New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 726270 link

Starred by 1 user

Issue metadata

Status: Assigned
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 3
Type: Bug



Sign in to add a comment

We offer to save card locally on Linux but do not offer to save unmasked server card

Project Member Reported by csashi@google.com, May 25 2017

Issue description

Chrome Version: 58.*
OS: Linux

What steps will reproduce the problem?
(1) Do not sign-in to Chrome.
(2) Visit dump-truck.appspot.com and fill forms with default values and submit.
(3) Chrome should offer to save card locally (See: https://cs.chromium.org/chromium/src/components/autofill/core/browser/autofill_manager.cc?l=1232&rcl=4dd065a3be8399b968ae44e93f1997254c173e84)

(4) Save a card on payments.google.com
(5) Sign-to Chrome
(6) Visit dump-truck.appspot.com and fill form by unmasking a card saved in step (4).
(7) Chrome will not offer to save the card locally (See: https://cs.chromium.org/chromium/src/components/autofill/core/browser/autofill_experiments.cc?l=162&rcl=4dd065a3be8399b968ae44e93f1997254c173e84)

What is the expected result?

We should either allow both saves or neither. What is the difference (security-wise) between these 2 cases?

What happens instead?

We only offer save for local cards, not unmasked server cards.

 
Project Member

Comment 1 by sheriffbot@chromium.org, May 25 2017

Status: Assigned (was: Untriaged)
Labels: -Type-Bug-Security Type-Bug
This doesn't sound like a security bug, only a functional issue.

Comment 3 by jsaul@google.com, May 25 2017

Cc: csashi@google.com
Components: -UI>Browser>Autofill>Payments UI>Browser>Payments
Project Member

Comment 6 by sheriffbot@chromium.org, Jul 14 2017

Labels: Hotlist-Google
Components: -UI>Browser>Payments UI>Browser>Autofill

Comment 8 by ma...@chromium.org, May 1 2018

Status: Untriaged (was: Assigned)
Status: Assigned (was: Untriaged)
This bug has an owner, thus, it's been triaged. Changing status to "assigned".

Sign in to add a comment