New issue
Advanced search Search tips

Issue 618885 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jul 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 2
Type: Bug



Sign in to add a comment

Chrome save password at domain name level which does NOT work for complex sites

Reported by tp.gam...@gmail.com, Jun 10 2016

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.84 Safari/537.36

Steps to reproduce the problem:
1. Have 3 different forums, all on same website
2. Have 3 different passwords, but same username
3. Chrome gives password but not necessarily for the right site. 

What is the expected behavior?
chrome needs to NOT remember Passwords only at the website.com level. It must remember it at the website.com/forum1/ level so that website.com/forum2/ website.com/blog/, website.com/directory1/ and website.com/directory2/ can all be secured properly. 

What went wrong?
 Chrome saves passwords at domain name level. Chrome can save multiple passwords for 1 site (in this case cPanel) but cannot save password for each URL on that domain.

When, I can not secure things properly, I have the issue that I have to use the same username and same password for every single unique log in situation on my website. Why? I can not remember 8 plus different passwords. 

Did this work before? N/A 

Chrome version: 51.0.2704.84  Channel: stable
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version: Shockwave Flash 21.0 r0

This is also an accessibility accommodation issue because I have Fetal Alcohol Syndrome Disorder and can not afford to buy a "password manager" that has a "password on it" for me to remember. I can't even remember THAT password. I tried that already and failed. The only PW I could remember, was the one that the crackers probably already had. My password are now extremely beyond me. Thanks! (BTW, your competitor does NOT have this issue!
 
Labels: Needs-Feedback
tp.game.s@Could you please provide sample website with actual and expected behavior screencast for better understanding the issue to triage it further.

Comment 2 by tp.gam...@gmail.com, Jun 10 2016

1. When you enter username and password at www.mywebsite.com/blog1/index.php
This username and password SHOULD be saved under that FULL URL. 
 Chrome saves it under: www.mywebsite.com
2. When you enter username and password at www.mywebsite.com/forum/index.php
This username and password SHOULD be saved under that FULL URL. 
 Chrome saves it under: www.mywebsite.com

NOTE: NO blog1 OR forum1 is saved by Chrome. Chrome does not give a rip about which directory the username and password is for, as it thinks that the only thing that matters is the domain name and the shortest version of that domain name as you can get - the one that is registered in icann. 

3. If you have subdomain.mywebsite.com/qwerty123/forum2/index.php
and have subdomain.mywebsite.com/zxcvb8v9/joomla/index.php
Chrome says NO you only have 
subdomain.mywebsite.com
and saves BOTH usernames and password under  subdomain.mywebsite.com
Taking a screen shot of CHROMES:
www.mywebsite.com        username1      password1
www.mywebsite.com        username1      password2
www.mywebsite.com        email1         password3
subdomain.mywebsite.com  username1      password4
subdomain.mywebsite.com  username1      password5
subdomain.mywebsite.com  email1         password6 

...won't give you any more info. When I say chrome ignores the directory part of the URL I mean that it lobs it off and insist that we do not need the directory as apart of the URL that the username and password is supposed to be saved under. 

AND...I found out that Chrome USED to do usernames and password saving correctly under the FULL URL about 4 - 6 weeks ago. https://productforums.google.com/forum/?utm_medium=email&utm_source=footer#!msg/chrome/hGM2veSNcnw/DMEL4dXFHQAJ

that is the forum link. Thanks! 
Project Member

Comment 4 by sheriffbot@chromium.org, Jun 11 2016

Labels: -Needs-Feedback Needs-Review
Owner: ssamanoori@chromium.org
Thank you for providing more feedback. Adding requester "ssamanoori@chromium.org" for another review and adding "Needs-Review" label for tracking.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: -Needs-Review
Owner: ----
Confirm! This bug is really annoying!
afu since one of the last updates !!!
Components: UI>Browser>Passwords

Comment 8 by vabr@chromium.org, Jul 20 2016

Labels: -OS-Windows Hotlist-Polish OS-All
Status: WontFix (was: Unconfirmed)
Thanks for the report.

There are two conflicting use-cases:
(1) 1-account per domain, with, e.g., separate login and change-password forms: example.com/login/index.html and example.com/settings/change.html; if Chrome kept the password stored at the latter separate from the password stored for the former, it would not be able to recognise when the user changes their password, filling it incorrectly the next time the user tries to log in.
(2) The use-case you describe, when multiple separate services run on the same domain and the user requires to have the same username for more of them.

The use-case (2) does not seem to be frequent, there is no popular site known to us which would have two separate login systems where user would be likely to need the same username across both. Because of that and because we cannot serve both, we decided to support (1) only.

You have two possible workarounds: use different usernames, or, if you own the site, register a separate domain for each login system you are running.

Comment 9 Deleted

What part of THIS IS A BUG AND IT WAS WORKING BEFORE Don't you get? The last update is what created this bug! We do not give a rip about "how easy chrome can update username and password" when it can't even give us the right username and password in the first place! 

I am NOT made of money! If Google arrogant corporation wants to pay me $1 million per year to have my crap on separate domains to honor Chromes low IQ, then fine. Humour me! I doubt that greedy company has ever gave a rip about any of its users. I had to jump through hoops to even get the bug reported! And someone else even confirmed that it is a bug!

I do NOT use example.com/login/index.html
and 
example.com/index.html and expect Chrome to see a difference. 

I am using:

sub-domain/example.com/rtlwsx/index.com
and
sub-dopmain/exmaple.com/juzpyterlkj/index.com

Notice that the folders are two VERY different file names completely? 
And no, I do not want to have to log into 30 difference cPanels in order to work behind the scenes on my installations! I do not have the time to waste it on Chrome. 

NOW: to change password and username the OLD way, simply delete the username name and password from settings password manager, delete cookies and you are good to go. Easy - even when my FASD is high! 

NOW: Who cares? I can't even GET the CORRECT USERNAME and PW to even BE on the form, why would I need chrome to be able to know when to change it when it can't even give me any good username and pw? 

PLEASE FIX YOUR BUG! I DO NOT WANT TO HEAR ANYTHING ABOUT USER NEEDS TO DO THINGS DIFFERENTLY - that cost money! I WANT A BUG FIX! If I did not have FASD, I'd be telling YOU how to fix the bug! It was confirmed that I would have been MENSA but for a stupid git of a mother! 

Sign in to add a comment