Chrome save password at domain name level which does NOT work for complex sites
Reported by
tp.gam...@gmail.com,
Jun 10 2016
|
|||||
Issue descriptionUserAgent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.84 Safari/537.36 Steps to reproduce the problem: 1. Have 3 different forums, all on same website 2. Have 3 different passwords, but same username 3. Chrome gives password but not necessarily for the right site. What is the expected behavior? chrome needs to NOT remember Passwords only at the website.com level. It must remember it at the website.com/forum1/ level so that website.com/forum2/ website.com/blog/, website.com/directory1/ and website.com/directory2/ can all be secured properly. What went wrong? Chrome saves passwords at domain name level. Chrome can save multiple passwords for 1 site (in this case cPanel) but cannot save password for each URL on that domain. When, I can not secure things properly, I have the issue that I have to use the same username and same password for every single unique log in situation on my website. Why? I can not remember 8 plus different passwords. Did this work before? N/A Chrome version: 51.0.2704.84 Channel: stable OS Version: 6.1 (Windows 7, Windows Server 2008 R2) Flash Version: Shockwave Flash 21.0 r0 This is also an accessibility accommodation issue because I have Fetal Alcohol Syndrome Disorder and can not afford to buy a "password manager" that has a "password on it" for me to remember. I can't even remember THAT password. I tried that already and failed. The only PW I could remember, was the one that the crackers probably already had. My password are now extremely beyond me. Thanks! (BTW, your competitor does NOT have this issue!
,
Jun 10 2016
1. When you enter username and password at www.mywebsite.com/blog1/index.php This username and password SHOULD be saved under that FULL URL. Chrome saves it under: www.mywebsite.com 2. When you enter username and password at www.mywebsite.com/forum/index.php This username and password SHOULD be saved under that FULL URL. Chrome saves it under: www.mywebsite.com NOTE: NO blog1 OR forum1 is saved by Chrome. Chrome does not give a rip about which directory the username and password is for, as it thinks that the only thing that matters is the domain name and the shortest version of that domain name as you can get - the one that is registered in icann. 3. If you have subdomain.mywebsite.com/qwerty123/forum2/index.php and have subdomain.mywebsite.com/zxcvb8v9/joomla/index.php Chrome says NO you only have subdomain.mywebsite.com and saves BOTH usernames and password under subdomain.mywebsite.com Taking a screen shot of CHROMES: www.mywebsite.com username1 password1 www.mywebsite.com username1 password2 www.mywebsite.com email1 password3 subdomain.mywebsite.com username1 password4 subdomain.mywebsite.com username1 password5 subdomain.mywebsite.com email1 password6 ...won't give you any more info. When I say chrome ignores the directory part of the URL I mean that it lobs it off and insist that we do not need the directory as apart of the URL that the username and password is supposed to be saved under. AND...I found out that Chrome USED to do usernames and password saving correctly under the FULL URL about 4 - 6 weeks ago. https://productforums.google.com/forum/?utm_medium=email&utm_source=footer#!msg/chrome/hGM2veSNcnw/DMEL4dXFHQAJ that is the forum link. Thanks!
,
Jun 10 2016
What chrome SHOULD be saving is: www.mywebsite.com/qwerty123/forum1/index.php username1 password1 www.mywebsite.com/zxcv78b/blog1/index.php username1 password2 www.mywebsite.com/forumname/forum2/index.php email1 password3 subdomain.mywebsite.com/book/joomla/index.php username1 password4 subdomain.mywebsite.com/venushatesmars/peacesocial/index.php username1 password5 subdomain.mywebsite.com/crapper/forum3/index.php email1 password6
,
Jun 11 2016
Thank you for providing more feedback. Adding requester "ssamanoori@chromium.org" for another review and adding "Needs-Review" label for tracking. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jun 20 2016
,
Jun 21 2016
Confirm! This bug is really annoying! afu since one of the last updates !!!
,
Jul 19 2016
,
Jul 20 2016
Thanks for the report. There are two conflicting use-cases: (1) 1-account per domain, with, e.g., separate login and change-password forms: example.com/login/index.html and example.com/settings/change.html; if Chrome kept the password stored at the latter separate from the password stored for the former, it would not be able to recognise when the user changes their password, filling it incorrectly the next time the user tries to log in. (2) The use-case you describe, when multiple separate services run on the same domain and the user requires to have the same username for more of them. The use-case (2) does not seem to be frequent, there is no popular site known to us which would have two separate login systems where user would be likely to need the same username across both. Because of that and because we cannot serve both, we decided to support (1) only. You have two possible workarounds: use different usernames, or, if you own the site, register a separate domain for each login system you are running.
,
Jul 20 2016
What part of THIS IS A BUG AND IT WAS WORKING BEFORE Don't you get? The last update is what created this bug! We do not give a rip about "how easy chrome can update username and password" when it can't even give us the right username and password in the first place! I am NOT made of money! If Google arrogant corporation wants to pay me $1 million per year to have my crap on separate domains to honor Chromes low IQ, then fine. Humour me! I doubt that greedy company has ever gave a rip about any of its users. I had to jump through hoops to even get the bug reported! And someone else even confirmed that it is a bug! I do NOT use example.com/login/index.html and example.com/index.html and expect Chrome to see a difference. I am using: sub-domain/example.com/rtlwsx/index.com and sub-dopmain/exmaple.com/juzpyterlkj/index.com Notice that the folders are two VERY different file names completely? And no, I do not want to have to log into 30 difference cPanels in order to work behind the scenes on my installations! I do not have the time to waste it on Chrome. NOW: to change password and username the OLD way, simply delete the username name and password from settings password manager, delete cookies and you are good to go. Easy - even when my FASD is high! NOW: Who cares? I can't even GET the CORRECT USERNAME and PW to even BE on the form, why would I need chrome to be able to know when to change it when it can't even give me any good username and pw? PLEASE FIX YOUR BUG! I DO NOT WANT TO HEAR ANYTHING ABOUT USER NEEDS TO DO THINGS DIFFERENTLY - that cost money! I WANT A BUG FIX! If I did not have FASD, I'd be telling YOU how to fix the bug! It was confirmed that I would have been MENSA but for a stupid git of a mother! |
|||||
►
Sign in to add a comment |
|||||
Comment 1 by ssamanoori@chromium.org
, Jun 10 2016