Feature Request: Authenticate-Block (PIN, Password, Fingerprint)

54 views
Skip to first unread message

daniel...@gmail.com

unread,
Jul 31, 2018, 6:54:28 PM7/31/18
to Automate
I've looked through the list of planned features and haven't found anything related to authentication.
What I would like is a block that queries the user to authenticate by PIN, password or fingerprint. My specific use-case would be a GET request towards my Home Automation software that for example would unlock the front door or perform some other security-related task. If I read the news correctly Tasker got that feature not too long ago. It would be nice if Automate would follow.
This of course would only make sense if the Automate App itself had a feature that would only allow to modify flows after successful authentication (for this I have found another thread, suggesting an external app to lock Automate).

Henrik "The Developer" Lindqvist

unread,
Jul 31, 2018, 9:27:40 PM7/31/18
to Automate
A block which simply halts the flow until fingerprint/PIN authentication is nonsense since a "hacker" could simply edit the flow and bypass it anyway.
"Locking" flows to prevent edit also seems unnecessary since you have to unlock the phone to do so, i.e. you're already authorized.

The only reason i see for "run-time" authentication would be to decrypt data. Automate currently doesn't have any encrypt/decrypt features, nor does it support working with "binary" data, which would have to be implemented first.
Anyhow everything is already on the to-do list.

Andreu Pinel

unread,
Jul 7, 2026, 1:31:45 PMJul 7
to Automate for Android
Sorry for bringing this old topic back again.
I think this "ID Request" block makes sense because:
1) if any flow with such block also requires ID (fingerprint, PIN, whatever...) to edit, there's no possibility to remove such block by someone else (assuming they are familiar with automate).
2) even if I am the owner of the device, I may want an ID requirement because I may press a shortcut by mistake (e.g. I may be away from home and open my home's door because I pressed the shortcut by mistake)
3) I can lend the phone to the kids  to play music/videos without having to worry they run a "for-my-eyes-only" flow.

At the end it would be like any other app that requests your fingerprint/PIN/Facial/Pattern... in order to execute specific actions, just for security/confirmation purposes (e.g. paying with a virtual credit card).
I would highly appreciate if this request could be reconsidered. If a dedicated block means too much effort, maybe a "require ID" checkbox option at the "flow beginning" block would be easier.

Thank you and best regards

Andreu Pinel

unread,
Jul 7, 2026, 1:41:09 PMJul 7
to Automate for Android
I forgot, requesting ID confirmation and locking the screen are not the same thing.
1) Locking in Automate forces the PIN/Password, no biometrics can be used
2) A confirmation can be cancelled (so the flow would continue through the "no" branch) and the phone remains usable (back to lending the phone to someone), while locking the phone prevents it from being used at all. Furthermore, once unlocked it will always execute the same rest of the flow, there's no possibility of cancelling (at least not any that I am aware of).

мJ ZЖУ

unread,
Jul 8, 2026, 9:16:38 AMJul 8
to Automate for Android
I would also support this feature since if I want a flow locked or not view able and contain sensitive and not encrypted with password alone.

Henrik "The Developer" Lindqvist

unread,
Jul 8, 2026, 10:18:50 AMJul 8
to Automate for Android
  1. Locking a flow would be very difficult to make 100% secure, a user could export/backup the flow, edit it, import/restore. Also, i don't like implementing ways that prevent users from accessing their own device/apps, since that could become a support nightmare with users claiming they can't stop a flow, etc..
  2. Just show a Dialog input with a PIN/Password, that's would be just a secure.
  3. When lending a device to someone to play a game it's probably best to "pin" the app so they can't exit it. Someone stopping/starting/editing a flow is probably the least damage they could do otherwise.
As said, the Android biometric authentication may eventually be supported, but that will probably only for "unlocking" cryptographic key usage, if users then use it something else, not secure, just for show, is up to them.

Henrik "The Developer" Lindqvist

unread,
Jul 8, 2026, 10:19:04 AMJul 8
to Automate for Android
  1. Using the Interact block with action Lock screen should use biometric lock if that's used as "smart lock".
  2. When i tested the Android biometric authentication feature it seemed that its dialog couldn't even be shown atop the lock screen, so the entire device had to be unlocked first, and as long is unlocked, Automate can always be Force-closed in system settings, there's no way to prevent that.
Reply all
Reply to author
Forward
0 new messages