Closed Bug 1653517 Opened 4 years ago Closed 3 years ago

Restrict about:logins OS-reauthentication feature to Thunderbird Daily

Categories

(Thunderbird :: Security, task, P1)

Tracking

(thunderbird_esr78+ fixed, thunderbird79 affected)

RESOLVED FIXED
84 Branch
Tracking Status
thunderbird_esr78 + fixed
thunderbird79 --- affected

People

(Reporter: wsmwk, Assigned: mkmelin)

References

Details

Attachments

(1 file)

+++ This bug was initially created as a clone of Bug #1641473 +++

(For Firefox the feature was disabled for 77 in bug 1636511.)

We shouldn't be shipping the OS login yet, as Firefox hasn't completed their work.
Thunderbird re-enable is bug 1653516

I think we only use it for when to change primary password (former master password). I don't see anything when opening the passwords dialog normally.

So just change https://searchfox.org/comm-central/source/mail/components/preferences/privacy.js#374 to "AppConstants.NIGHTLY_BUILD ||"?

It's also when you press "Show Passwords" in the password manager.

Assignee: nobody → mkmelin+mozilla
Status: NEW → ASSIGNED
Attachment #9187596 - Flags: review?(richard.marti)

Comment on attachment 9187596 [details] [diff] [review]
bug1653517_os_reauth_disable.patch

Thanks.

Attachment #9187596 - Flags: review?(richard.marti) → review+
Target Milestone: --- → 84 Branch

Pushed by mkmelin@iki.fi:
https://hg.mozilla.org/comm-central/rev/c128cb4ce9be
disable OS reauth for Tunderbird non-nightly builds. r=Paenglab

Status: ASSIGNED → RESOLVED
Closed: 3 years ago
Resolution: --- → FIXED

Comment on attachment 9187596 [details] [diff] [review]
bug1653517_os_reauth_disable.patch

[Approval Request Comment]
Regression caused by (bug #): not a regression
User impact if declined: possible confusion, unpolished UI requesting OS auth when viewing passwords
Testing completed (on c-c, etc.): been on beta
Risk to taking this patch (and alternatives if risky): no risk

Attachment #9187596 - Flags: approval-comm-esr78?

Comment on attachment 9187596 [details] [diff] [review]
bug1653517_os_reauth_disable.patch

[Triage Comment]
Approved for esr78

Attachment #9187596 - Flags: approval-comm-esr78? → approval-comm-esr78+
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: