[tor-bugs] #2148 [Torbutton]: 1.3.x: RefSpoofer fails on 5 test cases out of 12.

Tor Bug Tracker & Wiki torproject-admin at torproject.org
Mon Jan 31 10:58:06 UTC 2011


#2148: 1.3.x: RefSpoofer fails on 5 test cases out of 12.
--------------------------------+-------------------------------------------
 Reporter:  T(A)ILS developers  |       Owner:  koryk         
     Type:  defect              |      Status:  assigned      
 Priority:  critical            |   Milestone:  Torbutton: 1.3
Component:  Torbutton           |     Version:  Torbutton: 1.3
 Keywords:  refspoofer          |      Points:                
   Parent:                      |  
--------------------------------+-------------------------------------------

Comment(by mikeperry):

 Based on my reading of this and my informal opinion of how this feature
 should work, I'm going to declare that case B2 and B3 are bugs.

 I think it was Kory's intention to implement a superset of the same-origin
 policy here, not the same-origin policy itself. I think for the goal of
 making sure sites decide to render properly, case B3 *should* send a
 referrer, as should B2.

 However, I would also suspect that case B2 should send the proper
 referrer. If the TAILS developers report correctly, it is sending the
 *destination* site in the referrer, and not the origin. Is this correct?

 If so, that is also a bug. B2 should send the *source* site as the
 referrer.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/2148#comment:6>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list