New issue
Advanced search Search tips

Issue 809235 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 803428
Owner:
Closed: Feb 2018
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Bug



Sign in to add a comment

"never save" password rule not respected for iframe login forms

Reported by michael....@gmail.com, Feb 5 2018

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36

Steps to reproduce the problem:
1. Login to e.g. https://sso.brf.dk/login/NemIDLogin  (any danish banking, insurance, government site uses a similar login form)
2. The save password dialogue appears. Select "never save"
3. Repeat steps 1 & 2.... Save password dialogue appears again.

What is the expected behavior?
3. Save password dialogue does not appear

What went wrong?
It looks like the rule is saved for the iframe URL, which is something like https://appletk.danid.dk.  But when the rule is applied on the next visit, it is applied for the page URL, https://sso.brf.dk, instead of for the iframe URL.

Did this work before? N/A 

Chrome version: 63.0.3239.132  Channel: n/a
OS Version: OS X 10.11.6
Flash Version: 

The risk is that the user accidentally clicks "save" at some point.  If the user doesn't know how to delete the saved password, other users of the computer may gain access to this critical login (which is used for banks, taxes, finances etc.).
 


READ THIS FIRST!!!!!!!   Apologies - I made a mistake.  It seems like the issue is different.  Google Smart Lock saves the full URL, and this URL is dynamic, meaning it saves multiple copies for the same site, but with different URLs.  So the issue is that it saves the full path, and not the domain, as it states in the dialogue.  This is confusing.

99.9% of the time, there is only one login page per subdomain.

Comment 2 by palmer@google.com, Feb 5 2018

Components: UI>Browser>Passwords
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
This probably affects at least the other desktop platforms as well.
Labels: Needs-Triage-M63
Mergedinto: 803428
Owner: vasi...@chromium.org
Status: Duplicate (was: Unconfirmed)
vasilii@ has fixed this in Chrome 65 already. \o/

Sign in to add a comment