NextPass is a native, independent, unofficial Ubuntu Touch client for the Passwords app for Nextcloud.

It is designed specifically for the Ubuntu Touch browser workflow: search for one account, copy the username, open the website in Morph Browser, and copy the password only when it is actually needed.

DESIGN AND SECURITY DECISIONS

On-demand only
- NextPass makes no automatic network connection when the app starts.
- Network access begins only after Search, Test and save, Retry, or Copy password.
- No background synchronization or periodic refresh.
- The Qt network access manager is created lazily only after an explicit network action, so merely opening NextPass does not initialize its HTTP client.
- Search requires at least two characters and starts only after Search/Enter; there is no search-as-you-type.

Dedicated app passwords only
- NextPass intentionally has no normal Nextcloud account-password field.
- It accepts only the dedicated Nextcloud app-password shape xxxxx-xxxxx-xxxxx-xxxxx-xxxxx, with five groups of five ASCII alphanumeric characters.
- The app-password field uses the full dialog width; Show/Hide, Paste, and Copy buttons are below it.
- Pasted values are normalized by removing whitespace before validation, then the complete pasted token is validated once. A valid paste therefore does not flash a false invalid-format warning while it is being inserted. Copy selects the complete entered app password and copies it to the clipboard.
- Normal typing is not rejected mid-entry. The completed value is validated when Test and save or Retry is pressed, and invalid format is reported before any network request.
- This is a format check. A deliberately constructed normal password with exactly the same shape cannot be cryptographically distinguished, so the UI and documentation explicitly require a dedicated app password.

Filesystem access must be OFF
- NextPass has no reason to access Nextcloud Files.
- Before accepting credentials, before search, and before retrieving a selected password, NextPass creates a unique temporary WebDAV test path using MKCOL at /remote.php/dav/files/<username>/.nextpass-fs-probe-<uuid>.
- This deliberately tests the filesystem permission itself. PROPFIND is not used for the decision because a disabled app password can still see the DAV root, and a user with an empty root would otherwise be indistinguishable from a disabled token.
- MKCOL HTTP 201 proves filesystem access. NextPass immediately DELETEs only that exact random probe path and rejects the app password with a prominent `Filesystem access detected` error.
- MKCOL HTTP 401 or 403 is treated as explicit filesystem denial. The same credential must then successfully authenticate to the Passwords API before it is accepted.
- Cleanup is attempted only after MKCOL returned 201 for that exact path. If cleanup cannot be confirmed, the credential is still rejected and NextPass reports the probe name so it can be removed manually.
- The settings dialog stays open and the app password remains entered so the user can change the Nextcloud setting and press Retry without retyping or repasting the token.
- A button opens the Nextcloud security-settings page from the blocked dialog.

Fail closed
- NextPass blocks use if it cannot prove filesystem access is disabled.
- TLS certificate errors are never ignored.
- Authenticated redirects are not followed.
- Timeouts, connection failures, unexpected WebDAV statuses, and ambiguous responses block the operation.
- The canonical HTTPS Nextcloud base URL must be configured.

HTTPS only
- HTTP Nextcloud URLs are rejected.
- Embedded URL credentials, query strings, and fragments are rejected.
- Nextcloud installations in a URL subdirectory are supported.

Short Passwords API sessions
- NextPass uses the Passwords X-API-SESSION mechanism.
- Sessions are opened only for an explicit operation.
- NextPass requests session closure afterward and discards its local session identifier.

Search model
- The Passwords server password/find endpoint does not provide text search over label, username, URL, notes, or password values.
- NextPass therefore retrieves password models and performs local matching only over label, username, and URL.
- Notes, custom fields, and password contents are not search criteria.

No retained decrypted vault
- The Passwords model API includes the password field in the same object as searchable metadata, so non-CSE password values necessarily arrive over TLS during a list request.
- NextPass does not retain the complete list as a decrypted in-memory vault.
- It reads the top-level JSON response incrementally and processes one password object at a time.
- It stores only ID, label, username, and URL for matching results.
- The password value is discarded during search, including for matching results.
- This minimizes exposure but does not claim that an individual secret never enters process memory, because the upstream model API includes it in that object's JSON.

Explicit password retrieval
- Copy password performs a separate request for only the selected password entry.
- It repeats the filesystem restriction check first.
- The selected password is copied to the system clipboard only after the user explicitly presses Copy password.

