Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-53462

Jenkins websites use non-trusted 'submit' event to start form submission when current browser is Firefox

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Reopened (View Workflow)
    • Priority: Major
    • Resolution: Unresolved
    • Component/s: core
    • Labels:
    • Environment:
      classic login form (before 2.128), regular "Save" form submission buttons on the classic UI
    • Similar Issues:
    • Released As:
      Jenkins 2.173 to 2.201, removed from 2.202

      Description

      HTML spec [[1]|https://w3c.github.io/uievents/#trusted-events] says "Most untrusted events will not trigger default actions, with the exception of the click event.". Now Firefox doesn't comply with the spec. When I try to fix the bug [[2]|https://bugzilla.mozilla.org/show_bug.cgi?id=1370630], a regression has happened on all Jenkins websites. Users can't login Jenkins websites with Firefox anymore. After some experiments, it seems the Jenkins websites detect the browser's user agent and use untrusted 'submit' event to start form submission when the current browser is Firefox. Changing the UA of Chrome to the same string as Firefox also block the form submission.

       

      The steps I used to reproduce this problem

      On Chrome

      1. Change UA to the same string as Firefox
      2. Navigate https://jenkins.qa.ubuntu.com/
      3. Click login
      4. Enter username/password and press 'log in' button
      5. Nothing happened

      Expectation

      Don't use untrusted events to start form submission on Jenkins websites.

       

      [1] https://w3c.github.io/uievents/#trusted-events

      [2] https://bugzilla.mozilla.org/show_bug.cgi?id=1370630

       

        Attachments

          Issue Links

            Activity

            iamstone ming-chou shih created issue -
            rtyler R. Tyler Croy made changes -
            Field Original Value New Value
            Resolution Won't Fix [ 2 ]
            Status To Do [ 10003 ] Done [ 10004 ]
            top12345tw Edgar Chen made changes -
            Resolution Won't Fix [ 2 ]
            Status Done [ 10004 ] To Do [ 10003 ]
            danielbeck Daniel Beck made changes -
            Component/s core [ 15593 ]
            Component/s core [ 21434 ]
            Key WEBSITE-454 JENKINS-53462
            Workflow WEBSITE: Software Development Workflow [ 225179 ] JNJira + In-Review [ 231329 ]
            Project Jenkins Website [ 10401 ] Jenkins [ 10172 ]
            Status To Do [ 10003 ] Open [ 1 ]
            danielbeck Daniel Beck made changes -
            Environment All Jenkins websites. e.g. https://jenkins.qa.ubuntu.com/ Any Jenkins login form
            tscherler Thorsten Scherler made changes -
            Assignee Thorsten Scherler [ tscherler ]
            tscherler Thorsten Scherler made changes -
            Status Open [ 1 ] In Progress [ 3 ]
            danielbeck Daniel Beck made changes -
            Labels lts-candidate
            danielbeck Daniel Beck made changes -
            Link This issue is related to JENKINS-54333 [ JENKINS-54333 ]
            danielbeck Daniel Beck made changes -
            Link This issue is related to JENKINS-54261 [ JENKINS-54261 ]
            jglick Jesse Glick made changes -
            Link This issue relates to JENKINS-54551 [ JENKINS-54551 ]
            danielbeck Daniel Beck made changes -
            Link This issue is related to JENKINS-54570 [ JENKINS-54570 ]
            danielbeck Daniel Beck made changes -
            Link This issue is related to JENKINS-54318 [ JENKINS-54318 ]
            danielbeck Daniel Beck made changes -
            Released As Jenkins 2.173
            Assignee Thorsten Scherler [ tscherler ] Daniel Beck [ danielbeck ]
            Resolution Fixed [ 1 ]
            Status In Progress [ 3 ] Fixed but Unreleased [ 10203 ]
            danielbeck Daniel Beck made changes -
            Status Fixed but Unreleased [ 10203 ] Resolved [ 5 ]
            danielbeck Daniel Beck made changes -
            Environment Any Jenkins login form
            classic login form (before 2.128), regular "Save" form submission buttons on the classic UI
            olivergondza Oliver Gondža made changes -
            Labels lts-candidate 2.164.3-fixed
            danielbeck Daniel Beck made changes -
            Status Resolved [ 5 ] Closed [ 6 ]
            danielbeck Daniel Beck made changes -
            Link This issue is duplicated by JENKINS-54333 [ JENKINS-54333 ]
            dnusbaum Devin Nusbaum made changes -
            Link This issue relates to JENKINS-58296 [ JENKINS-58296 ]
            danielbeck Daniel Beck made changes -
            Assignee Daniel Beck [ danielbeck ]
            Resolution Fixed [ 1 ]
            Status Closed [ 6 ] Reopened [ 4 ]
            danielbeck Daniel Beck made changes -
            Released As Jenkins 2.173 Jenkins 2.173 to 2.2.201, removed from 2.202
            danielbeck Daniel Beck made changes -
            Released As Jenkins 2.173 to 2.2.201, removed from 2.202 Jenkins 2.173 to 2.201, removed from 2.202

              People

              Assignee:
              Unassigned Unassigned
              Reporter:
              iamstone ming-chou shih
              Votes:
              1 Vote for this issue
              Watchers:
              9 Start watching this issue

                Dates

                Created:
                Updated: