4 ms·
I wish sites would test their forms with popular password management systems. This kind of thing happens all too often (thought perhaps not with such a high cos
by tedyoung 6y ago
I wish sites would test their forms with popular password management systems. This kind of thing happens all too often (thought perhaps not with such a high cost). Why not make it easy for people who auto-fill with these programs -- don't fight them.
(And I won't get into sites that won't let you paste passwords into their forms.)
- s3cur3 6y agoThis. If your form is broken with autofill, your form is broken.
- MattGaiser 6y agoThe testing burden is already enormous for things people want sites tested for.
- thanksforfish 6y agoWhats the solution for the busy engineer? Anyone know a Selenium plug in that let's you run with browser extensions or something? There's too many popular extensions to test manually.
- MattGaiser 6y agoThis is probably so far down the list that I would be interested to hear of any kind of testing of extensions at all for non-extension companies.
- enjoylife 6y agoHaven't seen this automated, but I have seen internal issues raised by folks within large orgs when their extension started breaking things. But it's only once you have 50+ to 100's of engineers working on a product, each with a subset of extensions installed, that you can rely on the cross product of engineers and their installed extensions for realistic coverage.
- MattGaiser 6y agoI've never worked on a team of more than 7 on a product, so even testing on Firefox is considered too much work for testing. Put in dollars, it probably costs 5-10 million a year (if not more) to test extensions even haphazardly.
- edoceo 6y agoI feel like I could get pretty far building this, with that budget.
- clintonb 6y agoFollow this guide: https://support.1password.com/compatible-website-design/ https://support.1password.com/compatible-website-design/. Even if you can't test, at least try. I find that few forms take the basic steps. Most importantly: don't fuck with paste!
- deleted 6y ago[deleted]
- murermader 6y agoI mean what is there to test, really? Just use the the different input types and mark your fields as "email", "password" and so on. There is nothing to test really. If a password manager does not work when given clear hints / type description of what is expected, then that is the fault of the password manager.
- onelovetwo 6y agoOr 1Pass does a little bit more smart in checking before randomly entering text? It wouldn't be difficult to catch this
- chrismorgan 6y agoThe problem is that all of these autofillers are already way too complex, because almost no one uses the optimal markup (adding the attribute autocomplete="cc-exp-year", in this case)—almost no one has even heard of the proper autocomplete markup here (I remember being in a conference room with two or three hundred other web developers a couple of years back, and the speaker asked who knew about autocomplete="new-password" and the likes; only three of us raised our hands: I and my coworker, and one other). They’re already complex enough that it’s a disaster trying to figure anything out. You say it wouldn’t be difficult to catch this, but either it’ll be a special case finely tuned for this particular site, or it’ll break another site, causing expiry year to no longer be filled out where previously it was and should be.
- bombcar 6y agoWhere are these various autocompletes detailed?
- throwanem 6y agoMDN has a good list: https://developer.mozilla.org/en-US/docs/Web/HTML/Attributes/autocomplete https://developer.mozilla.org/en-US/docs/Web/HTML/Attributes...
- JimDabell 6y agoHTML 5.2 § 4.10.18.7. Autofill: https://www.w3.org/TR/html52/sec-forms.html#sec-autofill https://www.w3.org/TR/html52/sec-forms.html#sec-autofill
- lamontcg 6y agoI wonder how many of those devs use a password manager and just thought it was magic they didn't need to worry about when they were writing those kinds of forms. I assumed that kind of markup had to exist, but its not my job to do web development at all, so time being finite, I'd never seen those. But I always assumed that they'd have to exist if I ever went looking. Why do people whose job it is to know these things not bother checking?
- deleted 6y ago[deleted]
- kiririn 6y agoI’d settle for login forms that don’t hide the password box until you enter your username/email. I don’t see how they benefit real users in any way, and my password manager can’t understand it, requiring manual copy/paste entry
- jaywalk 6y agoThis is (generally) done because they offer SSO functionality, and need to know whether to redirect the user to their corporate SSO page or show the password prompt.