[GH-ISSUE #2107] Floccus on Firefox leaks cookies from Incognito into regular mode. #1414

Closed
opened 2026-02-25 22:39:57 +03:00 by kerem · 3 comments
Owner

Originally created by @kenrestivo on GitHub (Nov 26, 2025).
Original GitHub issue: https://github.com/floccusaddon/floccus/issues/2107

Which version of floccus are you using?

5.8.1

How many bookmarks do you have, roughly?

100

Are you using other means to sync bookmarks in parallel to floccus?

no

Sync method

WebDAV

Which browser are you using? In case you are using the phone App, specify the Android or iOS version and device please.

Firefox 128.5.0esr-1~deb12u1

Which version of Nextcloud Bookmarks are you using? (if relevant)

No response

Which version of Nextcloud? (if relevant)

No response

What kind of WebDAV server are you using? (if relevant)

nginx

Describe the Bug

If you click the bookmark star icon in an incognito window, the cookies from that page show up in your regular browser. This is surprising at least and potentially a significant security risk at worst.

Expected Behavior

When bookmarking from an incognito window, cookies from that window should not show up in the non-incognito regular browser windows.

To Reproduce

Perform these steps to duplicate:

  1. Have Floccus set to synchronize on changes
  2. Clear all cookies
  3. Inspect privacy by going to about:preferences#privacy and then Manage Data, to see you have no cookies
  4. Open an incognito window
  5. Go to a site that has cookies (99% of sites do)
  6. Click the bookmark star icon in the incognito tab
  7. Go to your non-incognito window
  8. Inspect privacy by going to about:preferences#privacy and then Manage Data,
  9. Notice the cookie from your incognito page has leaked into your non-incognito regular browser window

Debug log provided

  • I have provided a debug log file
Originally created by @kenrestivo on GitHub (Nov 26, 2025). Original GitHub issue: https://github.com/floccusaddon/floccus/issues/2107 ### Which version of floccus are you using? 5.8.1 ### How many bookmarks do you have, roughly? 100 ### Are you using other means to sync bookmarks in parallel to floccus? no ### Sync method WebDAV ### Which browser are you using? In case you are using the phone App, specify the Android or iOS version and device please. Firefox 128.5.0esr-1~deb12u1 ### Which version of Nextcloud Bookmarks are you using? (if relevant) _No response_ ### Which version of Nextcloud? (if relevant) _No response_ ### What kind of WebDAV server are you using? (if relevant) nginx ### Describe the Bug If you click the bookmark star icon in an incognito window, the cookies from that page show up in your regular browser. This is surprising at least and potentially a significant security risk at worst. ### Expected Behavior When bookmarking from an incognito window, cookies from that window should not show up in the non-incognito regular browser windows. ### To Reproduce Perform these steps to duplicate: 1. Have Floccus set to synchronize on changes 2. Clear all cookies 3. Inspect privacy by going to about:preferences#privacy and then Manage Data, to see you have no cookies 4. Open an incognito window 5. Go to a site that has cookies (99% of sites do) 6. Click the bookmark star icon in the incognito tab 7. Go to your non-incognito window 8. Inspect privacy by going to about:preferences#privacy and then Manage Data, 9. Notice the cookie from your incognito page has leaked into your non-incognito regular browser window ### Debug log provided - [ ] I have provided a debug log file
Author
Owner

@github-actions[bot] commented on GitHub (Nov 26, 2025):

