Closed Bug 367688 Opened 18 years ago Closed 18 years ago

Closing Tabs Doesn't Delete Session Cookies

Categories

(Firefox :: Bookmarks & History, defect)

x86
Linux
defect
Not set
major

Tracking

()

RESOLVED DUPLICATE of bug 117222

People

(Reporter: mlissner+bugzilla, Unassigned)

Details

User-Agent:       Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.1) Gecko/20060601 Firefox/2.0.0.1 (Ubuntu-edgy)
Build Identifier: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.1) Gecko/20060601 Firefox/2.0.0.1 (Ubuntu-edgy)

On websites that use cookies which expire when the browser is closed, closing the tabs does not delete them. This means that if a friend uses the a new tab in the same browser to visit a secure site, and then closes the tab as a way to log out, they will remain logged in, and the recently closed tabs feature will allow reentry.

Reproducible: Always

Steps to Reproduce:
 - Log into a site that uses cookies that expire upon browser closure
 - Close the tab
 - Reopen the tab using the recently used tabs feature or by navigating back to the page.
 - The login credentials are still good.
Actual Results:  
The cookie is not deleted, and one does not need to log back into the site.

Expected Results:  
It should delete session cookies when the tabs are closed as well as when the browser is closed.
> when the browser is closed

Do you mean when a browser window is closed, or when we exit the browser?
This sounds like expected behavior, to me. We don't equate "the tab is closed" with the "session ends". The "session" only ends when the browser process is terminated.
Group: security
Status: UNCONFIRMED → RESOLVED
Closed: 18 years ago
Resolution: --- → DUPLICATE
(In reply to comment #2)
> The "session" only ends when the browser process is terminated.

With Session Restore, even that's no longer generally true: see e.g. bug 345345.
Component: History → Bookmarks & History
QA Contact: history → bookmarks
You need to log in before you can comment on or make changes to this bug.