[tor-bugs] #4194 [EFF-HTTPS Everywhere]: Https everywhere 1.03 and 2.0 dev 2 blocking webfonts

Tor Bug Tracker & Wiki torproject-admin at torproject.org
Thu Oct 6 17:34:37 UTC 2011


#4194: Https everywhere 1.03 and 2.0 dev 2 blocking webfonts
----------------------------------+-----------------------------------------
 Reporter:  eilegz                |          Owner:  pde
     Type:  defect                |         Status:  new
 Priority:  normal                |      Milestone:     
Component:  EFF-HTTPS Everywhere  |        Version:     
 Keywords:  webfonts              |         Parent:     
   Points:                        |   Actualpoints:     
----------------------------------+-----------------------------------------

Comment(by pde):

 This is another nsIContentPolicy disablement bug (from the fix to #3882).
 Requests like this one aren't happening in 1.0.3 / 2.0development.1

 https://themes.googleusercontent.com/static/fonts/marvel/v1/L2PPfTze83vDMefumW3xvw.woff

 GET /static/fonts/marvel/v1/L2PPfTze83vDMefumW3xvw.woff HTTP/1.1
 Host: themes.googleusercontent.com
 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:7.0.1) Gecko/20100101
 Firefox/7.0.1 Iceweasel/7.0.1
 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
 Accept-Language: en-us,en;q=0.5
 Accept-Encoding: gzip, deflate
 Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
 Connection: keep-alive
 Referer:
 http://foros.slot-1.net/style.php?id=4&lang=en&sid=bcca3908c342e92b21e3adb16845c818
 Origin: http://foros.slot-1.net

 HTTP/1.1 200 OK
 Content-Type: font/woff
 Last-Modified: Wed, 03 Aug 2011 19:01:01 GMT
 Date: Thu, 06 Oct 2011 17:26:48 GMT
 Expires: Fri, 05 Oct 2012 17:26:48 GMT
 Access-Control-Allow-Origin: *
 X-Content-Type-Options: nosniff
 Server: sffe
 Content-Length: 20544
 X-XSS-Protection: 1; mode=block
 Cache-Control: public, max-age=31536000
 Age: 1

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/4194#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list