Fx Nightly 50.0a cannot login to plain http site

Ask for help about NoScript, no registration needed to post
hssg
Posts: 4
Joined: Sat Jun 11, 2016 8:25 am

Fx Nightly 50.0a cannot login to plain http site

Post by hssg »

Firefox 50.0a in private browser mode fails to log into http://bato.to, site redirects to https and than login dumped.
Last edited by barbaz on Mon Aug 01, 2016 4:55 pm, edited 1 time in total.
Reason: edit title
Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:50.0) Gecko/20100101 Firefox/50.0
barbaz
Senior Member
Posts: 11118
Joined: Sat Aug 03, 2013 5:45 pm

Post by barbaz »

Off-topic to viewtopic.php?f=7&t=21952 , splitting.

Does disabling NoScript (Tools > Add-ons Manager > NoScript > Disable > Yes, remove ALL protections) get it working?
If so, when this issue occurs, do you see anything related in the Browser Console? (Ctrl-Shift-J)
(if you don't know what's related, turn off CSS warnings and post everything else you see)
*Always* check the changelogs BEFORE updating that important software!
-
hssg
Posts: 4
Joined: Sat Jun 11, 2016 8:25 am

Re:

Post by hssg »

barbaz wrote:Off-topic to viewtopic.php?f=7&t=21952 , splitting.

Does disabling NoScript (Tools > Add-ons Manager > NoScript > Disable > Yes, remove ALL protections) get it working?
If so, when this issue occurs, do you see anything related in the Browser Console? (Ctrl-Shift-J)
(if you don't know what's related, turn off CSS warnings and post everything else you see)

It's cannot login because Automatic Secure Cookies management is enabled,

Code: Select all

[NoScript HTTPS] AUTOMATIC SECURE on https://bato.to: session_id=a26afdbbe9e36e3c846c9a8b197c5725; domain=.bato.to; path=/; HttpOnly; Secure
[NoScript HTTPS] AUTOMATIC SECURE on https://bato.to: member_id=324235; domain=.bato.to; path=/; HttpOnly; Secure
[NoScript HTTPS] AUTOMATIC SECURE on https://bato.to: pass_hash=fbbc59edf42c9a739c7b5560c90ffdc9; domain=.bato.to; path=/; HttpOnly; Secure
[NoScript HTTPS] AUTOMATIC SECURE on https://bato.to: ipsconnect_d8874f8d538b1279c8106e636bf7afe9=1; domain=.bato.to; path=/; Secure
[NoScript HTTPS] AUTOMATIC SECURE on https://bato.to: coppa=0; domain=.bato.to; path=/; Secure
[NoScript HTTPS] AUTOMATIC SECURE on https://bato.to: session_id=a26afdbbe9e36e3c846c9a8b197c5725; domain=.bato.to; path=/; HttpOnly; Secure
Password fields present on an insecure (http://) page. This is a security risk that allows user login credentials to be stolen.[Learn More]bato.to
But bato.to is not forced to https by me. it's doing on it's own.

I can solve this problem by adding url to "Ignore unsafe cookies" field though.
And these messages not show up with it.
Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:50.0) Gecko/20100101 Firefox/50.0
barbaz
Senior Member
Posts: 11118
Joined: Sat Aug 03, 2013 5:45 pm

Re: Fx Nightly 50.0a cannot login to plain http site

Post by barbaz »

hssg wrote:I can solve this problem by adding url to "Ignore unsafe cookies" field though.
Great! That's the answer Image
*Always* check the changelogs BEFORE updating that important software!
-
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: Fx Nightly 50.0a cannot login to plain http site

Post by Thrawn »

And then complain to the website owner, because they are using quite unsafe practices; it's possible for someone to eavesdrop on your connection and hijack your logged-in session.
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.

True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:47.0) Gecko/20100101 Firefox/47.0
Post Reply