Closed Bug 1238018 Opened 9 years ago Closed 7 years ago

Firefox allows sites to store data for offline use without prompting

Categories

(Firefox :: Settings UI, defect)

54 Branch
Unspecified
All
defect
Not set
normal

Tracking

()

RESOLVED INVALID

People

(Reporter: bugzilla, Unassigned)

References

Details

(Keywords: privacy)

User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:43.0) Gecko/20100101 Firefox/43.0
Build ID: 20160105164030

Steps to reproduce:

1. Check about:preferences#advanced that "Tell me when websites request to store data for offline use" is checked. Click "Exceptions" - verify empty. Press "Clear" to erase sites currently storing data.
2. Visit https://citiretailservices.citibankonline.com/RSnextgen/svc/launch/index.action?siteId=PLCN_BESTBUY#signon and log in.
3. Reload about:preferences#advanced, note that this site is now storing data for offline use.


Actual results:

Site is storing data, no prompt or notification of any kind.


Expected results:

A prompt or notification asking if the site should be allowed to store data.
This appears to reference bug#543860 which implies the text label is incorrect.
And re-tested, logging in is not required. Merely visiting the URL will trigger data storage.
Status: UNCONFIRMED → NEW
Component: Untriaged → Preferences
Ever confirmed: true
Keywords: privacy
See Also: → 543860
This is still a bug in Build identifier: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:51.0) Gecko/20100101 Firefox/51.0.
This is also a bug on Windows:

Build identifier: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:54.0) Gecko/20100101 Firefox/54.0

Every time I visit Microsoft's office365 suite I get 2 MB of data stored without prompting. Whitelist is empty.
OS: Unspecified → All
Version: 43 Branch → 54 Branch
Looks like it's not toggling:

offline-apps.allow_by_default = true

Setting this False I am now getting the correct prompts. Now it is missing a "never prompt."
I don't think this still exists.
Status: NEW → RESOLVED
Closed: 7 years ago
Resolution: --- → INVALID
You need to log in before you can comment on or make changes to this bug.