New issue
Advanced search Search tips

Issue 777211 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Oct 2017
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Cookies problem, authentication not getting renewed

Reported by subhra1...@gmail.com, Oct 22 2017

Issue description



VULNERABILITY DETAILS

I usually access JSTOR to download articles by scholars from my university WiFi
where we have a subscription. 
However, for some days (that is, about a month) I was able to access with my university's subscription from my home on my home WiFi. According to the webpage,
my access was being provided by my university. So, it was probably a bug with Google Chrome (where only this was happening) which stored the cookies or cache files in such a way that it reproduced the situation of being connected to a different WiFi network without a proper refresh procedure. 

However, I might also be mistaken regarding this. Would be great if Google looks into this.

P.S.  I can no longer access from now on. That is, from around yesterday. 

VERSION
Chrome Version: Version 61.0.3163.100 (Official Build) (64-bit)
Operating System: Windows 10 with Creator's Update

 
Status: WontFix (was: Unconfirmed)
JSTOR offers a wide variety of authentication methods: https://support.jstor.org/hc/en-us/articles/115004983547-Access-Management-A-Practical-Overview

Most of these will work regardless of what network you're connected to. Only one (IP address) of these is specific to the network, and any problem whereby the server is over-broad in acceptance of IP addresses would be a bug in the server, not a but in the client.

Chrome follows applicable RFCs in relation to its management of cookies and cache files.
Project Member

Comment 2 by sheriffbot@chromium.org, Jan 29 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment