Closed Bug 1751191 Opened 3 years ago Closed 1 year ago

Some Chinese sites are broken in Firefox 96

Categories

(Core :: Networking: Cookies, defect, P2)

Firefox 96
defect

Tracking

()

RESOLVED WONTFIX
Tracking Status
firefox-esr91 --- unaffected
firefox96 --- disabled
firefox97 --- disabled
firefox98 --- disabled
firefox99 --- disabled
firefox100 --- disabled
firefox101 --- disabled
firefox102 --- disabled
firefox103 --- disabled
firefox104 --- disabled

People

(Reporter: yyzh888888, Unassigned)

References

(Regression)

Details

(Keywords: regression, webcompat:needs-diagnosis, Whiteboard: [necko-triaged])

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:96.0) Gecko/20100101 Firefox/96.0

Steps to reproduce:

用火狐浏览器,淘宝购物后无法收货。这是一个大BUg, 将令火狐失去中国市场。

Actual results:

用火狐浏览器,淘宝购物后无法收货。这是一个大BUg, 将令火狐失去中国市场。

Expected results:

用火狐浏览器,淘宝购物后无法收货。这是一个大BUg, 将令火狐失去中国市场。

我认为您应当提供具体的信息,而不是扔下一句“这是一个大BUg, 将令火狐失去中国市场。”就离开。

Flags: needinfo?(yyzh888888)

The Bugbug bot thinks this bug is invalid.
If you think the bot is wrong, please reopen the bug and move it back to its prior component.

Please note that this is a production bug database used by the Mozilla community to develop Firefox, Thunderbird and other products.
Filing test bugs here will waste the time of our contributors, volunteers and employees.
If you continue to abuse bugzilla.mozilla.org, your account will be disabled.

Status: UNCONFIRMED → RESOLVED
Closed: 3 years ago
Component: zh-CN / Chinese (Simplified) → General
Product: Mozilla Localizations → Invalid Bugs
Resolution: --- → INVALID

The reporter said he was can't to confirm the shopping order on taobao.com website.

This is a new topic in the Chinese forum. Dupe it if repeated.
Based on a post, worldwide.jd.com, qidian.com, pan.baidu.com, etc. are affected.

Status: RESOLVED → UNCONFIRMED
OS: Unspecified → All
Product: Invalid Bugs → Firefox
Regressed by: samesitelax
Hardware: Unspecified → All
Resolution: INVALID → ---
Summary: 用火狐浏览器,淘宝购物后无法收货。这是一个大BUg, 将令火狐失去中国市场。 → Some Chinese sites are broken in Firefox 96
Version: unspecified → Firefox 96
Has Regression Range: --- → yes

Set release status flags based on info from the regressing bug 1617609

comment 0 was:

Using the Firefox browser, Taobao could not receive the goods after shopping. This is a big bug that will make Firefox lose the Chinese market.

comment 1 was telling the original reporter that they needed to leave more specific information

I tried a few of them but didn't get very far -- they seemed to want me to sign in with various apps. But as far as I was able to check none of the sites use explicit SameSite cookie attributes so in Firefox 96 they would get "SameSite=lax". But I'm seeing the same thing in Chrome, which has turned unspecified cookies into SameSite=Lax since August 2020.

Does Chrome work on these sites?

(In reply to Daniel Veditz [:dveditz] from comment #5)

comment 0 was:

Using the Firefox browser, Taobao could not receive the goods after shopping. This is a big bug that will make Firefox lose the Chinese market.

comment 1 was telling the original reporter that they needed to leave more specific information

I tried a few of them but didn't get very far -- they seemed to want me to sign in with various apps. But as far as I was able to check none of the sites use explicit SameSite cookie attributes so in Firefox 96 they would get "SameSite=lax". But I'm seeing the same thing in Chrome, which has turned unspecified cookies into SameSite=Lax since August 2020.

Does Chrome work on these sites?

I can see the lax errors in https://www.qidian.com/. Tested version: FIREFOX_96_0_BUILD2.

STR:

  1. Open the https://www.qidian.com/.
  2. Click the 登录 (Login) in the upper-right corner.
  3. Try to log in to a registered account. I used WeChat, but the international mobile phone should be feasible with the "手机验证码登录" (SMS Login).

Console warnings when logon authentication is successful:
Some cookies are misusing the “SameSite“ attribute, so it won’t work as expected
Cookie “newstatisticSID” has “SameSite” policy set to “Lax” because it is missing a “SameSite” attribute, and “SameSite=Lax” is the default value for this attribute. phoneAreaSortNew.js:472:12
Cookie “newstatisticSID” has been rejected because it is in a cross-site context and its “SameSite” is “Lax” or “Strict”. phoneAreaSortNew.js:472:12
....

Google Chrome 97.0.4692.99 work fine.

If this is samesite lax, let's move to networking to get it out of Fx::General.

Component: General → Networking: Cookies
Product: Firefox → Core

marking as disabled for fx96 since we set sameSite.laxByDefault and sameSite.noneRequiresSecure to false via a pref flip

Disabled for 97 also by way of bug 1751435.

The bug has a release status flag that shows some version of Firefox is affected, thus it will be considered confirmed.

Status: UNCONFIRMED → NEW
Ever confirmed: true

A needinfo is requested from the reporter, however, the reporter is inactive on Bugzilla. Closing the bug as incomplete.

For more information, please visit auto_nag documentation.

Status: NEW → RESOLVED
Closed: 3 years ago3 years ago
Flags: needinfo?(yyzh888888)
Resolution: --- → INCOMPLETE
Status: RESOLVED → REOPENED
Resolution: INCOMPLETE → ---

(In reply to YF (Yang) from comment #6)

STR:

  1. Open the https://www.qidian.com/.
  2. Click the 登录 (Login) in the upper-right corner.
  3. Try to log in to a registered account. I used WeChat, but the international mobile phone should be feasible with the "手机验证码登录" (SMS Login).

I can confirm the site is still broken with sameSiteLax = true with the steps above. If I flip the pref login works.

Severity: -- → S3
Priority: -- → P2
Whiteboard: [necko-triaged]
Status: REOPENED → NEW

We won't be shipping samesitelax by default, so all of this breakage bug can be closed: Bug 1617609

Status: NEW → RESOLVED
Closed: 3 years ago1 year ago
Resolution: --- → WONTFIX
You need to log in before you can comment on or make changes to this bug.