[tbb-bugs] #27589 [Applications/Tor Browser]: "Javascript is disabled on non-HTTPS sites" from security slider has regressed in TBB 8 / NoScript 10

Tor Bug Tracker & Wiki blackhole at torproject.org
Tue Sep 11 10:08:35 UTC 2018


#27589: "Javascript is disabled on non-HTTPS sites" from security slider has
regressed in TBB 8 / NoScript 10
-------------------------------------------------+-------------------------
 Reporter:  cypherpunks_reply                    |          Owner:  tbb-
                                                 |  team
     Type:  enhancement                          |         Status:  new
 Priority:  Medium                               |      Milestone:
Component:  Applications/Tor Browser             |        Version:
 Severity:  Normal                               |     Resolution:
 Keywords:  noscript, tbb-8.0-issues, tbb-       |  Actual Points:
  regression                                     |
Parent ID:                                       |         Points:
 Reviewer:                                       |        Sponsor:
-------------------------------------------------+-------------------------

Comment (by cypherpunks_reply):

 I should clarify that the issue of "no obvious way to revoke the
 permission without restarting the browser" only applies if you grant HTTP
 sites the default permission.  You could grant all HTTP sites Trusted
 permissions, and then when you're done, change them to Untrusted
 permission.  This seems wrong since HTTPS sites only get Default
 permissions with the slider on Safer.

 This is because of how NoScript works.  A changing a site to default
 permissions deletes it from from the per-site permission list.  This is
 only problematic because the way the "scripts disable for non-HTTPS"
 features is implemented.  The site's domain doesn't appear in the NoScript
 button popup as normal, but only as a line "http://http:" that applies to
 all http sites.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/27589#comment:7>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list