Implemented with and 2f5622edaf84a15f239c6bdaa483ca3da40b8958 and 2e6a3efd253a986cf177f812d47b64f0e611f1e0.
Password stored as plain text in the "accounts.db" file
In the database found under “/data/system/users/0/accounts.db” the owncloud password is stored as plain text.
This means anyone with root access on the phone, probablly including closed source apps that need root, can aquire the password.
This might lead to the discussion that a rooted phone is always a risk, however it would still be nice to add an additional layer of security here.
Thanks for your suggestion, but this is intended Android design. DAVdroid uses the Android account management and password methods. Additional security would have to be implemented in this API.