[tor-commits] [torbutton/master] Bug 26624: Only block OBJECT on highest slider level

gk at torproject.org gk at torproject.org
Tue Sep 18 07:35:25 UTC 2018


commit b9626557ddf9a3faf5fb88f99f479145d7789a7f
Author: Georg Koppen <gk at torproject.org>
Date:   Wed Sep 12 06:16:53 2018 +0000

    Bug 26624: Only block OBJECT on highest slider level
---
 src/modules/noscript-control.js | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/src/modules/noscript-control.js b/src/modules/noscript-control.js
index a03755de..66a00528 100644
--- a/src/modules/noscript-control.js
+++ b/src/modules/noscript-control.js
@@ -16,20 +16,20 @@ let log = (level, msg) => logger.log(level, msg);
 // ## NoScript settings
 
 // Minimum and maximum capability states as controlled by NoScript.
-const max_caps = ["fetch", "font", "frame", "media", "other", "script", "webgl"];
+const max_caps = ["fetch", "font", "frame", "media", "object", "other", "script", "webgl"];
 const min_caps = ["frame", "other"];
 
 // Untrusted capabilities for [Standard, Safer, Safest] safety levels.
 const untrusted_caps = [
   max_caps, // standard safety: neither http nor https
-  ["frame", "font", "other"], // safer: http
+  ["frame", "font", "object", "other"], // safer: http
   min_caps, // safest: neither http nor https
 ];
 
 // Default capabilities for [Standard, Safer, Safest] safety levels.
 const default_caps = [
   max_caps, // standard: both http and https
-  ["fetch", "font", "frame", "other", "script", "webgl"], // safer: https only
+  ["fetch", "font", "frame", "object", "other", "script", "webgl"], // safer: https only
   min_caps, // safest: both http and https
 ];
 



More information about the tor-commits mailing list