[tor-commits] [tor-browser-bundle/maint-7.0] Bug 22362: NoScript's XSS filter freezes the browser

gk at torproject.org gk at torproject.org
Thu Jun 8 18:18:31 UTC 2017


commit f0584bcbec0f5c15ad510368df5088ce64ec48b6
Author: Georg Koppen <gk at torproject.org>
Date:   Wed Jun 7 11:58:21 2017 +0000

    Bug 22362: NoScript's XSS filter freezes the browser
    
    Due to a bug in NoScript's XSS filter Tor Browser freezes on some websites.
    We disable that filter for now while waiting on a NoScript update.
---
 .../Data/Browser/profile.default/preferences/extension-overrides.js   | 4 ++++
 .../Data/Browser/profile.default/preferences/extension-overrides.js   | 4 ++++
 .../Data/Browser/profile.default/preferences/extension-overrides.js   | 4 ++++
 3 files changed, 12 insertions(+)

diff --git a/Bundle-Data/linux/Data/Browser/profile.default/preferences/extension-overrides.js b/Bundle-Data/linux/Data/Browser/profile.default/preferences/extension-overrides.js
index 6ef2c45..a34fb36 100644
--- a/Bundle-Data/linux/Data/Browser/profile.default/preferences/extension-overrides.js
+++ b/Bundle-Data/linux/Data/Browser/profile.default/preferences/extension-overrides.js
@@ -55,3 +55,7 @@ pref("noscript.restrictSubdocScripting", true);
 pref("noscript.showVolatilePrivatePermissionsToggle", false);
 pref("noscript.volatilePrivatePermissions", true);
 pref("noscript.clearClick", 0);
+// Workaround for bug 22362: Disable XSS filter for now as it freezes the
+// browser in some circumstances.
+pref("noscript.filterXGet", false);
+pref("noscript.filterXPost", false);
diff --git a/Bundle-Data/mac/TorBrowser/Data/Browser/profile.default/preferences/extension-overrides.js b/Bundle-Data/mac/TorBrowser/Data/Browser/profile.default/preferences/extension-overrides.js
index 6ef2c45..a34fb36 100644
--- a/Bundle-Data/mac/TorBrowser/Data/Browser/profile.default/preferences/extension-overrides.js
+++ b/Bundle-Data/mac/TorBrowser/Data/Browser/profile.default/preferences/extension-overrides.js
@@ -55,3 +55,7 @@ pref("noscript.restrictSubdocScripting", true);
 pref("noscript.showVolatilePrivatePermissionsToggle", false);
 pref("noscript.volatilePrivatePermissions", true);
 pref("noscript.clearClick", 0);
+// Workaround for bug 22362: Disable XSS filter for now as it freezes the
+// browser in some circumstances.
+pref("noscript.filterXGet", false);
+pref("noscript.filterXPost", false);
diff --git a/Bundle-Data/windows/Data/Browser/profile.default/preferences/extension-overrides.js b/Bundle-Data/windows/Data/Browser/profile.default/preferences/extension-overrides.js
index 6ef2c45..a34fb36 100644
--- a/Bundle-Data/windows/Data/Browser/profile.default/preferences/extension-overrides.js
+++ b/Bundle-Data/windows/Data/Browser/profile.default/preferences/extension-overrides.js
@@ -55,3 +55,7 @@ pref("noscript.restrictSubdocScripting", true);
 pref("noscript.showVolatilePrivatePermissionsToggle", false);
 pref("noscript.volatilePrivatePermissions", true);
 pref("noscript.clearClick", 0);
+// Workaround for bug 22362: Disable XSS filter for now as it freezes the
+// browser in some circumstances.
+pref("noscript.filterXGet", false);
+pref("noscript.filterXPost", false);



More information about the tor-commits mailing list