Closed Bug 2040124 (my.nos.pt) Opened 4 months ago Closed 2 months ago

login.nos.pt and my.nos.pt return HTTP 403 Unauthorized Operation on Firefox 150.0.3 but work correctly on Microsoft Edge 148 and Google Chrome 148

Categories

(Web Compatibility :: Site Reports, defect, P2)

Firefox 150
Desktop
Windows 11

Tracking

(Webcompat Priority:P1, Webcompat Score:8)

RESOLVED INCOMPLETE
Webcompat Priority P1
Webcompat Score 8

People

(Reporter: 40o5ezm3c, Unassigned)

References

()

Details

(Keywords: reporter-external, webcompat:needs-diagnosis, webcompat:site-report)

User Story

user-impact-score:1000
platform:windows,mac,linux,android
impact:site-broken
configuration:general
affects:all
branch:release
diagnosis-team:networking

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36 Edg/148.0.0.0

Steps to reproduce:

  1. Open Firefox 150.0.3 (64-bit)
  2. Navigate to https://my.nos.pt/
  3. The website redirects to https://login.nos.pt/ for authentication
  4. Log in using valid NOS customer credentials
  5. Return to https://my.nos.pt/ after authentication
  6. Attempt to access customer account or customer service functionality
  7. Observe the resulting HTTP 403 error ("Unauthorized Operation")

The issue reproduces consistently on Firefox.

The same workflow works correctly on:

  • Microsoft Edge 148.0.3967.70 (Official build) (64-bit)
  • Google Chrome 148

Actual results:

The NOS authentication/login flow involving https://login.nos.pt/ and https://my.nos.pt/ fails on Firefox with an HTTP 403 error ("Unauthorized Operation").

Authentication appears to begin correctly, but subsequent authenticated requests fail with HTTP 403 during or after the redirect between login.nos.pt and my.nos.pt.

The issue appears Firefox-specific because it does not occur in Chromium-based browsers.

Firefox version:
150.0.3 (64-bit)

Working browsers:

  • Microsoft Edge 148.0.3967.70 (Official build) (64-bit)
  • Google Chrome 148

Troubleshooting attempted:

  • Cleared cookies and cache
  • Tested in Private Browsing mode
  • Disabled extensions
  • Tested with default Firefox settings

User Agent:
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:150.0) Gecko/20100101 Firefox/150.0

Expected results:

The NOS authentication flow should complete successfully and allow normal access to My NOS customer account and customer service functionality, matching the behavior observed in Microsoft Edge and Google Chrome.

Not a security bug: unhiding to make it available to a larger pool of developers who might fix it.

Thank you for being specific about the broken Firefox version 150.0.3. Can you please clarify if this site worked in earlier versions of Firefox and you first noticed that it broke in 150.0.3, or is the first time you've tried this site in Firefox so you don't know?

Group: firefox-core-security

Thank you for the reply.

It was working fine with 150.0.1 and 150.0.2.

The bug was noted on forum.nos.pt a community with 162806 costumers.

Flags: needinfo?(dveditz)
Component: Untriaged → Site Reports
Product: Firefox → Web Compatibility
Alias: my.nos.pt
OS: Unspecified → Windows 11
Hardware: Unspecified → Desktop
User Story: (updated)
Webcompat Priority: --- → P3
Webcompat Score: --- → 1
Severity: -- → S2
User Story: (updated)
Webcompat Priority: P3 → P2
Webcompat Score: 1 → 6
Priority: -- → P2
Flags: needinfo?(dveditz)
User Story: (updated)
Webcompat Priority: P2 → P1
Webcompat Score: 6 → 8

I would have suspected bug 2035801, but that landed in 150.0.2.
@NOS, do you think you could use mozregression to figure out what change caused the issue?
https://mozilla.github.io/mozregression/quickstart.html

Thanks!

User Story: (updated)
Flags: needinfo?(40o5ezm3c)

Thanks for the reply.
I'm not using Linux or Mac do you suggest something else?

Flags: needinfo?(40o5ezm3c) → needinfo?(valentin.gosu)

Mozregression should work on windows too - it even has a GUI - https://mozilla.github.io/mozregression/install.html

Flags: needinfo?(valentin.gosu) → needinfo?(40o5ezm3c)

Redirect a needinfo that is pending on an inactive user to the triage owner.
:skyschub, since the bug has high severity, could you have a look please?

For more information, please visit BugBot documentation.

Flags: needinfo?(40o5ezm3c) → needinfo?(sky)

If we don't get more info, there's very little we can do here, it seems. I'll close this bug for now to get this out of the queue, but if you ever get around to running mozregression, we can always reopen this bug!

Status: UNCONFIRMED → RESOLVED
Closed: 2 months ago
Flags: needinfo?(sky)
Resolution: --- → INCOMPLETE
You need to log in before you can comment on or make changes to this bug.