Closed Bug 1345924 Opened 8 years ago Closed 7 years ago

Username on insecure forms doesn't suggest previously used values (no saved logins)

Categories

(Firefox :: Security, defect)

defect
Not set
normal

Tracking

()

RESOLVED WONTFIX

People

(Reporter: flod, Unassigned)

References

(Blocks 1 open bug)

Details

Attachments

(1 file)

Attached file log.txt (deleted) —
I login into an insecure login form, I see the warning and decide to ignore it. I then see a request to save the login information in Firefox, but I don't want to save both username and password. If I then try to login into the same form, double clicking into the field doesn't show the previously used username, while that happens on secure login forms. It seems like a bug, since I can easily save the full login on a such form, there seems to be no reason to show existing usernames. Attached is the log with signon.debug set to true, following mconley's suggestion.
Behavior also doesn't change if I set signon.autofillForms.http to false. Tried on 55.0a1 (2017-03-09) (64 bit) with a clean profile.
Flags: needinfo?(MattN+bmo)
Also worth mentioning is that flod can reproduce this with signon.autofillForms.http set to true or false.
This was originally reported as an issue on our local support forum (with 52). I haven't tested it personally, but I assume it's in all versions.
Summary: Login on insecure forms doesn't suggest previously used usernames (no saved logins) → Username on insecure forms doesn't suggest previously used values (no saved logins)
This was an unfortunate side-effect of how we had to implement the insecure warning and we were aware of this downside.
Status: NEW → RESOLVED
Closed: 7 years ago
Flags: needinfo?(MattN+bmo)
Resolution: --- → WONTFIX
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: