Skip to content

Floccus on Firefox leaks cookies from Incognito into regular mode. #2107

@kenrestivo

Description

@kenrestivo

Which version of floccus are you using?

5.8.1

How many bookmarks do you have, roughly?

100

Are you using other means to sync bookmarks in parallel to floccus?

no

Sync method

WebDAV

Which browser are you using? In case you are using the phone App, specify the Android or iOS version and device please.

Firefox 128.5.0esr-1~deb12u1

Which version of Nextcloud Bookmarks are you using? (if relevant)

No response

Which version of Nextcloud? (if relevant)

No response

What kind of WebDAV server are you using? (if relevant)

nginx

Describe the Bug

If you click the bookmark star icon in an incognito window, the cookies from that page show up in your regular browser. This is surprising at least and potentially a significant security risk at worst.

Expected Behavior

When bookmarking from an incognito window, cookies from that window should not show up in the non-incognito regular browser windows.

To Reproduce

Perform these steps to duplicate:

  1. Have Floccus set to synchronize on changes
  2. Clear all cookies
  3. Inspect privacy by going to about:preferences#privacy and then Manage Data, to see you have no cookies
  4. Open an incognito window
  5. Go to a site that has cookies (99% of sites do)
  6. Click the bookmark star icon in the incognito tab
  7. Go to your non-incognito window
  8. Inspect privacy by going to about:preferences#privacy and then Manage Data,
  9. Notice the cookie from your incognito page has leaked into your non-incognito regular browser window

Debug log provided

  • I have provided a debug log file

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status

    Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions