New issue
Advanced search Search tips

Issue 601359 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Feb 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 1
Type: Bug



Sign in to add a comment

`requireUserMediation` not working as expected on Credential Managment API

Project Member Reported by agektmr@chromium.org, Apr 7 2016

Issue description

Version: Version 51.0.2701.0 canary (64-bit)
OS: Mac OS X 10.11.4

What steps will reproduce the problem?
(1) go to https://legacy-cma-dot-credential-management-sample.appspot.com/
(2) Register yourself using fake id/password
(3) Signout
Repeat 2 and 3 for couple times.

What is the expected output?
Once intentionally signed out, you should be able to see `/` page.

What do you see instead?
Forced to auto sign in and redirected to `/main` even though `requireUserMediation()` is called when signing out.
 

Comment 1 by mkwst@chromium.org, Apr 7 2016

Status: Started (was: Untriaged)
I'll try to reproduce this. It's the second report I've seen about `requireUserMediation()` not working, so there's got to be something there.

Comment 2 by mkwst@chromium.org, Apr 7 2016

Investigating this uncovered an issue in `body` processing: https://codereview.chromium.org/1862293003 resolves the 403 errors thrown by `/register`. Still no luck reproducing the core of the issue, though, agektmr@.
I have reproduced the issue.

Revised steps :
(1) go to https://legacy-cma-dot-credential-management-sample.appspot.com/
(2) Register yourself using fake id/password
(3) Sign out
(4) Sign in
(5) Sign out

At step (3), the credential is stored without any consents or bubble.
At step (4), id/password will be auto filled.
After (5), the user will be automatically signed in.

Comment 4 by mkwst@chromium.org, Apr 8 2016

Cc: cfroussios@chromium.org
Eiji seems to be seeing this sporadically. I haven't been able to reproduce it on Linux. Christos (CC'd), can no longer reproduce a similar-sounding issue he saw on Chrome OS.

I'll poke at it a bit today on Mac to see if I can make it show up there.
I have started to see this behavior again following the steps I have raised on comment #3 OR:
(0) remove id/password at chrome://settings/passwords
(1) go to https://legacy-cma-dot-credential-management-sample.appspot.com/
(2) Sign in using form
(3) Sign out
(4) Sign in
(5) Sign out

Can you please check?

Comment 6 by rbyers@chromium.org, Nov 18 2016

Components: Blink>SecurityFeature

Comment 7 by mkwst@chromium.org, Feb 23 2017

Owner: ----
Status: WontFix (was: Started)
I don't believe this is happening in Chrome today. I poked at it again this morning, and was not able to reproduce. Please reopen the bug if you're still seeing this, Eiji!

Sign in to add a comment