New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 605735 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Apr 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Android
Pri: 2
Type: Bug-Security



Sign in to add a comment

Removing Google account from phone does not clear autofill data and causes merge problems

Project Member Reported by jsaul@google.com, Apr 21 2016

Issue description

Steps to reproduce the problem:
(Vaguely related to crbug 589028, rouslan@ asked me to spin it into a new issue)

1. Add a Google account to your Android phone, sign in through Chrome
2. See that all of your data is synced (see screenshot #1)
3. Don't sign out through Chrome.  Rather, go to Android's settings and remove the account entirely.
4. Chrome shows you as not signed in (see screenshot #2)
5. Clicking on Autofill Forms reveals that all of my NON-Google Payments addresses and credit cards are still freely available (see screenshot #3)

BONUS PROBLEM:
6. Add *another* Google account to your Android phone
7. Try to sign in through Chrome
8. Chrome says the *old* account is already signed in, and signing in with the new account will merge all your data and bookmarks and whatnot.

Screenshots (hosted on Googleplex because CC data):
[1] https://screenshot.googleplex.com/E7tNmotbk2a.png
[2] https://screenshot.googleplex.com/Xkqn2bOMrOh.png
[3] https://screenshot.googleplex.com/5uhNGF9Crp1.png

What is the expected behavior?
Chrome logs you out and clears all data when an account is removed from the phone.

What went wrong?
Chrome is essentially not completely logging me out when my account is cleared from the phone.  Additionally, since Chrome tries to merge any new account that signs in, the only way to actually fix this problem is to *re-add* the account to the phone, then sign out through Chrome, then re-remove the account.

Did this work before? N/A 

Chrome version: 49.0.2623.105  Channel: stable
OS Version: 
Flash Version:
 

Comment 1 by jsaul@google.com, Apr 21 2016

Can whoever sees this please CC rouslan@ and jdonnelly@?  Thanks!

Comment 2 by mea...@chromium.org, Apr 21 2016

Cc: rouslan@chromium.org jdonnelly@chromium.org
Components: Services>SignIn UI>SignIn Services>SignInSSO
Adding some components to get the right folks chimed in.

Comment 4 by vakh@chromium.org, Apr 22 2016

Labels: Security_Severity-Low Security_Impact-Stable
Owner: bzanotti@chromium.org
Status: Assigned (was: Unconfirmed)
bzanotti@ -- marking you as the owner based on the current components.
If you are the right person, that's great.
If not, but you know who the right person is, please assign it to them.
Otherwise, please remove yourself as the owner and I'll resume my hunt :)
Cc: anthonyvd@chromium.org bzanotti@chromium.org
Owner: ew...@chromium.org
I am probably not the correct owner, I work almost exclusively on iOS.

That being said, we probably have the same issue on iOS as well. Not clearing browsing data when signing out an account is actually a feature so I guess this would be Working as Intended?

Looping in Chrome Signin PM (ewald@) and eng (anthonyvd@).

Elias: Can you confirm this is intended?

Comment 6 by ew...@chromium.org, Apr 22 2016

Status: WontFix (was: Assigned)
There are a couple different things going on here.

1) We never auto-clear your browser data on sign out (whether you signed out because you removed the account or because you clicked "Sign out of Chrome"). This is indeed WAI. If you want to clear your data, you should just clear your browsing data.

2) The UX for clearing/merging data as you switched sync accounts (by signing out and back in) was horrific pre-M50 (as you mentioned). This has been fixed in M50 as part of our sign-in/account settings revamp. If you go through this same flow again in M50, you *should* get a dialogue which asks whether you want to import your old data to your new account (as you're signing in with your newly added account) or keep your data separate by clearing it. I believe this addresses the "bonus problem" :)

I'm marking this as Won'tFix for now, since I think that addresses both your issues. Please re-open if that's incorrect.

Comment 7 by jsaul@google.com, Apr 22 2016

I believe that does address both of my issues.  Thank you very much for the explanation, ewald.
Project Member

Comment 8 by sheriffbot@chromium.org, Jul 30 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 9 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 10 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment