Disable password visibility toggling in the capture doorhanger outside Nightly

VERIFIED FIXED in Firefox 43, Firefox OS v2.5

Status

()

Toolkit
Password Manager
VERIFIED FIXED
2 years ago
2 years ago

People

(Reporter: MattN, Assigned: MattN)

Tracking

unspecified
mozilla45
Points:
---

Firefox Tracking Flags

(firefox42 unaffected, firefox43 verified, firefox44 verified, firefox45 verified, b2g-v2.5 fixed)

Details

MozReview Requests

()

Submitter Diff Changes Open Issues Last Updated
Loading...
Error loading review requests:

Attachments

(1 attachment)

+++ This bug was initially created as a clone of Bug #1203294 +++

There are still more follow-ups on this UI so disable this UI with the pref behind an ifdef for Nightly through Beta.
Created attachment 8695621 [details]
MozReview Request: Bug 1230391 - Disable password visibility toggling in the capture doorhanger outside Nightly. rs=bnicholson

Bug 1230391 - Disable password visibility toggling in the capture doorhanger outside Nightly. rs=bnicholson
Comment on attachment 8695621 [details]
MozReview Request: Bug 1230391 - Disable password visibility toggling in the capture doorhanger outside Nightly. rs=bnicholson

Approval Request Comment
[Feature/regressing bug #]: Bug 1169702
[User impact if declined]: Users will experience an unpolished password capture visibility toggle. They may be surprised that their password is revealed.
[Describe test coverage new/current, TreeHerder]: Reverting to existing behaviour for non-Nightly which has been tested for years.
[Risks and why]: Low risk reverting to previous behaviour.
[String/UUID change made/needed]: None
Attachment #8695621 - Flags: review+
Attachment #8695621 - Flags: approval-mozilla-beta?
Attachment #8695621 - Flags: approval-mozilla-aurora?
Assignee: nobody → MattN+bmo
Status: NEW → ASSIGNED

Comment 4

2 years ago
bugherder
https://hg.mozilla.org/mozilla-central/rev/aea828e2cdf7
Status: ASSIGNED → RESOLVED
Last Resolved: 2 years ago
status-firefox45: affected → fixed
Resolution: --- → FIXED
Target Milestone: --- → mozilla45
Comment on attachment 8695621 [details]
MozReview Request: Bug 1230391 - Disable password visibility toggling in the capture doorhanger outside Nightly. rs=bnicholson

Too late for 43 as this missed the beta 9 build.
Attachment #8695621 - Flags: approval-mozilla-beta? → approval-mozilla-beta-
Sorry, wontfixing for 43 but we should take this for 44.
status-firefox43: affected → wontfix
(In reply to Liz Henry (:lizzard) (needinfo? me) from comment #6)
> Sorry, wontfixing for 43 but we should take this for 44.

If we don't take this for 43 then the damage may already be done so I don't think we would disable on 44 and instead would wait for the follow-ups. Note that we disabled this on betas for the last two versions without any trouble in bug 1203294 and I really don't think we should ship the feature in the current state due to bug 1217134, bug 1174900 and the related bug to not allow toggling after the initial close of the doorhanger. All three of these bugs are about the ability to reveal a user's passwords in plain text when they don't expect it.

Can you reconsider?
Flags: needinfo?(lhenry)
Yes, ok.  Sorry I missed your needinfo. We will be doing a dot release for 43.  I can take it for that, or in case we do an rc2.  I'll approve this for uplift to beta and release now.
Flags: needinfo?(lhenry)
Comment on attachment 8695621 [details]
MozReview Request: Bug 1230391 - Disable password visibility toggling in the capture doorhanger outside Nightly. rs=bnicholson

After discussion with MattN it sounds like we need to take this for aurora, beta, and m-r; low risk and better for user privacy
Attachment #8695621 - Flags: approval-mozilla-release+
Attachment #8695621 - Flags: approval-mozilla-beta-
Attachment #8695621 - Flags: approval-mozilla-beta+
Attachment #8695621 - Flags: approval-mozilla-aurora?
Attachment #8695621 - Flags: approval-mozilla-aurora+
status-firefox43: wontfix → fixed
Can you verify this is fixed on 43.0 or 43.0.1? Thanks.
Flags: qe-verify+
Flags: needinfo?(andrei.vaida)
Matt, are you seeing that this is fixed on release?
Flags: needinfo?(MattN+bmo)
Yes, fixed on release.
Flags: needinfo?(MattN+bmo)
(In reply to Liz Henry (:lizzard) (needinfo? me) from comment #12)
> Can you verify this is fixed on 43.0 or 43.0.1? Thanks.

We'll take care of this first thing tomorrow.
Flags: needinfo?(andrei.vaida) → needinfo?(cornel.ionce)
Verified that the password visibility toggling in the capture doorhanger is not available anymore on Firefox 43.0.2, Firefox 44 beta 2 and latest Developer Edition 45.0a2 across platforms (Windows 7 64-bit, Mac OS X 10.11.1 and Ubuntu 14.04 32-bit).
Status: RESOLVED → VERIFIED
status-firefox43: fixed → verified
status-firefox44: fixed → verified
status-firefox45: fixed → verified
Flags: qe-verify+
Flags: needinfo?(cornel.ionce)
You need to log in before you can comment on or make changes to this bug.