Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Suggestion: Autocomplete, don't save query parameters #5191

Open
cliffordh opened this issue Jul 9, 2019 · 1 comment
Open

Suggestion: Autocomplete, don't save query parameters #5191

cliffordh opened this issue Jul 9, 2019 · 1 comment

Comments

@cliffordh
Copy link

@cliffordh cliffordh commented Jul 9, 2019

Description

Started typing "paypal.com" into the address bar, was presented with numerous autocomplete suggestions that included query parameters. This could be viewed as a security risk.

Steps to Reproduce

Checkout with Paypal on a site. Then start typing paypal.com into the address bar, the site redirect URL and other information about the transaction is exposed because of the query parameters.

Actual result:

Screen Shot 2019-07-09 at 11 18 27 AM

Expected result:

Autocomplete should only complete primary domain names and paths, but not include query parameters.

Reproduces how often:

Easily

Brave version (brave://version info)

0.66.99 Chromium: 75.0.3770.100 (Official Build) (64-bit)

Version/Channel Information:

Mac OS X Desktop, only tested.

  • Can you reproduce this issue with the current release?
    Yes

  • Can you reproduce this issue with the beta channel?
    Haven't tried

  • Can you reproduce this issue with the dev channel?
    Haven't tried

  • Can you reproduce this issue with the nightly channel?
    Haven't tried

Other Additional Information:

  • Does the issue resolve itself when disabling Brave Shields?
    No
  • Does the issue resolve itself when disabling Brave Rewards?
    No
  • Is the issue reproducible on the latest version of Chrome?
    I uninstalled Chrome :-)

Miscellaneous Information:

@bsclifton bsclifton added this to Untriaged Backlog in Security & Privacy via automation Jul 11, 2019
@diracdeltas diracdeltas added the sec-low label Jul 16, 2019
@fmarier fmarier moved this from Untriaged Backlog to P3, P4, & P5 Backlog in Security & Privacy Sep 27, 2019
@Brave-Matt
Copy link
Collaborator

@Brave-Matt Brave-Matt commented Oct 3, 2019

+1 on reddit:
https://www.reddit.com/r/brave_browser/comments/da2o5b/going_to_switch_to_brave_today_but_the_auto_fill/

I'd also like to note that in addition to option to disable Autocomplete suggestions, it may also be worth including the option to disable all suggestions in the address bar. Even if you turn of URL and Search suggestions in Settings, you'll still be suggested sites based on history and Bookmarks. Users should be have an option to disable these as well.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Security & Privacy
  
P3, P4, & P5 Backlog
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
5 participants
You can’t perform that action at this time.