firefox preserves logins across sessions when not asked to

Bug #693791 reported by Vincent Povirk
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
firefox (Ubuntu)
Expired
Undecided
Unassigned

Bug Description

Binary package hint: firefox

Steps to reproduce:
1. Navigate to gmail.com.
2. Log out, if logged in.
3. Uncheck the "Stay signed in" button.
4. Log in with the button unchecked.
5. Wait for the gmail inbox to appear.
6. Close firefox.
7. Start firefox again.

Expected results:
You are no longer logged into gmail.

Actual results:
You are still logged into gmail.

There is a preference in about:config named "browser.sessionstore.privacy_level". In this release, it apparently defaults to 0. Setting it to 1 or 2 restores the expected behavior.

ProblemType: Bug
DistroRelease: Ubuntu 11.04
Package: firefox 4.0~b7+nobinonly-0ubuntu3
ProcVersionSignature: Ubuntu 2.6.37-10.24-generic 2.6.37-rc6
Uname: Linux 2.6.37-10-generic x86_64
NonfreeKernelModules: nvidia
Architecture: amd64
Date: Thu Dec 23 08:13:41 2010
InstallationMedia: Ubuntu 9.10 "Karmic Koala" - Release amd64 (20091027)
ProcEnviron:
 LANGUAGE=en_US:en
 PATH=(custom, user)
 LANG=en_US.UTF-8
 LC_MESSAGES=en_US.utf8
 SHELL=/bin/bash
SourcePackage: firefox

Revision history for this message
Vincent Povirk (madewokherd) wrote :
visibility: private → public
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

I couldn't reproduce this issue in an up-to-date Natty VM.

I suspect what is happening to you is your firefox is actually crashing on shutdown, at which point firefox keeps your cookies and restores your session.

Can you reproduce this with firefox 4.0 beta 8?

Changed in firefox (Ubuntu):
status: New → Incomplete
Revision history for this message
Vincent Povirk (madewokherd) wrote :

Yes, this still happens with 4.0b8.

Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for firefox (Ubuntu) because there has been no activity for 60 days.]

Changed in firefox (Ubuntu):
status: Incomplete → Expired
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.