Open Bug 1946482 Opened 1 month ago Updated 11 days ago

[contextual-password-manager] Weak password alert displayed for Vulnerable passwords

Categories

(Toolkit :: Password Manager, defect)

Firefox 137
Desktop
All
defect

Tracking

()

Tracking Status
firefox137 --- disabled

People

(Reporter: epopescu, Unassigned)

References

(Blocks 1 open bug)

Details

(Whiteboard: [fxcm-cpm-milestones-3-4])

Found in

  • Nightly 137.0a1

Affected versions

  • Nightly 137.0a1

Tested platforms

  • Affected platforms: Windows 11, macOS 13 ARM, Ubuntu 22.04
  • Unaffected platforms: none

Preconditions:

  • Set pref browser.contextual-password-manager.enabled to true in about:config
  • Enable Sidebar
  • Have several saved password records with active breach and vulnerable alerts

Steps to reproduce

  1. Locate an account with a vulnerable password that is also breached
  2. Click on "View alert" button

Expected result

  • The vulnerable password alert should be displayed for passwords that are both vulnerable and used on a breached account, instead of the weak password alert. Weak password alerts should be exclusively for easily guessable passwords.

Actual result

  • Only the weak password alert is shown, even for passwords that are vulnerable but not weak.

Regression range

  • N/A

Additional notes

Blocks: 1942365
Has STR: --- → yes
OS: Unspecified → All
Hardware: Unspecified → Desktop
Whiteboard: [fxcm-cpm-milestones-3-4]
Version: unspecified → Firefox 137
You need to log in before you can comment on or make changes to this bug.