the impression they are able to peek into the private messages of users who use Twitter to create accounts.

Please see the attached screenshots taken from the HonestAbe’s Tap & Grill app.

I’m not OCD enough (at least not yet!) to download all 121 apps released by ZerAppa to see if they all require this permission. But, since the first seven I downloaded all did require this permission, I am willing to guess this is pretty common with apps released by ZerAppa.



Steps to Reproduce:

1.     Download Honest Abe’s Tap & Grill for iOS
2.     Launch the app, dismiss the pop up messages
3.     Select the settings icon in the upper right hand corner of the screen (above Abe)
4.     From “Accounts” select the “Connect >” next to Twitter
5.     Note that “full access to Direct Messages” is a requirement for creating an account using your twitter credentials

Result: Numerous apps released by ZerAppa require “full access to Direct Messages” for users who want to use their Twitter credentials to create an account

Expected: The requirement of “full access to Direct Messages” should NOT be required for users who want to use their Twitter credentials to create new accounts in ZerAppa apps

Select the settings option in upper right...

Choose the connect option for Twitter...

Monday, May 15, 2017

Michael's Pizza & Pasta app by VRINDI INC. gives an "Error on line 3 at column 6" error message

Michael's Pizza & Pasta app (version 1.0) on an iPad Mini 
Date: 05/16/2017

Description:

I downloaded an app called Michael's Pizza & Pasta by a company called VRINDI. Michael's Pizza & Pasta is a pizza place in White Plains, New York.

When you launch this particular app, you'll receive an error message. The error message is:

"error on line 3 at column 6: XML declaration allowed only at the start of this document"

Please see the attached screenshots. Judging by some comments I read on the internet, this is a problem related to (yes, again!) trailing whitespaces!

Steps to reproduce:

1. Download and launch the Michael's Pizza & Pasta app
2. Note the error message

Result: The Michael's Pizza & Pasta app displays an error message that states, "error on line 3 at column 6: XML declaration allowed only at the start of this document"

Expected: No error messages after launching the Michael's Pizza & Pasta app


Download Michael's Pizza & Pasta, then launch it...


This is the error I get.