User Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:15.0) Gecko/20100101 Firefox/15.0.1 Build ID: 20120905151427 Steps to reproduce: 1. Sign in on any web-site, asking user to enter username and password. 2. When Firefox asks for permission to remember the password, allow Firefox to do so. 3. Log out from the web-site, you logged in. 4. Even close the tab from where you logged in. 5. Don't close Firefox. 6. Try to sign-in again on the same web-site, with same user name, but with invalid or blank password. Actual results: User gets logged in. Verified the password being sent from the Firefox to the web-site, using Wireshark and base64 decoder: The password is the same one, which was allowed Firefox to remember (cookie). If close Firefox and start a new instance of Firefox and follow the test again, Firefox behaves as expected. Expected results: User should not be logged in with invalid or blank password, anytime.
Tested same on Firefox 16.0 Beta update channel, and observed the same issue.
tried this on yahoo and google, I can't reproduce. Can you list a specific web site where this happens? What addons do you have installed, could any of them be interfering with the log-in process?
Summary: User is able to login with invalid or blank password. → User is able to login with invalid or blank password. (password autocomplete overrides what is entered)
(In reply to Daniel Veditz [:dveditz] from comment #2) > tried this on yahoo and google, I can't reproduce. Can you list a specific > web site where this happens? What addons do you have installed, could any of > them be interfering with the log-in process? My bad, I was not precise. The web-site, I tried with, is an internal web-site, running on Local Net. Interesting observation is same problem is not encountered, if I use IE or Chrome. We will investigate more on this issue and come back with findings.
What we have figured out is, the mentioned issue is already reported as follows. https://bugzilla.mozilla.org/show_bug.cgi?id=654348 You can mark this bug as duplicate of above one.
Status: UNCONFIRMED → RESOLVED
Last Resolved: 6 years ago
Resolution: --- → DUPLICATE
Duplicate of bug: 654348
You need to log in before you can comment on or make changes to this bug.