[tor-bugs] #18271 [Website]: move <script> from wml files to separate js files

Tor Bug Tracker & Wiki blackhole at torproject.org
Sun Feb 7 16:29:25 UTC 2016


#18271: move <script> from wml files to separate js files
-----------------------------+-----------------------
     Reporter:  arma         |      Owner:  Sebastian
         Type:  enhancement  |     Status:  new
     Priority:  Medium       |  Milestone:
    Component:  Website      |    Version:
     Severity:  Normal       |   Keywords:
Actual Points:               |  Parent ID:
       Points:               |    Sponsor:
-----------------------------+-----------------------
 Right now we have <script> tags mixed with our other html in the wml files
 on the website.

 Weasel believes that if we move the scripts to their own separate .js
 files, then we could enable a Content-Security-Policy header with script-
 src 'self', thus making it harder for xss injections.

 This seems like a wise step to take.

 Affected files include (and I think are limited to):
 en/index.wml
 donate/en/donate.wml
 donate/en/donate-amazon.wml
 docs/en/debian.wml
 download/en/download-easy.wml
 download/en/download.wml
 docs/torbutton/en/index.wml

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/18271>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list