wrong domain given in error message about third-party cookies

RESOLVED INCOMPLETE

Status

--
major
RESOLVED INCOMPLETE
5 years ago
5 years ago

People

(Reporter: justdave, Unassigned)

Tracking

Firefox Tracking Flags

(Not tracked)

Details

Attachments

(2 attachments)

Created attachment 814667 [details]
Screen Shot 2013-10-08 at 9.06.45 PM.png

When logging into Persona with a mozilla.com address with third-party cookies disabled, you get an error message which states you need to enable third-party cookies for "mozilla.com" in order to use Persona.  This is incorrect, and adding this domain to your third-party cookies exceptions does not work.

The correct domain that needs an exception is "login.mozilla.org"

I'm pretty sure this also only applies to mozilla.com and mozillafoundation.org email addresses.  Hopefully this message is specific to the domain (I'm sure google logins need some google domain to be whitelisted, for example).
Created attachment 814668 [details]
Screen Shot 2013-10-08 at 9.20.18 PM.png

OK, as this screenshot demonstrates, it appears to be putting the user's domain-part of their email address as the domain that needs an exception.  This is not correct in either case.  It should be the domain of the IDP that gets used for this message, not the domain part of the email address.
(In reply to Dave Miller [:justdave] (justdave@bugzilla.org) from comment #0)
> Created attachment 814667 [details]
> Screen Shot 2013-10-08 at 9.06.45 PM.png
> 
> When logging into Persona with a mozilla.com address with third-party
> cookies disabled, you get an error message which states you need to enable
> third-party cookies for "mozilla.com" in order to use Persona.  This is
> incorrect, and adding this domain to your third-party cookies exceptions
> does not work.
> 
> The correct domain that needs an exception is "login.mozilla.org"
> 
> I'm pretty sure this also only applies to mozilla.com and
> mozillafoundation.org email addresses.  Hopefully this message is specific
> to the domain (I'm sure google logins need some google domain to be
> whitelisted, for example).

Filed in GitHub as https://github.com/mozilla/browserid/issues/3966
:justdave, I'm closing this in favor of the github bug. I've referenced @justdave in the github bug (which I assume is your github handle) so that you're added to any conversation there (assuming your github notifications are sorted).

:pdehaan thanks for transferring the bug from here to there, :beers:
Status: NEW → RESOLVED
Last Resolved: 5 years ago
Resolution: --- → INCOMPLETE
Yep, that's me. I had already flagged that big for my watch list anyway :)

thanks
Goooooo team!

Thanks for the report, Dave! Keep em coming [in GitHub]!
You need to log in before you can comment on or make changes to this bug.