Closed Bug 1491023 Opened 7 years ago Closed 7 years ago

Automatically close other sessions when user opens a new one with the IP restriction feature enabled

Categories

(bugzilla.mozilla.org :: General, enhancement)

Production
enhancement
Not set
normal

Tracking

()

RESOLVED WONTFIX

People

(Reporter: testbr09, Unassigned)

References

Details

(Keywords: reporter-external)

User Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.92 Safari/537.36 Steps to reproduce: 1 access https://bugzilla.mozilla.org 2 on other IP access the same account on https://bugzilla.mozilla.org> check the option "Restrict this session to this IP address (using this option improves security)" 3 return to step 1 device Session is still active Actual results: Even if you select the option 'restrict this session to this IP' the other active sessions are not closed Expected results: It seems to me that the option to restrict access to an IP does not work correctly. If the session is restricted to that IP I believe that the other sessions should be closed
Hi team, Any update on this?
Restrict IP associates a single session with an IP, it has no impact on other sessions as implemented. Management of active sessions can happen on https://bugzilla.mozilla.org/userprefs.cgi?tab=sessions
Flags: needinfo?(jclaudius)
Flags: needinfo?(jclaudius) → sec-bounty?
Additionally we could consider this a feature request, but it doesn't seem that urgent to me. Also "Restrict by IP" is often a very negative experience for users of mobile devices.
Group: bugzilla-security → mozilla-employee-confidential
Flags: sec-bounty?
Flags: sec-bounty-hof-
Flags: sec-bounty-
Personally I would hate this: My home computer is logged in with the IP restriction enabled but my laptop and phone are logged into different roaming sessions. The PITA of logging in on my phone all the time would mean I could not enable the protection on my home windows computer which is probably the most at risk of compromise (since I do non-work things on it).
Summary: IP restriction issue → Automatically close other sessions when user opens a new one with the IP restriction feature enabled
Group: mozilla-employee-confidential
Severity: normal → enhancement
Status: UNCONFIRMED → RESOLVED
Closed: 7 years ago
Resolution: --- → WONTFIX
(In reply to Dylan Hardison [:dylan] (he/him) from comment #3) > Additionally we could consider this a feature request, but it doesn't seem > that urgent to me. Also "Restrict by IP" > is often a very negative experience for users of mobile devices. “Restrict by IP” is probably a legacy of the desktop computer era. Now people are using multiple devices including a laptop, tablet and mobile phone, moving around regularly. I’d suggest removing the option to improve UX.
See Also: → 1402894
You need to log in before you can comment on or make changes to this bug.