Closed
Bug 1491023
Opened 7 years ago
Closed 7 years ago
Automatically close other sessions when user opens a new one with the IP restriction feature enabled
Categories
(bugzilla.mozilla.org :: General, enhancement)
Tracking
()
RESOLVED
WONTFIX
People
(Reporter: testbr09, Unassigned)
References
Details
(Keywords: reporter-external)
User Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.92 Safari/537.36
Steps to reproduce:
1 access https://bugzilla.mozilla.org
2 on other IP access the same account on https://bugzilla.mozilla.org> check the option "Restrict this session to this IP address (using this option improves security)"
3 return to step 1 device
Session is still active
Actual results:
Even if you select the option 'restrict this session to this IP' the other active sessions are not closed
Expected results:
It seems to me that the option to restrict access to an IP does not work correctly. If the session is restricted to that IP I believe that the other sessions should be closed
Comment 2•7 years ago
|
||
Restrict IP associates a single session with an IP, it has no impact on other sessions as implemented. Management of active sessions can happen on https://bugzilla.mozilla.org/userprefs.cgi?tab=sessions
Flags: needinfo?(jclaudius)
Updated•7 years ago
|
Flags: needinfo?(jclaudius) → sec-bounty?
Comment 3•7 years ago
|
||
Additionally we could consider this a feature request, but it doesn't seem that urgent to me. Also "Restrict by IP"
is often a very negative experience for users of mobile devices.
Updated•7 years ago
|
Group: bugzilla-security → mozilla-employee-confidential
Flags: sec-bounty?
Flags: sec-bounty-hof-
Flags: sec-bounty-
Comment 4•7 years ago
|
||
Personally I would hate this: My home computer is logged in with the IP restriction enabled but my laptop and phone are logged into different roaming sessions. The PITA of logging in on my phone all the time would mean I could not enable the protection on my home windows computer which is probably the most at risk of compromise (since I do non-work things on it).
Summary: IP restriction issue → Automatically close other sessions when user opens a new one with the IP restriction feature enabled
Updated•7 years ago
|
Group: mozilla-employee-confidential
Severity: normal → enhancement
Updated•7 years ago
|
Status: UNCONFIRMED → RESOLVED
Closed: 7 years ago
Resolution: --- → WONTFIX
Comment 5•7 years ago
|
||
(In reply to Dylan Hardison [:dylan] (he/him) from comment #3)
> Additionally we could consider this a feature request, but it doesn't seem
> that urgent to me. Also "Restrict by IP"
> is often a very negative experience for users of mobile devices.
“Restrict by IP” is probably a legacy of the desktop computer era. Now people are using multiple devices including a laptop, tablet and mobile phone, moving around regularly. I’d suggest removing the option to improve UX.
See Also: → 1402894
Updated•1 year ago
|
Keywords: reporter-external
You need to log in
before you can comment on or make changes to this bug.
Description
•