Browser copy/paste workflow
- Each result provides Copy user, Copy password, Copy site, and Open site.
- Copy site copies the stored website URL for pasting into any browser. Open site allows only HTTP and HTTPS URLs. Result actions use compact icons and show their descriptions on long press.
- Clipboard/search timeout is configurable from 15 to 120 seconds in 15-second steps; the default remains 45 seconds.
- A completed search starts the timeout. Copying a username, website URL, retrieved password, or app password restarts it so NextPass search state and its most recently copied value expire together.
- When the timeout fires, the search box and all current search results are cleared, including after a zero-result search.
- NextPass stores only a SHA-256 hash for the delayed clipboard comparison, so it does not keep another plaintext copied value merely to expire the clipboard.
- If the clipboard still contains the value copied by NextPass when the timer fires, NextPass overwrites it with `[NextPass clipboard expired]` instead of relying on clipboard clear, which was unreliable on the tested Ubuntu Touch clipboard implementation.
- If the user copied something else, NextPass leaves the newer clipboard content untouched while still clearing the expired search state.

Client-side encryption limitation
- NextPass 0.1.9 detects Passwords CSE entries such as CSEv1r1 but does not implement the CSE cryptographic protocol yet.
- CSE entries are skipped during search and reported to the user.
- CSE password retrieval is rejected rather than pretending the entry is supported.
- CSE support must be implemented independently because the upstream Passwords server/client projects are AGPL-3.0 while NextPass is MIT-0.

Backup and phone migration
- Backup and restore is available from the hamburger menu.
- Configuration is exported as UTF-8 JSON through Content Hub.
- Password entries are not copied into the backup; they remain on the Nextcloud server.
- Include credentials/secrets is optional and off by default. When enabled, the dedicated Nextcloud app password is written to the JSON in plaintext. Protect or delete that file after migration.
- Without secrets, connection settings are restored and the app password must be entered again.

Remembering the app password
- Remember app password is optional and OFF by default.
- If enabled, the revocable app token is stored in NextPass's private Qt settings area inside the Ubuntu Touch application sandbox.
- This private settings storage is not an encrypted or hardware-backed secret store; the option exists as an explicit convenience/security tradeoff.
- If remembering is disabled, the app password is retained only for the current NextPass process after successful verification.
- Forget connection removes saved connection data, any remembered app password, and current results.

Ubuntu Touch integration
- Native Qt/QML application.
- Ubuntu Touch 24.04.
- arm64.
- Square PNG cloud-and-key logo with no pre-rounded corners so the OS/store can apply the user's selected corner treatment.
- Light mode and dark mode.
- Hamburger menu at the top right.
- About dialog includes version 0.1.9.
- AppArmor requests networking plus Content Hub exchange/source access for backup import and export.
- No filesystem, camera, microphone, location, contacts, background-service, or privileged permission groups.
- NextPass does not request broader NetworkManager permissions merely to silence Qt bearer-management probes; the HTTP network manager is created lazily and Qt bearer polling is disabled.

Fresh Retry verification
- Every MKCOL filesystem probe uses an isolated network manager; cleanup DELETE also uses an isolated manager.
- Automatic cookie loading/saving and cached HTTP-authentication reuse are disabled for these requests.
- No-cache headers are sent and the requests ask the connection to close.
- WebDAV receives only the app-password Basic Authorization header and never a Passwords API session header.
- Retry therefore tests the current server-side scope without requiring an application restart.
- Safe diagnostics log only MKCOL/DELETE HTTP status and Qt network error numbers, never credentials or password data.

Privacy
- no advertising
- no analytics
- no tracking
- no telemetry
- no developer-operated cloud service
- no background sync
- no startup network connection
- no local password-vault database
- direct communication only with the user's configured Nextcloud server

NextPass is not affiliated with or endorsed by Nextcloud GmbH or the Passwords project.

The Passwords app for Nextcloud is an AGPL-3.0 project by Marius David Wieschollek and contributors. NextPass does not bundle or copy the Passwords server implementation or its JavaScript client; it independently implements the HTTP interoperability surface with Qt Network.

This app was vibe coded with AI assistance. The source code is published for inspection and improvement.

NextPass is released under MIT No Attribution, SPDX identifier MIT-0.

MIT No Attribution

Copyright 2026 Barry de Graaff

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

