3 ms·
Chrome is 100% the IE. They blatantly ignore standards, the most obvious of which is their treatment of autocomplete=off in forms[1]. They broke the ability t
by Arcsech 9y ago
Chrome is 100% the IE.
They blatantly ignore standards, the most obvious of which is their treatment of autocomplete=off in forms[1]. They broke the ability to disable autocomplete, and since then have been intentionally breaking workarounds people find to actually turn off autocomplete. This has been a major pain in the butt at work.
Before you yell at me about password managers or whatever, we don't use this on our login form: We make an app that collects some sensitive data that it is very pointless to autocomplete, and we've had user complaints about this very issue, but there's nothing we can do about it because Google unilaterally decided they know better than us.
[1]: https://stackoverflow.com/a/22694173 https://stackoverflow.com/a/22694173 (make sure to read the comments!)
- kuschku 9y ago> They blatantly ignore standards, the most obvious of which is their treatment of autocomplete=off in forms[1]. They broke the ability to disable autocomplete, and since then have been intentionally breaking workarounds people find to actually turn off autocomplete. This has been a major pain in the butt at work. My solution to that is simple. I have a microservice that tells my services how to get autocomplete=off automatically. This microservice determines the required values and ids by scraping the search box on google.com every hour, and extracting the values of the tag matching input[name=q]. That way I can fully automate autocomplete=off, and ensure it works.
- JohnBooty 9y agoThat is filthy, and I absolutely love it.
- kuschku 9y agoIndeed it is, but sometimes it’s necessary. I absolutely only use it for search boxes where I provide custom history for previous entries, and custom suggestions. Without autocomplete=off, these are horrible to use. And this was the only way I could figure out that would guarantee that it would be disabled, even after browser updates.
- paulirish 9y agoFWIW, the HTML spec says that the autocomplete=off means either 1) the input shouldn't be autofilled or 2) the input is for sensitive information. It doesn't require handling it only as the first case. https://html.spec.whatwg.org/multipage/form-control-infrastructure.html#autofilling-form-controls:-the-autocomplete-attribute https://html.spec.whatwg.org/multipage/form-control-infrastr...
- Arcsech 9y ago> "When an element's autofill field name is "off", the user agent should not remember the control's data, and should not offer past values to the user." Seems pretty clear to me. The only exception I see is: > "A user agent may allow the user to override an element's autofill field name, e.g. to change it from "off" to "on" to allow values to be remembered and prefilled despite the page author's objections, or to always "off", never remembering values." But that's user-initiated action, not something the browser should do for every field just because it feels like it.