Closed Bug 481750 Opened 15 years ago Closed 15 years ago

Password manager mixes different passwords with same username in same domain but different application

Categories

(Toolkit :: Password Manager, defect)

x86
Windows XP
defect
Not set
major

Tracking

()

RESOLVED DUPLICATE of bug 263387

People

(Reporter: faramir0cl, Unassigned)

Details

User-Agent:       Mozilla/5.0 (Windows; U; Windows NT 5.1; es-AR; rv:1.9.0.7) Gecko/2009021910 Firefox/3.0.7 (.NET CLR 3.5.30729)
Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 5.1; es-AR; rv:1.9.0.7) Gecko/2009021910 Firefox/3.0.7 (.NET CLR 3.5.30729)

Firefox 3 password manager is not distinguishing correctly between 2 different applications installed in the same domain but in different folders.

If I login to
www.somedomain.com/forum1/ with username1 and password1 and then to
www.somedomain.com/forum2/ with username1 and password2, Firefox overwrites password1, if I chose to make it remember password2.

Firefox2 didn't have that problem.

If I access to www.somedomain/webapp3/ which is a software very different from forum1 and forum2, with username1 and password3, it also overwrites password1 or password2.

Reproducible: Always

Steps to Reproduce:
1.Login to mydomain/forum1 and make firefox to remember user1 password1
2.Login to mydomain/forum2 and make firefox to remember user1 password2
3.
Actual Results:  
Next time I try to login to forum1, firefox enters user1 and password2

Expected Results:  
Bind user1 and password1 combination to forum1, and bind user1 and password2 combination to forum2, as FireFox2 did without any problem.

FireFox 1.5 and FireFox 2.0.0.x didn't had this problem, I just noticed it since FireFox 3. I have just tried with FireFox for Windows.
Component: General → Password Manager
Product: Firefox → Toolkit
QA Contact: general → password.manager
I have seen this behaviour for some time now, and I'm not sure that it really didn't happen with FF2. At least it happens now with FF 3.0.7 and is rather annoying. I get this when I log into a bunch of web applications as "admin". As described in the entry above: same domain, different address/folder, same username, different password. It would be great if someone who knows the internals of the password manager could look into this. :-)
Status: UNCONFIRMED → RESOLVED
Closed: 15 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.