[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

Firefox noscript bug

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 11
Thread images: 1

File: orly.png (38KB, 192x192px) Image search: [Google]
orly.png
38KB, 192x192px
mozilla annoys me: I recently discovered that with the new webextensions you cannot "disable" javascript. you can only block it. there is an api which actually seems to be similar or even the same as the one in chrome:

tab.responseHeaders.push({
'name': 'Content-Security-Policy',
'value': 'script-src \'none\''
});

the problem with this crap is that javascript is not really disabled - it is blocked.

however, stupid as they were when they implemented this api, <noscript> tags are not treated the way they should be.

they are ignored, in the same way they would be ignored if javascript was enabled.

I have already filled a bug report and I have even hacked a webextension that inserts another fucking javascript file which then grabs all the <noscript> tags and replaces them with <span>. now my addon was rejected because:

>This version didn't pass review because of the following problems:
>
> This add-on is creating DOM nodes from HTML strings containing potentially unsanitized data,
>by assigning to innerHTML, jQuery.html, or through similar means.
>Aside from being inefficient, this is a major security risk.
>For more information, see https://developer.mozilla.org/en/XUL_School/DOM_Building_and_HTML_Insertion .

what do?

also:
there is no ?ltern?tive
>>
uMatrix doesn't have this problem
>>
>>62064644
I just checked and sorry - yes it does have the problem.

if I use only uMatrix to block everything except images and css on any page that has <noscript> tags, they will not be rendered or used for DOM building.
>>
>>62064781
That's good since the CIA niggers can't tell I'm blocking scripts. The scripts are however still blocked since unlike NoScript, uMatrix blocks the script from being fetched.
>>
>>62064468
>disabling js
use icecat
>>
>>62064827
how can they tell that you are blocking scripts just by NOT RENDERING <noscript> tags in your browser which have already been downloaded as part of the html?

if there was a <meta http-equiv="fresh"> anywhere, then you could be redirected. that should be disabled and this is another topic.

I did not know that NoScript fetches the blocked scripts. I am not using NoScript but this makes me wonder.
>>
>>62064848
I doubt that IceCat version 57 will behave differently than Firefox nightly 57

I also do not disable JS. I could do that in about:config and Javascript.enabled = false.

I just want to disable javascript on some pages.
>>
>>62064827
Looks like even web technology is too hard for /g/ now.
>>
>>62065115
I think that he was trolling because
>2017
>disable javascript
>wtf
>>
>>62065248
we js nao
>>
>>62065392
we lost privacy nao

have you got any meaningful addition to the topic of <noscript> tags in new firefox versions?
Thread posts: 11
Thread images: 1


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.