Specific test from TestRail cannot be interacted with from Firefox when samesite lax by default is enabled (breaks SSO login state in some way)
Categories
(Core :: Networking: Cookies, defect, P2)
Tracking
()
People
(Reporter: vsangerean, Unassigned)
References
(Regression)
Details
(Keywords: regression, Whiteboard: [necko-triaged])
Attachments
(1 file)
5.21 MB,
image/gif
|
Details |
Found in
105.0b2
Affected versions
105.0b1
105.0b2
106.0a1
Not reproducible in 104.0
Tested platforms
Affects all Desktop versions of FF
Steps to reproduce
- Go to https://testrail.stage.mozaws.net/index.php?/tests/view/4457269&group_by=cases:section_id&group_id=191843&group_order=asc
- Click on "+ Add Result"
Expected result
The "Add result" window should be open, and test result can be properly set.
Actual result
You are not logged in prompt is displayed.
Errors are present in the browser console :
"Cookie “tr_rememberme” has been rejected because it is already expired. index.php
Cookie “notificationbar” has been rejected because it is already expired."
Regression range
-
First bad: 9a55ce1e0df8375be5c3f24a25c051067bf1bfa5
-
Last good: 9505197158716faadc101286218960166e038c6f
-
Potentially regressed by:
Reporter | ||
Updated•2 years ago
|
Comment 1•2 years ago
|
||
:vsangerean, if you think that's a regression, could you try to find a regression range using for example mozregression?
Reporter | ||
Updated•2 years ago
|
Comment 2•2 years ago
|
||
This regression window doesn't make sense - bug 1744945 got fixed in Firefox 97 but comment 0 says release (Fx104) is fine.
Does testrail actually use samesite cookies? Can you re-check the regression range and/or whether this repros on 104?
Comment 3•2 years ago
|
||
(In reply to Virgil Sangerean from comment #0)
Steps to reproduce
I just tried to reproduce but I do not see this item. Where is it and is it visible to all users?
Comment 4•2 years ago
|
||
I still can't see the "Add result" button but I also get prompted to log in if I click "history & context" and "defects" tabs, near the top.
If I turn off network.cookie.sameSite.laxByDefault
then the site works correctly. This explains the regression window and why it's working on release - we haven't enabled that pref on release (or on late beta, so later betas shouldn't have this problem either)
Reporter | ||
Updated•2 years ago
|
Comment 5•2 years ago
|
||
Set release status flags based on info from the regressing bug 1744945
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Comment 6•2 years ago
|
||
Set release status flags based on info from the regressing bug 1744945
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Updated•1 year ago
|
Comment 7•2 months ago
|
||
We won't be shipping samesitelax by default, so all of this breakage bug can be closed: Bug 1617609
Description
•