[tor-bugs] #29872 [Applications/Tor Browser]: Searching from about:tor cause a NoScript XSS warning popup

Tor Bug Tracker & Wiki blackhole at torproject.org
Sun Mar 24 22:02:19 UTC 2019


#29872: Searching from about:tor cause a NoScript XSS warning popup
--------------------------------------+-----------------------------------
 Reporter:  boklm                     |          Owner:  tbb-team
     Type:  defect                    |         Status:  needs_information
 Priority:  Medium                    |      Milestone:
Component:  Applications/Tor Browser  |        Version:
 Severity:  Normal                    |     Resolution:
 Keywords:  TorBrowserTeam201903      |  Actual Points:
Parent ID:                            |         Points:
 Reviewer:                            |        Sponsor:
--------------------------------------+-----------------------------------

Comment (by ma1):

 OK, I can see it. It's when you use the search box inside the page, not
 the one(s) in the browser UI, which are exempt by the XSS filter fallback
 warning on every cross-site POST request I had to introduce for POST
 scanning being disabled due to
 https://bugzilla.mozilla.org/show_bug.cgi?id=1532530.
 I'm trying to add a further exception for about:tor, but the real solution
 would be the aforementioned Mozilla bug (which already has a patch
 attached) being fixed, of course.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/29872#comment:4>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list