New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 730465 link

Starred by 4 users

Issue metadata

Status: Available
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 3
Type: Bug

Blocking:
issue 699530



Sign in to add a comment

Undo paste in username field still shows up in Google Smart Lock remember dialog after login

Reported by i...@stefanbonnici.com, Jun 7 2017

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36

Steps to reproduce the problem:
1. Fill in username and password. Do not sign in yet.
2. Paste something in the username using CMD + V
3. Undo the paste using CMD + Z
4. Login
5. The pasted but deleted phrase still shows up in the Google Smart Lock dialog

What is the expected behavior?
I expect that the deleted phrase is forgotten entirely and does not show up in the Google Smart Lock dialog

What went wrong?
The pasted but deleted phrase still shows up in the Google Smart Lock dialog appended to the username.

Did this work before? N/A 

Chrome version: 58.0.3029.110  Channel: n/a
OS Version: OS X 10.11.6
Flash Version:
 
username-paste-undo-problem.jpg
75.1 KB View Download
Components: UI>Browser>Passwords
This definitely looks like a functional issue; it may well occur due to code that tries to keep track of the username after it's manipulated by JavaScript (e.g. some sites will replace parts of the username string with **** after the field is exited).

The security impact seems Low to None, insofar as this only gives a local viewer the opportunity to re-view a string that was just displayed.
Labels: Needs-Feedback
I haven't been able to reproduce this on a simple page (http://http://debugtheweb.com/test/forms/password.asp) in Chrome 59 or Canary. 

Are you able to reproduce this on every page? Is the URL of the site in your screenshot public?
I cannot share the URL and credentials, but I just tried and have managed to reproduce this on multiple WordPress websites. Not sure if it helps you, but I had passwords saved so username/password fields were prefilled upon page load.
Project Member

Comment 4 by sheriffbot@chromium.org, Jun 8 2017

Cc: elawrence@chromium.org
Labels: -Needs-Feedback
Thank you for providing more feedback. Adding requester "elawrence@chromium.org" to the cc list and removing "Needs-Feedback" label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Owner: tengs@chromium.org
Status: Assigned (was: Unconfirmed)
tengs@: I don't know if the bug is in Smart Lock per se, but could you help triage this bug?
Issue 731788 has been merged into this issue.

Comment 7 by est...@chromium.org, Jun 14 2017

Cc: tengs@chromium.org
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Owner: ----
Status: Unconfirmed (was: Assigned)
Removing security labels.

Comment 8 by vabr@chromium.org, Jun 16 2017

Blocking: 699530
Labels: -Pri-2 Hotlist-Polish Pri-3
Owner: vabr@chromium.org
Status: Assigned (was: Unconfirmed)
[mac triage] Able to reproduce. Assigning to vabr for password bugs

Comment 10 by vabr@chromium.org, Jun 20 2017

Owner: ----
Status: Available (was: Assigned)
... and back in the queue of bugs to fix.
Project Member

Comment 11 by sheriffbot@chromium.org, Jun 20 2018

Labels: Hotlist-Recharge-Cold
Status: Untriaged (was: Available)
This issue has been Available for over a year. If it's no longer important or seems unlikely to be fixed, please consider closing it out. If it is important, please re-triage the issue.

Sorry for the inconvenience if the bug really should have been left as Available.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: Needs-Feedback
Can somebody give an example site? I can't reproduce on a testing page.
Status: Available (was: Untriaged)
I guess it's still happening on some sites.

Sign in to add a comment