henry pushed to branch tor-browser-153.3.0esr-16.0-1 at The Tor Project / Applications / Tor Browser Commits: 18e1b0a6 by Henry Wilkes at 2026-09-17T16:47:40+01:00 BB 45249: Remove the duplicate "Verified by" from the old site identity panel. - - - - - 088c60ee by Henry Wilkes at 2026-09-17T16:49:05+01:00 fixup! TB 23247: Communicating security expectations for .onion TB 45249: Hide verifier information when it is empty. Special thanks to @soni. - - - - - 3 changed files: - browser/base/content/browser-siteIdentity.js - browser/components/controlcenter/content/securityInformation.inc.xhtml - browser/themes/shared/controlcenter/panel.css Changes: ===================================== browser/base/content/browser-siteIdentity.js ===================================== @@ -1203,16 +1203,21 @@ var gIdentityHandler = { let owner = ""; // Fill in the CA name if we have a valid TLS certificate. - if (this._isSecureConnection || this._isCertUserOverridden) { - verifier = this._identityIconLabel.tooltipText; + if ( + this._secInfo && + (this._isSecureConnection || this._isCertUserOverridden) + ) { + // Remove "Verified by " from the verifier string. tor-browser#45249. + verifier = this.getIdentityData().caOrg; } // Fill in organization information if we have a valid EV certificate or // QWAC. - if (this._isEV || this._qwac) { + if (this._secInfo && (this._isEV || this._qwac)) { let iData = this.getIdentityData(this._qwac || this._secInfo.serverCert); owner = iData.subjectOrg; - verifier = this._identityIconLabel.tooltipText; + // Remove "Verified by " from the verifier string. tor-browser#45249. + verifier = iData.caOrg; // Build an appropriate supplemental block out of whatever location data we have if (iData.city) { @@ -1263,6 +1268,12 @@ var gIdentityHandler = { this._identityPopupContentOwner.textContent = owner; this._identityPopupContentSupp.textContent = supplemental; this._identityPopupContentVerif.textContent = verifier; + + // Hide "Verified by" section if this is empty for an onion host. + // tor-browser#45249. + document + .getElementById("identity-popup-securityView-extended-info") + .toggleAttribute("noverifier", this._uriIsOnionHost && verifier === ""); }, setURI(uri) { ===================================== browser/components/controlcenter/content/securityInformation.inc.xhtml ===================================== @@ -36,9 +36,11 @@ when-connection="secure-ev secure-etsi"/> <description id="identity-popup-content-verifier-label" when-connection="secure secure-ev secure-etsi" + when-verifier="true" data-l10n-id="identity-verifier-label"/> <description id="identity-popup-content-verifier" when-connection="secure secure-ev secure-etsi" + when-verifier="true" class="header"/> <description id="identity-popup-content-etsi" when-connection="secure-etsi" ===================================== browser/themes/shared/controlcenter/panel.css ===================================== @@ -109,6 +109,11 @@ display: none; } +/* Hide verifier information. tor-browser#45249. */ +#identity-popup-securityView-extended-info[noverifier] description[when-verifier] { + display: none !important; +} + /* Make sure hidden elements don't accidentally become visible from one of the above selectors (see Bug 1194258) */ #identity-popup [hidden] { View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/compare/fd1c191... -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/compare/fd1c191... You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help