CLOSED INVALID 11210
WebKit won't offer to save password in keychain if there is no accompanying username field
https://bugs.webkit.org/show_bug.cgi?id=11210
Summary WebKit won't offer to save password in keychain if there is no accompanying u...
John Dagen
Reported 2006-10-07 14:36:53 PDT
When typing in a password field, WebKit doesn't seem to be able to save a keychain value for said password if there isn't also a username field in the form on a web page. You might wonder why anyone would want to save a password without a username, so I'll give an example. Bank of America's online banking system doesn't have the username and password on the same page, instead, what they do is have you enter your username on their home page, and then submit it. The user is then taken to a second page, wherein the user is presented with a customized keyphrase and particular image that the user has chosen. The idea is that if the user never sees their own custom phrase and image than they can tell it isn't an authentic Bank of America page, and thus have a safeguard against phishing. This is all fine and dandy except for the fact that the password is entered on this second page, with the custom keyphrase and image. If WebKit could be made to save keychain values in situations such as this it would be quite nice. I'll attach two images to visually demonstrate what Bank of America does.
Attachments
The front page of Bank of America, with username field (233.14 KB, image/png)
2006-10-07 14:38 PDT, John Dagen
no flags
Sitekey confirmation page with (blacked out) custom phrase and image (100.87 KB, image/png)
2006-10-07 14:39 PDT, John Dagen
no flags
John Dagen
Comment 1 2006-10-07 14:38:34 PDT
Created attachment 10967 [details] The front page of Bank of America, with username field
John Dagen
Comment 2 2006-10-07 14:39:11 PDT
Created attachment 10968 [details] Sitekey confirmation page with (blacked out) custom phrase and image
Timothy Hatcher
Comment 3 2006-10-25 10:47:27 PDT
Good report, however this is a Safari bug, since Safari does the autofill. Please fiel a bug at http://bugreport.apple.com with all this info and copies of the HTML.
John Dagen
Comment 4 2006-12-29 10:43:22 PST
Filed as requested, radar 4902784. (It took me forever but I finally remembered to do so.)
Note You need to log in before you can comment on or make changes to this bug.