View Full Version : Gallery passwords can't be remembered by browser
jfriend
Apr-02-2009, 03:10 PM
It appears that gallery passwords cannot be properly remembered by my browser (Firefox 3). It will remember one gallery password, but then if I go to a different password protected gallery, it won't separately remember that password. I suspect that's because the URL is the same for all password screens, regardless of gallery. I would like it if it could be made to work so that the browser can remember each gallery password separately. I don't know if that means the gallery ID needs to be tacked onto the URL or something like that.
Andy
Apr-03-2009, 09:07 AM
Hm. I was able to use passwords, saved, on this site:
http://andydemo.smugmug.com/DemoSite
(gallery Just Stuff and Gallery NPS Map - passwords are the hints).
Also this gallery: http://andytheme.smugmug.com/gallery/4552903_jx8jj#502675104_pN8rA
Or am I not understanding you?
jfriend
Apr-03-2009, 03:49 PM
Hm. I was able to use passwords, saved, on this site:
http://andydemo.smugmug.com/DemoSite
(gallery Just Stuff and Gallery NPS Map - passwords are the hints).
Also this gallery: http://andytheme.smugmug.com/gallery/4552903_jx8jj#502675104_pN8rA
Or am I not understanding you?
Perhaps I didn't explain. The browser doesn't know the difference between a password for Gallery A, a password for Gallery B and a password for Gallery C (because the URL is the same for all pwd prompts) so all the browser does is save the last password you entered. This is of not value because Smugmug saves the last password in a cookie. What I want is for the browser to be able to save the password for all the galleries I access. It currently can't do that. I think the issue is that the URL is the same no matter what gallery you are entering the pwd for so the browser thinks they are all the same destination when they are not.
Steps to reproduce:
Create three galleries each with different pwds
Log out
Access Gallery A. You are prompted for a pwd. Enter the pwd and let the browser remember the pwd.
Access Gallery B. You are prompted for a pwd. Enter the pwd and let the browser remember the pwd.
Access Gallery C. You are prompted for a pwd. Enter the pwd and let the browser remember the pwd.
Access Gallery A. You are prompted for a pwd and the browser has filled in a pwd. If you try the pwd that the browser has filled in, it doesn't work (my guess is that it has filled in the pwd for Gallery C, not Gallery A). This is what I want to work.I think it would work properly if each pwd dialog was a different URL.
Make sense?
Andy
Apr-03-2009, 06:22 PM
Perhaps I didn't explain. The browser doesn't know the difference between a password for Gallery A, a password for Gallery B and a password for Gallery C (because the URL is the same for all pwd prompts) so all the browser does is save the last password you entered. This is of not value because Smugmug saves the last password in a cookie. What I want is for the browser to be able to save the password for all the galleries I access. It currently can't do that. I think the issue is that the URL is the same no matter what gallery you are entering the pwd for so the browser thinks they are all the same destination when they are not.
Steps to reproduce:
Create three galleries each with different pwds
Log out
Access Gallery A. You are prompted for a pwd. Enter the pwd and let the browser remember the pwd.
Access Gallery B. You are prompted for a pwd. Enter the pwd and let the browser remember the pwd.
Access Gallery C. You are prompted for a pwd. Enter the pwd and let the browser remember the pwd.
Access Gallery A. You are prompted for a pwd and the browser has filled in a pwd. If you try the pwd that the browser has filled in, it doesn't work (my guess is that it has filled in the pwd for Gallery C, not Gallery A). This is what I want to work.I think it would work properly if each pwd dialog was a different URL.
Make sense?Yeah it makes sense. Did you try my examples? Maybe I'm dumb but it's working for me?
jfriend
Apr-03-2009, 06:49 PM
Yeah it makes sense. Did you try my examples? Maybe I'm dumb but it's working for me? Interesting, something changed recently so maybe this isn't much of an issue. If I login to three successive password protected galleries (all with different passwords), I can still get into to all three of them without even being prompted for a password, even after quitting from the browser. When I look at the cookies, I see a password cookie for each browser. Unless I'm going bonkers, this is fairly new functionality because I know it didn't use to work that way.
Anyway, I like the way it works now. The saved password in the browser is just confusing, but isn't needed very often anymore because you cookie multiple passwords.
Now, something else I noticed. Passwords are saved "in the clear" in the cookie and thus all these passwords are sent with the cookies in the clear over the internet on nearly every xxx.smugmug.com page access. Is that how your sorcerers intend for it to work?
cabbey
Apr-03-2009, 10:34 PM
It appears that gallery passwords cannot be properly remembered by my browser (Firefox 3). It will remember one gallery password, but then if I go to a different password protected gallery, it won't separately remember that password. I suspect that's because the URL is the same for all password screens, regardless of gallery. I would like it if it could be made to work so that the browser can remember each gallery password separately. I don't know if that means the gallery ID needs to be tacked onto the URL or something like that.
hmm.... Are you perhaps looking at the url after a failure attempt? On the *first* try the url will be something like /gallery/id_key. If you get the password wrong on that try, the url will become /gallery/password.mg, but the gallery identification is passed along in the form, so it doesn't need to be on the url. it will remain like that until you get it right. Without passing that along, we would never be able to put the proper gallery name or hint on the page, or look authenticate the password when you give it.
And as far as I know, this has worked for as long as I've been a customer... long before I joined the company. My parents computer has at least 5 different gallery passwords cookied onto it across two accounts. I set them on a visit a couple years ago, they've never asked me what the passwords are, probably don't even know the galleries are protected, and they have no issues accessing those galleries.
So I don't know what you're seeing with firefox on your box... but it definitely doesn't match my experience. :dunno
vBulletin® v3.8.5, Copyright ©2000-2012, Jelsoft Enterprises Ltd.