Hello! 👋

Thank you for taking the time to open this issue with floccus. I know it's frustrating when software causes problems. You have made the right choice to come here and open an issue to make sure your problem gets looked at and if possible solved. Let me give you a short introduction on what to expect from this issue tracker to avoid misunderstandings. I'm Marcel. I created floccus a few years ago, and have been maintaining it since. I currently work for Nextcloud which leaves me with less time for side projects like this one than I used to have. I still try to answer all issues and if possible fix all bugs here, but it sometimes takes a while until I get to it. Until then, please be patient. It helps when you stick around to answer follow up questions I may have, as very few bugs can be fixed directly from the first bug report, without any interaction. If information is missing in your bug report and the issue cannot be solved without it, I will have to close the issue after a while. Note also that GitHub in general is a place where people meet to make software better together. Nobody here is under any obligation to help you, solve your problems or deliver on any expectations or demands you may have, but if enough people come together we can collaborate to make this software better. For everyone. Thus, if you can, you could also have a look at other issues to see whether you can help other people with your knowledge and experience. If you have coding experience it would also be awesome if you could step up to dive into the code and try to fix the odd bug yourself. Everyone will be thankful for extra helping hands! If you cannot lend a helping hand, to continue the development and maintenance of this project in a sustainable way, I ask that you donate to the project when opening an issue (or at least once your issue is solved), if you're not a donor already. You can find donation options at https://floccus.org/donate/. Thank you!

One last word: If you feel, at any point, like you need to vent, this is not the place for it; you can go to the Nextcloud forum, to twitter or somewhere else. But this is a technical issue tracker, so please make sure to focus on the tech and keep your opinions to yourself.

Thank you for reading through this primer. I look forward to working with you on this issue! Cheers! 💙

<!-- gh-comment-id:3583371063 --> @github-actions[bot] commented on GitHub (Nov 26, 2025): Hello! :wave: Thank you for taking the time to open this issue with floccus. I know it's frustrating when software causes problems. You have made the right choice to come here and open an issue to make sure your problem gets looked at and if possible solved. Let me give you a short introduction on what to expect from this issue tracker to avoid misunderstandings. I'm Marcel. I created floccus a few years ago, and have been maintaining it since. I currently work for Nextcloud which leaves me with less time for side projects like this one than I used to have. I still try to answer all issues and if possible fix all bugs here, but it sometimes takes a while until I get to it. Until then, please be patient. It helps when you stick around to answer follow up questions I may have, as very few bugs can be fixed directly from the first bug report, without any interaction. If information is missing in your bug report and the issue cannot be solved without it, I will have to close the issue after a while. Note also that GitHub in general is a place where people meet to make software better *together*. Nobody here is under any obligation to help you, solve your problems or deliver on any expectations or demands you may have, but if enough people come together we can collaborate to make this software better. For everyone. Thus, if you can, you could also have a look at other issues to see whether you can help other people with your knowledge and experience. If you have coding experience it would also be awesome if you could step up to dive into the code and try to fix the odd bug yourself. Everyone will be thankful for extra helping hands! If you cannot lend a helping hand, to continue the development and maintenance of this project in a sustainable way, I ask that you donate to the project when opening an issue (or at least once your issue is solved), if you're not a donor already. You can find donation options at <https://floccus.org/donate/>. Thank you! One last word: If you feel, at any point, like you need to vent, this is not the place for it; you can go to the Nextcloud forum, to twitter or somewhere else. But this is a technical issue tracker, so please make sure to focus on the tech and keep your opinions to yourself. Thank you for reading through this primer. I look forward to working with you on this issue! Cheers! :blue_heart:
Author
Owner

@marcelklehr commented on GitHub (Nov 28, 2025):

Hi @kenrestivo
Thank you for taking the time to give feedback by opening this issue!
I'm wondering if this is actually due to floccus or if this is simply a bug in firefox 128 🤔
Could you try disabling floccus and trying your steps again?

<!-- gh-comment-id:3588596465 --> @marcelklehr commented on GitHub (Nov 28, 2025): Hi @kenrestivo Thank you for taking the time to give feedback by opening this issue! I'm wondering if this is actually due to floccus or if this is simply a bug in firefox 128 🤔 Could you try disabling floccus and trying your steps again?
Author
Owner

@kenrestivo commented on GitHub (Nov 30, 2025):

Yep that's it, it appears to be a severe bug in Firefox! Even with the Floccus extension turned off, cookies from incognito mode are showing up in regular mode. How bizarre.

Thanks for your time, closing.

<!-- gh-comment-id:3592281107 --> @kenrestivo commented on GitHub (Nov 30, 2025): Yep that's it, it appears to be a severe bug in Firefox! Even with the Floccus extension turned off, cookies from incognito mode are showing up in regular mode. How bizarre. Thanks for your time, closing.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/floccus#1414
No description provided.