Opened 8 months ago

Closed 8 months ago

#32429 closed defect (fixed)

Issues with about:blank and NoScript on .onion sites

Reported by: Owned by: tbb-team
Priority: High Milestone:
Component: Applications/Tor Browser Version:
Severity: Major Keywords: about:blank noscript
Cc: ma1 Actual Points: 0.1
Parent ID: Points:
Reviewer: Sponsor:

Description (last modified by Thorin)

Tor Browser: 9.0.1 (based on Mozilla Firefox 68.2.0esr) (64-bit) (Linux)

NoScript displays the following weird behavior on *.onion sites when the home page is changed from its default "about:tor" to "about:blank":

  • Impossible to forbid scripts on the Standard security level
  • Impossible to allow scripts on the Safest security level by setting TRUSTED/Temp. or TRUSTED/Custom. Scripts can only be enabled by disabling restrictions for this tab or disabling restrictions globally.

The first issue misleads the user about actual security settings, the second breaks functionality on sites.
We suspect that other functions or extensions of the browser may be broken when "about:tor" is replaced with "about:blank" as the default home page.

These issues do not affect clearnet sites and local files. They are also absent if the default home page is changed do some URL or any other special page like "about:logo" or "about:library".

These issues were absent in versions 8.5.* and 9.0

How to reproduce:

# Preferences => Home => Homepage and new windows => Blank Page
# Restart browser
# Open one of these URL to demonstrate:

# Try to disallow scripts Standard or allow on Safest

Example HTML/JS code:

<html lang="en">
        <title>Tor Browser 9.0.1 NoScript bug demonstration</title>
        <meta name="description" content="Tor Browser 9.0.1 NoScript bug demonstration" />
        <div id="center-link">
            <script>document.write("<span style='color:red; font-weight: bold'>Java Script works</span>")</script>
            <noscript><span style='color:green'>Java Script doesn't work</span></noscript>

Child Tickets

Change History (6)

comment:1 Changed 8 months ago by

Sorry, the "Restart browser" step must be before the demonstration step.

comment:2 Changed 8 months ago by Thorin

Description: modified (diff)

Sorry, the "Restart browser" step must be before the demonstration step

I edited it for you

comment:3 Changed 8 months ago by pili

Cc: ma1 added

comment:4 Changed 8 months ago by ma1

Thank you for your report.
I cannot reproduce with NoScript 11.0.8. Can you?

comment:5 Changed 8 months ago by

I also couldn't reproduce it after NoScript 11.0.8 was installed.

comment:6 Changed 8 months ago by gk

Actual Points: 0.1
Resolution: fixed
Status: newclosed

Thanks. I bumped Noscript to 11.0.8 (commit a750c9303469cd524c9091bbebca95a7905de912 and a8066f0972088860ac44ebb66da5b3c036f47135 on tor-browser-build's master and maint-9.0).

Note: See TracTickets for help on using tickets.