If you think a bug might affect users in the 57 release, please set the correct tracking and status flags for Release Management.

mail.password_protect_local_cache doesn't work - shows message headers in thread pane

RESOLVED WORKSFORME

Status

Thunderbird
Security
--
major
RESOLVED WORKSFORME
14 years ago
8 years ago

People

(Reporter: Sergio A. Kessler, Unassigned)

Tracking

unspecified
x86
Windows XP
Bug Flags:
blocking-thunderbird3 -
wanted-thunderbird3 -

Firefox Tracking Flags

(Not tracked)

Details

(Whiteboard: closeme check 2009-02-02)

(Reporter)

Description

14 years ago
User-Agent:       Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Build Identifier: Mozilla Thunderbird 0.5a (20040113)

when putting:
// Password protect the message list pane
user_pref("mail.password_protect_local_cache", true);

in user.js, thunderbird ask for a password before showing the
IMAP folders content, BUT if you press 'Cancel' it shows all
the folder content...  :(


Reproducible: Always

Steps to Reproduce:
1. put
// Password protect the message list pane
user_pref("mail.password_protect_local_cache", true);

in user.js

2. restart thunderbird

3. when asked for a password, click 'Cancel'

Actual Results:  
all the content of imap.inbox appear.

Expected Results:  
all the content of imap.inbox stay blank.

the bug also happened with previos versions of thunderbird...
tested in win98 and winXP

Comment 1

13 years ago
This is also the case if the connection to the server times out before the user
is asked for a password.  Thunderbird throws a connection timed-out error
message and when the user clicks OK to dismiss the dialogue box the subject
lines of the messages in the currently selected folder are shown.

Comment 2

13 years ago
(In reply to comment #1)
> This is also the case if the connection to the server times out before the user
> is asked for a password.  Thunderbird throws a connection timed-out error
> message and when the user clicks OK to dismiss the dialogue box the subject
> lines of the messages in the currently selected folder are shown.

I've managed to reproduce this always with entering the password wrong multiple
times (two times seems to be enough).

Comment 3

13 years ago
confirm in thunderbird version 0.9+ (20041127)

Updated

13 years ago
Status: UNCONFIRMED → NEW
Ever confirmed: true
QA Contact: preferences

Comment 4

9 years ago
still true - trunk.
security bug which shouldn't continue to TB3
Assignee: mscott → nobody
Severity: normal → major
Component: Preferences → Security
Flags: blocking-thunderbird3?
QA Contact: preferences → thunderbird
Summary: mail.password_protect_local_cache doesn't work → mail.password_protect_local_cache doesn't work - shows message headers in thread pane

Updated

9 years ago
Flags: wanted-thunderbird3+
Flags: blocking-thunderbird3?
Flags: blocking-thunderbird3-
Retriaging according to new policy for flags.  

https://wiki.mozilla.org/Thunderbird:Release_Driving

(bugs marked wanted- don't indicate we wouldn't accept patches, but that they're not going to be the focus for release drivers)
Flags: wanted-thunderbird3+ → wanted-thunderbird3-
This works for me on the current Thunderbird nightlies does anyone have a problem with those builds (note you will now need to use a master password for mail.password_protect_local_cache to work).

ftp://ftp.mozilla.org/pub/thunderbird/nightly/latest-comm-1.9.1/
Whiteboard: closeme check 2009-02-02
@Reporter, we have not heard back from you in a while, so I am closing this bug as INCOMPLETE. You can reopen this bug if more information becomes available.
Status: NEW → RESOLVED
Last Resolved: 9 years ago
Resolution: --- → INCOMPLETE

Comment 8

9 years ago
I'm not sure Tyler meant to close this, given the closeme date.  This is WFM after the PWD manager changes.

Sergio, please reopen of you see the problem using a current trunk build or the future Thunderbird 3.
Resolution: INCOMPLETE → WORKSFORME

Comment 9

8 years ago
I seem to be having issues regarding this particular notification. Either 1) I don't seem to understand something fundamental or 2) this bug has returned in version 3.0 

Priors:
I have set the master password. 
I have set mail.password_protect_local_cache to true. 
I have two IMAP accounts.
One has the password stored the other doesn't. 

Upon load of the application the master password is requested. Upon cancel no email related data is shown within the subject/header window. (Good) 

Once the master password is entered in, the account with the password saved can be accessed and used immediately. Data within the subject/header window is available. (Good)

Upon attempting to access the second account (the account without the password saved) the password window is displayed. (Good)

Upon CANCELING the password window all headers that exist on disk are displayed. (BAD)

It's my understanding the purpose of this flag: mail.password_protect_local_cache
was to hide the headers until the password of the account was entered. Therefore the headers should still be hidden. This should be prevalent in each of the account folders and also in the Inbox SmartFolder correct?
You need to log in before you can comment on or make changes to this bug.