[tbb-bugs] #20097 [Applications/Tor Browser]: javascript: execution is disabled on medium-high security level on HTTPS website

Tor Bug Tracker & Wiki blackhole at torproject.org
Wed Sep 7 11:08:22 UTC 2016


#20097: javascript: execution is disabled on medium-high security level on HTTPS
website
-------------------------------------+-------------------------------------
     Reporter:  gk                   |      Owner:  tbb-team
         Type:  defect               |     Status:  new
     Priority:  Medium               |  Milestone:
    Component:  Applications/Tor     |    Version:
  Browser                            |   Keywords:  tbb-security-slider,
     Severity:  Normal               |  tbb-usability-website
Actual Points:                       |  Parent ID:
       Points:                       |   Reviewer:
      Sponsor:                       |
-------------------------------------+-------------------------------------
 With the security slider on Medium-High we disabled JavaScript execution
 on non HTTPS websites. However, it seems we are overly strict here as
 `javascript:` execution on HTTPS sites is not working either. This got
 reported on our blog:

 https://blog.torproject.org/blog/tor-browser-604-released#comment-203337

 https://bug1259785.bmoattachments.org/attachment.cgi?id=8734814 is the
 testcase mentioned there.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/20097>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list