Wednesday, May 29, 2019

Barneys New York app for iOS: Error Messaging: Can't use plaintext as a password - no explanation why

Barneys New York app for iOS (version 3.6)
Date: 05/29/2019

Description:

Unusual error message is displayed during account creation, if the user attempts to use <plaintext> as password.

An error message pop-up that says:

"Error
Expected status code in (200-299), got 403"



Is displayed if the user uses <plaintext> as a password.

I have not usually seen <plaintext> prohibited with other apps, or, if it is, there is usually a message about unsupported characters. No such message with Barney's New York app for iOS.

This is easier to show than it is to describe, so please see the attached screenshots.

Steps to Reproduce:

1. Download and launch the Barneys New York app for iOS (version 3.6)
2. Select the "My Account" option on the bottom right
3. Select "SIGN IN / REGISTER"
4. Select "CREATE AN ACCOUNT"
5. Enter in a valid First Name
6. Enter in a valid Last Name
7. Enter in a valid Email
8. Enter in <plaintext> as a password
9. Enter in <plaintext> to confirm password
10. Click on "SIGN UP"

Result: Unusual error message if the user attempts to create an account using <plaintext> as their password - error message is uninformative

Expected: User should either be able to create an account that uses <plaintext> as a password, or there should be an understandable error message

Enter in the term <plaintext> as a password when creating a new account for the Barneys New York iOS app...

With <plaintext> entered in, click on SIGN UP...

Unusual error message. Usually <plaintext> is allowed as a password. If it isn't, then there is usually an informative error message explaining that certain characters are prohibited.

No comments:

Post a Comment