Last modified: 2013-10-18 17:43:30 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T56626, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 54626 - forceHTTPS session cookie placed even with HTTPS opt-out set
forceHTTPS session cookie placed even with HTTPS opt-out set
Status: RESOLVED FIXED
Product: MediaWiki extensions
Classification: Unclassified
CentralAuth (Other open bugs)
master
All All
: High normal (vote)
: ---
Assigned To: Nobody - You can work on this!
:
: 55368 (view as bug list)
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2013-09-26 08:53 UTC by Derk-Jan Hartman
Modified: 2013-10-18 17:43 UTC (History)
9 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Derk-Jan Hartman 2013-09-26 08:53:02 UTC
Forced secure connection...again...[edit]

Even though the "always use a secure connection" box is unchecked, I'm being redirected to https:// no matter what I do on each and every page. This is becoming bothersome. - The Bushranger One ping only 22:43, 25 September 2013 (UTC)


Which browser are you using? If Firefox, try zapping all the forceHTTPS cookies, as suggested a few weeks back. --Redrose64 (talk) 23:09, 25 September 2013 (UTC)


I'm using FF22. I tried that - but there was no forceHTTPS cookie after I logged out per the directions there. There was one that existed while I was logged in, and I deleted it while logged in - and was then able to navigate using http://...however, as soon as I signed out and back in again, I was right back stuck on https://. This is a Wikipedia issue, not a my-browser isssue, as it's force-feeding me the forceHTTPS cookie every time I log in, even though it was just fine on http:// this morning. - The Bushranger One ping only 23:25, 25 September 2013 (UTC)


I tried deleting and had similar problems - it's also force feeding me that cookie every time I log in. Why do the technical people have meddle so... and not tell us. Dpmuk (talk) 06:07, 26 September 2013 (UTC)
Comment 2 Gerrit Notification Bot 2013-09-26 14:31:02 UTC
Change 86101 had a related patch set uploaded by Anomie:
Explicitly clear forceHTTPS cookie when insecure

https://gerrit.wikimedia.org/r/86101
Comment 3 Gerrit Notification Bot 2013-09-26 22:19:57 UTC
Change 86101 merged by jenkins-bot:
Explicitly clear forceHTTPS cookie when insecure

https://gerrit.wikimedia.org/r/86101
Comment 4 Brad Jorsch 2013-09-27 16:15:08 UTC
Marking this fixed, since the patch is merged. It looks like this just missed being included in 1.22wmf19, so it should go out to WMF wikis with 1.22wmf20. See https://www.mediawiki.org/wiki/MediaWiki_1.22/Roadmap for the schedule.

Unless, of course, Chris or someone wants to backport it (which would probably happen then on Monday).
Comment 5 Betacommand 2013-10-06 15:18:22 UTC
*** Bug 55368 has been marked as a duplicate of this bug. ***
Comment 6 Erik Moeller 2013-10-10 07:58:46 UTC
Is this in fact in wmf20? I don't see it in the release notes in https://www.mediawiki.org/wiki/MediaWiki_1.22/wmf20
Comment 7 Brad Jorsch 2013-10-10 16:23:32 UTC
I don't know why it's not on that release notes page, but I just checked on tin and it is included in the version of CentralAuth in /a/common/php-1.22wmf20/extensions/CentralAuth.
Comment 8 Erik Moeller 2013-10-10 17:32:08 UTC
Thanks for checking, Brad.
Comment 9 Carolina wren 2013-10-13 22:12:35 UTC
I'm getting forced into using HTTPS again today, so I'm reopening this bug.  Not only that, but clearing the cookies doesn't help.  If do that, then I get the popup message:
Central login
You are centrally logged in as XXXXXXX. Reload the page to apply your user settings.

And 15 different new HTTPS cookies added:
commons, incubator, login, mediawiki, meta, species, wikibooks, wikidata, wikinews, wikipedia, wikiquote, wikisource, wikiversity, wikivoyage, and wiktionary.

I am using Firefox 24.0.
Comment 10 Carolina wren 2013-10-13 22:36:33 UTC
Just realized something.  One of the cookies was "wikipedia.org".   If I remember correctly, then before there were separate cookies for en.wikipedia.org, fr.wikipedia.org, etc.  Did someone do an optimization to use only one cookie per domain and then forget to give us the ability to opt out  since there are no preferences users can set on "wikipedia.org", just on the individual sites?
Comment 11 Carolina wren 2013-10-13 22:58:19 UTC
Okay, just tried one more thing.  Clearing the cookies, logging out, and logging back in.  That worked.  But still, I should not have ever gotten into the state I was in of it forcing me into HTTPS, so something is still wonky, even if intermittently so.
Comment 12 Brad Jorsch 2013-10-15 16:15:35 UTC
If you can reproduce this now that you've logged out and logged back in, please file a new bug with specific instructions on reproducing.
Comment 13 Erik Moeller 2013-10-16 17:15:03 UTC
Confirmed fixed in a Chrome private browser session with HTTPS disabled.
Comment 14 Carolina wren 2013-10-18 17:43:30 UTC
I have managed to reproduce it and this time noticed the trigger.  Using Google Translate on a Wikipedia page.  I have filed a new bug, Bug 55887.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links