New issue
Advanced search Search tips

Issue 676272 link

Starred by 1 user

Issue metadata

Status: Assigned
Owner:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug



Sign in to add a comment

form-based sign-up and http-auth sign-in are bad for generation

Project Member Reported by vabr@chromium.org, Dec 21 2016

Issue description

Chrome Version: 55.0.2883.87, password generation enabled by a flag
OS: GNU/Linux

What steps will reproduce the problem?
(1) Sign-up for an account on https://www.w3.org/accounts/request
    (Note: see  bug 676267 , also due to the sign-up form reappearing, only a username-less password for the domain will silently be saved.)
(2) Try to validate the account with the link sent to your e-mail.
(3) Observe the http-auth dialogue displayed after clicking Validate.

What is the expected result?
There should be a way to get the generated password filled in the http-auth dialogue.

What happens instead?
Nothing is filled. One has to copy the password over from settings.

This is because internally, Chrome distinguishes between credentials saved on web forms, and credentials saved for http-auth. It won't fill across these two boundaries. However, sign-up credentials always come from forms, while sign-in can be done via http-auth.

Also, it is strange that generation kicked in. Perhaps w3c has also a form-based login page, which I did not find yet.
 

Comment 1 by vabr@chromium.org, Dec 21 2016

Attaching screenshot of the forms, just for illustration.
http-auth.png
15.2 KB View Download
sign-up.png
59.3 KB View Download

Comment 2 by kolos@chromium.org, Mar 9 2017

dvadym@: is it a critical issue? shall we try to fix it now?

Sign in to add a comment