[tor-bugs] #27824 [- Select a component]: TorBrowser or NoScript 10 prevents cookies even if cookie exceptions are present

Tor Bug Tracker & Wiki blackhole at torproject.org
Sat Sep 22 23:04:43 UTC 2018


#27824: TorBrowser or NoScript 10 prevents cookies even if cookie exceptions are
present
-------------------------------------+-------------------------------------
 Reporter:  joebt                    |          Owner:  (none)
     Type:  defect                   |         Status:  new
 Priority:  Medium                   |      Component:  - Select a
                                     |  component
  Version:                           |       Severity:  Normal
 Keywords:  Tor Browser, NoScript,   |  Actual Points:
  cookies                            |
Parent ID:                           |         Points:
 Reviewer:                           |        Sponsor:
-------------------------------------+-------------------------------------
 In Linux-64 Mint 18.1 & NoScript 10.1.9.6, I can't set TBB 8 or 8.0.1 UI
 prefs to "Block cookies" and use cookie exceptions (session cookies).  TBB
 and / or NS won't use the exceptions to set cookies for them.

 -Up through TBB 7.5 & NS 5.x, blocking cookies globally & using exceptions
 worked fine.

 -It appeared the problem may be mostly NS, as uninstalling NS fixed most
 of the problem.  (NoScript forum says contact TorProject "support" for TBB
 & NS problems).

 Blocking cookies by default in browser prefs & entering site exceptions as
 needed always worked in TBB & NS 3, 4, 5.x.  It STILL works in Fx 60.1 &
 NS 10.1.9.6.

 When cookies are blocked & but an exception is entered,
 https://trac.torproject.org shows: "''Missing or invalid form token. Do
 you have cookies enabled''?"

 Switch the TBB UI pref to "Allow cookies" & cookies are set & allows
 logging in or browsing (for sites demanding cookies).
 Though to login on many sites, **every** option in NS 10 "Trusted" mode
 must be enabled.  I don't know if that's a good idea.  That wasn't true in
 TBB 7,5 & NS 5.x.

 Switch TBB pref back to "Block cookies & data" & no sites I've tested
 worked (but had cookie exceptions).  There's no reason to allow cookies
 for all sites, all the time.

 * Even if TBB cookies are enabled, only cookie names show in TBB "View
 cookies."  If you R-click the web page > Page Info > Security, cookie
 names & content are visible there.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/27824>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list