When we consolidate the security slider options into just "High", "Medium", and "Default", we should ask Giorgio if he can give us a way to allow javascript: links when JS is enabled for HTTPS first party pages (but not http pages).
This is the main thing that I've noticed breaking on "Medium-High", which if we make the new "Medium", we should definitely fix.
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Child items 0
Show closed items
No child items are currently assigned. Use child items to break down this issue into smaller parts.
Linked items 0
Link issues together to show that they're related.
Learn more.
It's good that you find some of my comments on the blog useful :), only some of them, though :(
And we need to cope with NoScript's whitelisting, because Giorgio is busy with fighting with e10s :(
Fixing this is in my TODO list for next release, thank you.
Thanks. Just to give you a heads-up on our timeframe for getting a stable 6.5 out (which includes the enhanced security slider): we currently plan to release 6.5 end of January 2017. Thus, if a NoScript version with a fix would be available by then that would be neat.