Opened 2 years ago

Last modified 4 weeks ago

#17933 assigned defect

Tor Browser does not isolate the pdf 'download' (via the download button) to URL bar domain

Reported by: arma Owned by: tbb-team
Priority: Medium Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: tbb-linkability, tbb-usability
Cc: arthuredelstein Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

I've logged in to the pets reviewing website, and I clicked on a pdf, and the pdf.js is showing me the pdf. Then I click on the 'download' link inside the pdf viewer, which in the past caused a pdf to end up on my disk. Now it causes an html file, essentially saying that I wasn't logged in, to end up on my disk instead.

I managed to work around it by "right click, save page as", which does what the download button used to do. But not sending any of the current credentials/cookies/etc to whatever is doing the download is pretty surprising.

Child Tickets

Change History (7)

comment:1 Changed 23 months ago by gk

Status: newneeds_information

Interesting. Do you think you could make the log for this available after setting extensions.torbutton.loglevel to 3 and extensions.torbutton.logmethod to 0 and restarting tor-browser with the --log switch? There should be a tor-browser.log file available this way.

I don't have a setup to reproduce that myself.

comment:2 Changed 23 months ago by gk

Keywords: tbb-linkability added

comment:3 Changed 15 months ago by gk

Keywords: tbb-usability added
Status: needs_informationassigned
Summary: Recent Tor Browser isolates the pdf 'download' outcome from the current tabTor Browser does not isolate the pdf 'download' (via the download button) to URL bar domain

We probably have arma's issue as downloading with the Download button is going over the catch-all curcuit and is not isolated to the URL bar domain.

comment:4 Changed 6 months ago by cypherpunks

Status: assignedneeds_information

arma, it seems to be fixed on alpha?

comment:5 in reply to:  4 ; Changed 6 months ago by gk

Status: needs_informationassigned

Replying to cypherpunks:

arma, it seems to be fixed on alpha?

That's not clear yet as the download is still broken, see comment:45:ticket:21766 (at least with e10s enabled).

comment:6 in reply to:  5 Changed 6 months ago by cypherpunks

Replying to gk:

Replying to cypherpunks:

arma, it seems to be fixed on alpha?

That's not clear yet as the download is still broken, see comment:45:ticket:21766 (at least with e10s enabled).

The download is fine (just set the checkbox ;)
The main problem is that the entire pdf doc is cached now, and saves without any network requests. (But try to open 100 MB pdf, and you'll be surprised :)

comment:7 Changed 4 weeks ago by arthuredelstein

Cc: arthuredelstein added
Note: See TracTickets for help on using tickets.