Sunday, February 23, 2020

Topshop US app for iOS: User restriction of camera roll access not respected

iOS 13.3.1
Topshop US app for iOS (version 5.7.16)
Date: 02/24/2020

Description:

There's a camera roll access bug with the current (5.7.16) version of the Topshop app which is available for download from the app store. This app is similar to a bug with the Tangi app, which was immediately fixed after being reported.

The Topshop US app does not respect the user declining camera roll access. The app displays the following required message:

Selecting "Don't Allow" means nothing - the app still is granted camera roll access, even though the Settings area of the device shows that NEVER is the setting.

The app should respect the clear direction of the user to NOT allow camera roll access. As was stated by a developer response from the Tangi app, the app (or a third-party library used by the app) is doing something wrong.

Note: The word "null" also inexplicably appears in the app!

Steps to Reproduce:

1. Download the Topshop US app for iOS
2. Dismiss the notifications pop-up - Select "SKIP"
3. Select "Scan" from the bottom menu
4. Select "Don't Allow" from the camera prompt
5. Select "Don't Allow" from "Access Your Photos" prompt

Result: The Topshop US app for iOS has full camera roll access, even after the user selects the "Don't Allow" option from an "Access Your Photos" prompt

Expected: The Topshop US app for iOS should NOT have full camera roll access, after the user specifically selects "Don't Allow" from an "Access Your Photos" prompt

Please see the attached screenshots:

Download the app, and then select the "SCAN" option from the bottom menu...

From the camera access prompt, select the "Don't Allow" option...

From the "Access Your Photos" prompt, select "Don't Allow"...

Select the "[null]" option...

App has access to the camera roll...

Head to the Settings area of the iOS device. Look at the settings for "Topshop"...

The "Photos" area says that the app "NEVER" has access to photos on the device...

The device says that the app "Never" has photo access - which is not accurate.


No comments:

Post a Comment