New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 718747 link

Starred by 1 user

Issue metadata

Status: Available
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug

Blocking:
issue 771657



Sign in to add a comment

Chrome store 2FA and not password

Reported by bau...@gmail.com, May 5 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.36 Safari/537.36

Steps to reproduce the problem:
1. open https://ctx.olisnet.com
2. enter username, password, 2FA

What is the expected behavior?
store username, password

What went wrong?
chrome store username, 2FA and after return to page autofill username (good) but autofill password with previous 2FA

Did this work before? N/A 

Chrome version: 59.0.3071.36  Channel: beta
OS Version: 6.3
Flash Version:
 
Cc: brajkumar@chromium.org
Labels: Needs-Feedback
Tested this issue on Windows-10 using chrome latest Beta #59.0.3071.36. By opening the site https://ctx.olisnet.com/vpn/index.html observed a log on page displayed. Entered random username and password in the fields and clicked on Log on button. Observed pop-up displayed to save username and password as expected.

baudav@ could you please let us know where to access 2FA? Is there any sample test account available to check this issue?


Comment 2 by bau...@gmail.com, May 8 2017

oh,  new problem for you: it's not as expected.. chrome can store password only when login is success?  (but I not reproduce this with 59.0.3071.36 beta (64-bit), work as expected with bad login = not store login/pass)

This website is not the best in presentation; I can't share my login/pass/2FA or create account.. this login page is Citrix Netscaler (see screenshot: no second page for 2FA, all in the first page).

 
netscaler_2017-05-08_10-11-23.png
166 KB View Download
Project Member

Comment 3 by sheriffbot@chromium.org, May 8 2017

Labels: -Needs-Feedback
Thank you for providing more feedback. Adding requester "brajkumar@chromium.org" to the cc list and removing "Needs-Feedback" label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Components: -UI UI>Browser>Passwords
Could someone from password team can look in to this issue?
Labels: Needs-Triage-M59

Comment 6 by battre@chromium.org, May 16 2017

Cc: kolos@chromium.org
+kolos

I think this will be extremely hard to fix because the site gives us basically this:

<div class="right"><input type="password" id="dummy_pass1" name="a1745395780803143" style="display:none"><input type="password" id="passwd" class="prePopulatedCredentials" autocomplete="off" spellcheck="true" name="a1602824153098271" size="30" maxlength="127" width="0"></div>
[...]
<div class="right"><input type="password" id="dummy_pass2" name="a5960528989311505" style="display:none"><input type="password" id="passwd1" class="prePopulatedCredentials" autocomplete="off" spellcheck="true" name="a0443197341693800" size="30" maxlength="127" width="0"></div>

Even the names change after each reload.

Comment 7 by bau...@gmail.com, May 16 2017

It's possible to save the first password only in this situation? same as autocomplete, chrome autocomplete only the first password field.

The problem is: if you decide to trust Chrome and save the password, the next time you authenticate the password is wrong, and after several attempts the site blocks access.
kolos@ Would you mind checking this issue?

Thanks!

Comment 9 by kolos@chromium.org, Jun 8 2017

Description: Show this description

Comment 10 by vabr@chromium.org, Jun 8 2017

Blocking: 674151
Labels: Hotlist-Polish
Status: Available (was: Unconfirmed)
In cases where we cannot rely on the field IDs/names, we should remember their order in the form. That does not answer how to find the true password field, but how to be consistent in filling if the user forces saving the right one with the coming manual fallbacks.

Comment 11 by kolos@chromium.org, Feb 16 2018

Blocking: -674151 771657
Should be fixed in 2018. Assigning to the umbrella bug of such issues.

Sign in to add a comment