Last modified: 2013-12-02 17:23:11 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T57760, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 55760 - wikipedia.beta.wmflabs.org sending forceHTTPS cookie
wikipedia.beta.wmflabs.org sending forceHTTPS cookie
Status: RESOLVED FIXED
Product: Wikimedia Labs
Classification: Unclassified
deployment-prep (beta) (Other open bugs)
unspecified
All All
: Unprioritized normal
: ---
Assigned To: Nobody - You can work on this!
:
Depends on: 55804
Blocks:
  Show dependency treegraph
 
Reported: 2013-10-15 21:20 UTC by Chris McMahon
Modified: 2013-12-02 17:23 UTC (History)
8 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments
cookies in Chrome (32.62 KB, image/png)
2013-10-15 21:20 UTC, Chris McMahon
Details

Description Chris McMahon 2013-10-15 21:20:04 UTC
Created attachment 13498 [details]
cookies in Chrome

don't send forceHTTPS cookie for any beta.wmflabs.org host
Comment 1 Chris Steipp 2013-10-16 17:53:48 UTC
I'm not able to reproduce this in development, but I do see it in beta.

It seems like SUL2 isn't configured correctly in beta, so I'll probably try and fix that first.

I'm also a little suspicious that SpecialCentralAutoLogin::getCentralSession() looks directly at the user preference for cookie security instead of calling User::requiresHTTPS(), which would check if wgSecureLogin is disabled.
Comment 2 Gerrit Notification Bot 2013-10-18 22:56:48 UTC
Change 90670 had a related patch set uploaded by CSteipp:
Update beta to use loginwiki for SUL

https://gerrit.wikimedia.org/r/90670
Comment 3 Gerrit Notification Bot 2013-10-22 21:58:32 UTC
Change 90670 merged by jenkins-bot:
Update beta to use loginwiki for SUL

https://gerrit.wikimedia.org/r/90670
Comment 4 Antoine "hashar" Musso (WMF) 2013-12-02 14:45:38 UTC
Chris, is that still an issue?
Comment 5 Chris Steipp 2013-12-02 17:23:11 UTC
It shouldn't be. Anyone can reopen if they see this pop up again.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links