Chrome store 2FA and not password
Reported by
bau...@gmail.com,
May 5 2017
|
|||||||
Issue descriptionUserAgent: Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.36 Safari/537.36 Steps to reproduce the problem: 1. open https://ctx.olisnet.com 2. enter username, password, 2FA What is the expected behavior? store username, password What went wrong? chrome store username, 2FA and after return to page autofill username (good) but autofill password with previous 2FA Did this work before? N/A Chrome version: 59.0.3071.36 Channel: beta OS Version: 6.3 Flash Version:
,
May 8 2017
oh, new problem for you: it's not as expected.. chrome can store password only when login is success? (but I not reproduce this with 59.0.3071.36 beta (64-bit), work as expected with bad login = not store login/pass) This website is not the best in presentation; I can't share my login/pass/2FA or create account.. this login page is Citrix Netscaler (see screenshot: no second page for 2FA, all in the first page).
,
May 8 2017
Thank you for providing more feedback. Adding requester "brajkumar@chromium.org" to the cc list and removing "Needs-Feedback" label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
May 9 2017
Could someone from password team can look in to this issue?
,
May 12 2017
,
May 16 2017
+kolos I think this will be extremely hard to fix because the site gives us basically this: <div class="right"><input type="password" id="dummy_pass1" name="a1745395780803143" style="display:none"><input type="password" id="passwd" class="prePopulatedCredentials" autocomplete="off" spellcheck="true" name="a1602824153098271" size="30" maxlength="127" width="0"></div> [...] <div class="right"><input type="password" id="dummy_pass2" name="a5960528989311505" style="display:none"><input type="password" id="passwd1" class="prePopulatedCredentials" autocomplete="off" spellcheck="true" name="a0443197341693800" size="30" maxlength="127" width="0"></div> Even the names change after each reload.
,
May 16 2017
It's possible to save the first password only in this situation? same as autocomplete, chrome autocomplete only the first password field. The problem is: if you decide to trust Chrome and save the password, the next time you authenticate the password is wrong, and after several attempts the site blocks access.
,
Jun 1 2017
kolos@ Would you mind checking this issue? Thanks!
,
Jun 8 2017
,
Jun 8 2017
In cases where we cannot rely on the field IDs/names, we should remember their order in the form. That does not answer how to find the true password field, but how to be consistent in filling if the user forces saving the right one with the coming manual fallbacks. |
|||||||
►
Sign in to add a comment |
|||||||
Comment 1 by brajkumar@chromium.org
, May 8 2017Labels: Needs-Feedback