I am hosting with FireBase and using Firebase Auth with SDK for Flutter. If I induce a password reset email then the user is directed to a slightly different domain than the hosting domain for my app, i.e. <domain>.firebaseapp.com rather than: <domain>.web.app, the user then creates the new password and instinctively (90% of users so far) hit 'yes' to saving the password they just set in chromes database.
Then they go to my app and try to login. This is where the issue comes: Chrome detects the same password is in use as has been saved elsewhere, i.e. it spots a saved password for that different domain. As a result it lights up the usual SSL padlock with a big red "dangerous" and gives a terrifying warning saying that my website is deceptive and has just stolen all the users money and probably their dog.
This is an absolute show-stopper. I tried, thinking that human procedure would get me round this quickly, to warn users not to save their new password at the point of setting it, which spectacularly failed, in tests I tried putting the first sentence of the password reset email as "Please do not save your password immediately after setting it, but only when you are at the point of logging into the app." 4/5 testers didn't notice that sentence, they are all too used to password reset emails and ignored all content and just hit the link, the one person who did read the warning refused to go any further as they'd only read first half of sentence and understood that they weren't allowed to save password at all.
I could start creating a new domain and some cnames, but for a start that might not work - I can imagine some SSL issues doing that, also I'd rather liked the domain firebase made. If I went down the route of creating a password reset page myself, I presume I'd have to have named routes in the flutter navigator to accept a url (currently the app never shows any more detail beyond the # and this was quite deliberate), also I guess I'd need to access the token somehow to verify it etc. I'd really rather just use the built in mechanism, even if there isn't currently an option to redirect the user to my app afterwards they perform the reset.
A slightly tangential subject, but I've never come across the 'dangerous' tag in chrome when using the same password on two sites, until this time - for my app... Is there something specific to my flutter web app or firebase hosting causing this? Perhaps instead of dealing with the flow described above I can somehow eliminate that warning? While the warning seems like a reasonable one (using the same password all over the place is a silly), it strikes me as suspicious that I haven't seen it before until it happened on my app.
Thanks for any help