[tbb-commits] [tor-browser-bundle/master] Bug 22362: NoScript's XSS filter freezes the browser

gk at torproject.org gk at torproject.org
Thu Jun 8 18:17:47 UTC 2017


commit e8178d1373d6ce2599ef58eca4d52d1b6817263f
Author: Georg Koppen <gk at torproject.org>
Date:   Wed Jun 7 11:58:21 2017 +0000

    Bug 22362: NoScript's XSS filter freezes the browser
    
    Due to a bug in NoScript's XSS filter Tor Browser freezes on some websites.
    We disable that filter for now while waiting on a NoScript update.
---
 .../Data/Browser/profile.default/preferences/extension-overrides.js   | 4 ++++
 .../Data/Browser/profile.default/preferences/extension-overrides.js   | 4 ++++
 .../Data/Browser/profile.default/preferences/extension-overrides.js   | 4 ++++
 3 files changed, 12 insertions(+)

diff --git a/Bundle-Data/linux/Data/Browser/profile.default/preferences/extension-overrides.js b/Bundle-Data/linux/Data/Browser/profile.default/preferences/extension-overrides.js
index 6ef2c45..a34fb36 100644
--- a/Bundle-Data/linux/Data/Browser/profile.default/preferences/extension-overrides.js
+++ b/Bundle-Data/linux/Data/Browser/profile.default/preferences/extension-overrides.js
@@ -55,3 +55,7 @@ pref("noscript.restrictSubdocScripting", true);
 pref("noscript.showVolatilePrivatePermissionsToggle", false);
 pref("noscript.volatilePrivatePermissions", true);
 pref("noscript.clearClick", 0);
+// Workaround for bug 22362: Disable XSS filter for now as it freezes the
+// browser in some circumstances.
+pref("noscript.filterXGet", false);
+pref("noscript.filterXPost", false);
diff --git a/Bundle-Data/mac/TorBrowser/Data/Browser/profile.default/preferences/extension-overrides.js b/Bundle-Data/mac/TorBrowser/Data/Browser/profile.default/preferences/extension-overrides.js
index 6ef2c45..a34fb36 100644
--- a/Bundle-Data/mac/TorBrowser/Data/Browser/profile.default/preferences/extension-overrides.js
+++ b/Bundle-Data/mac/TorBrowser/Data/Browser/profile.default/preferences/extension-overrides.js
@@ -55,3 +55,7 @@ pref("noscript.restrictSubdocScripting", true);
 pref("noscript.showVolatilePrivatePermissionsToggle", false);
 pref("noscript.volatilePrivatePermissions", true);
 pref("noscript.clearClick", 0);
+// Workaround for bug 22362: Disable XSS filter for now as it freezes the
+// browser in some circumstances.
+pref("noscript.filterXGet", false);
+pref("noscript.filterXPost", false);
diff --git a/Bundle-Data/windows/Data/Browser/profile.default/preferences/extension-overrides.js b/Bundle-Data/windows/Data/Browser/profile.default/preferences/extension-overrides.js
index 6ef2c45..a34fb36 100644
--- a/Bundle-Data/windows/Data/Browser/profile.default/preferences/extension-overrides.js
+++ b/Bundle-Data/windows/Data/Browser/profile.default/preferences/extension-overrides.js
@@ -55,3 +55,7 @@ pref("noscript.restrictSubdocScripting", true);
 pref("noscript.showVolatilePrivatePermissionsToggle", false);
 pref("noscript.volatilePrivatePermissions", true);
 pref("noscript.clearClick", 0);
+// Workaround for bug 22362: Disable XSS filter for now as it freezes the
+// browser in some circumstances.
+pref("noscript.filterXGet", false);
+pref("noscript.filterXPost", false);



More information about the tbb-commits mailing list