Closed Bug 1240288 Opened 8 years ago Closed 8 years ago

Possible privacy issue with "Show my windows and tabs from last time"

Categories

(Firefox :: Session Restore, defect)

43 Branch
defect
Not set
normal

Tracking

()

RESOLVED DUPLICATE of bug 530594

People

(Reporter: tamas.dev.tarjanyi, Unassigned)

Details

(Keywords: privacy)

Attachments

(1 file)

Attached image ff2.png
User Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.111 Safari/537.36

Steps to reproduce:

If you choose about:preferences#general "When Firefox start:" "Show my windows and tabs from last time" restored tab logs you in into gmail even if you have selected there NOT to "Stay signed in" 
I have tried different options to force to loose session data without any luck:
about:preferences#privacy "Keep until:" "I close Firefox" is also selected.


Actual results:

* Logged in to gmail via accounts.google.com and removing check box of "Stay signed in" so forcing not to stay signed in.
* After signing in closed firefox.
* Restarted firefox and I was in gmail without auth



Expected results:

After browser restart gmail should ask auth again even if I have tabs from last time reloaded.
Not sure this is an issue or a feature request but I believe this is a firefox issue because:
* If I close the gmail tab before closing firefox google requires auth after firefox restart
* If I do not choose "Show my windows and tabs from last time" after restarting firefox google requires auth

So logging back without auth happens only if you select "Show my windows and tabs from last time" and keep the gmail tab open while restarting firefox or using "Always use private browsing mode" but than tabs are lost and "Show my windows and tabs from last time" can not be selected.

This might be an improvement idea and not a bug to have a "Securely show my windows and tabs from last time" where all session data/cookies are lost.
OS: Unspecified → Linux
Hardware: Unspecified → x86_64
Status: UNCONFIRMED → RESOLVED
Closed: 8 years ago
Component: Untriaged → Session Restore
Keywords: privacy
OS: Linux → All
Hardware: x86_64 → All
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: