Bug 1667379 - "Remember me" checkbox is gone from Red Hat Bugzilla 5
Summary: "Remember me" checkbox is gone from Red Hat Bugzilla 5
Keywords:
Status: CLOSED DUPLICATE of bug 1410316
Alias: None
Product: Bugzilla
Classification: Community
Component: User Interface
Version: 5.0
Hardware: All
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: PnT DevOps Devs
QA Contact: tools-bugs
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2019-01-18 10:05 UTC by Dmitry Zhukovski
Modified: 2019-01-22 22:43 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-01-22 22:43:41 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Bugzilla 1659832 0 unspecified CLOSED Add a cookie to remember authentication choice 2021-02-22 00:41:40 UTC

Description Dmitry Zhukovski 2019-01-18 10:05:15 UTC
Description of problem:
"Remember me" checkbox is gone from Red Hat Bugzilla 5

Version-Release number of selected component (if applicable):
5.0

How reproducible:
everytime

Steps to Reproduce:
1. come to main page next day 
2.
3.

Actual results:
you need to enter you credentials agian since portal does not remmbers old session

Expected results:
something like "Remember Me" checkbox that was in old BZ that saves session coockies and restores the session to be implemented

Additional info:

Comment 1 Jeff Fearn 🐞 2019-01-22 00:03:35 UTC
This site now uses similar security policies to other public facing Red Hat infrastructure, such as the portal. Long lived sessions are insecure and modern security practice discourages them.

The linked bug has something we will implement, a long lived cookie to remember which SSO provider a users wishes to use. When a user lands in BZ if this cookie is detected it will trigger the SSO login chosen, if the user is already logged in on another site using that SSO provider, that would automatically log them in to Bugzilla.

Comment 2 Dmitry Zhukovski 2019-01-22 07:49:18 UTC
But how about customers/external users that do not have any SSO provider?

I have just tetsted in another browser. 1) login 2) close browser 3) open again in a few seconds - seesion is not saved. 

Here ^ we dont speak about long-living session - just couple of seconds and session is gone - very upractical.

Can you comment of that ?

Comment 3 Jeff Fearn 🐞 2019-01-22 21:46:11 UTC
(In reply to Dmitry Zhukovski from comment #2)
> But how about customers/external users that do not have any SSO provider?
> 
> I have just tetsted in another browser. 1) login 2) close browser 3) open
> again in a few seconds - seesion is not saved. 
> 
> Here ^ we dont speak about long-living session - just couple of seconds and
> session is gone - very upractical.
> 
> Can you comment of that ?

This is how session cookies works.

Comment 4 Jeff Fearn 🐞 2019-01-22 22:43:41 UTC

*** This bug has been marked as a duplicate of bug 1410316 ***


Note You need to log in before you can comment on or make changes to this bug.