Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Opening a link to "notifications" in an email received from facebookmail.com with Firefox that has Facebook Container Addon installed results in Firefox redirecting to a page to reset the account password. #929

Open
Aoxo opened this issue Jun 6, 2023 · 0 comments

Comments

@Aoxo
Copy link

Aoxo commented Jun 6, 2023

  • Facebook Container Version: 2.3.9
  • Operating System + Version: Xubuntu 22.04 LTS
  • Firefox Version: 113.0.2
  • Other installed Add-ons + Version + Enabled/Disabled-Status: Ublock Origin 1.49.2 (Enabled)
  • Facebook is set to stay logged in and credentials saved.
  • These are legitimate emails from Facebook.

Actual behavior

If the Facebook Container addon is ENABLED and firefox is closed:
Opening a hyperlink to "Notifications" in an email received from facebookmail.com using Thunderbird opens the URL in Firefox, but it immediately redirects to a "reset your password" page with a url beginning with "http://www.facebook.com/recover/initiate...".

If the Facebook Container addon is ENABLED and firefox is already running and logged into facebook:
Opening a hyperlink to "Notifications" in an email received from facebookmail.com using Thunderbird opens the URL in Firefox. I am not prompted to login. I am presented with the Facebook Notifications.

If the Facebook Container addon is DISABLED and Firefox is closed:
Opening a hyperlink to "Notifications" in an email received from facebookmail.com using Thunderbird opens the URL in Firefox. I am then presented with a prompt to login to facebook. After providing credentials I'm presented with the Facebook Notifications.

If the Facebook Container addon is DISABLED and Firefox is already running and logged into facebook:
Opening a hyperlink to "Notifications" in an email received from facebookmail.com using Thunderbird opens the URL in Firefox. I am presented with the Facebook Notifications.

Expected behavior

Opening a link to facebook in an email that is legitimate should not trigger a password reset when facebook container is enabled. It should open the notifications page if I am logged in, or ask me to log in if I am not already.

Steps to reproduce

  1. Install and enable facebook container
  2. Close Firefox
  3. Open Thunderbird (or any other email client probably)
  4. Open an email from facebook that contains a link to "Notifications".
  5. Click on a link that says "you have [x] notifications"
  6. Watch Firefox open.
  7. Watch Firefox begin to load the notifications page, then suddenly redirect to http://www.facebook.com/recover/initiate...
  8. The facebook page that opens is not Notifications or a login prompt, but a screen that would appear if one has chosen to reset their password.

Notes

Because of this bug my poor mom, who is suffering from dementia, resets her facebook password several times a day sometimes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant