#32429 closed defect (fixed)

Issues with about:blank and NoScript on .onion sites

Reported by: pf.team Owned by: tbb-team
Priority: High Milestone:
Component: Applications/Tor Browser Version:
Severity: Major Keywords: about:blank noscript
Cc: ma1 Actual Points: 0.1
Parent ID: Points:
Reviewer: Sponsor:

Description (last modified by Thorin)

Tor Browser: 9.0.1 (based on Mozilla Firefox 68.2.0esr) (64-bit) (Linux)

NoScript displays the following weird behavior on *.onion sites when the home page is changed from its default "about:tor" to "about:blank":

  • Impossible to forbid scripts on the Standard security level
  • Impossible to allow scripts on the Safest security level by setting TRUSTED/Temp. or TRUSTED/Custom. Scripts can only be enabled by disabling restrictions for this tab or disabling restrictions globally.

The first issue misleads the user about actual security settings, the second breaks functionality on sites.
We suspect that other functions or extensions of the browser may be broken when "about:tor" is replaced with "about:blank" as the default home page.

These issues do not affect clearnet sites and local files. They are also absent if the default home page is changed do some URL or any other special page like "about:logo" or "about:library".

These issues were absent in versions 8.5.* and 9.0

How to reproduce:

# Preferences => Home => Homepage and new windows => Blank Page
# Restart browser
# Open one of these URL to demonstrate:

# Try to disallow scripts Standard or allow on Safest

Example HTML/JS code:

<html lang="en">
        <title>Tor Browser 9.0.1 NoScript bug demonstration</title>
        <meta name="description" content="Tor Browser 9.0.1 NoScript bug demonstration" />
        <div id="center-link">
            <script>document.write("<span style='color:red; font-weight: bold'>Java Script works</span>")</script>
            <noscript><span style='color:green'>Java Script doesn't work</span></noscript>

Child Tickets

Change History (6)

comment:1 Changed 12 months ago by pf.team

Sorry, the "Restart browser" step must be before the demonstration step.

comment:2 Changed 12 months ago by Thorin

Description: modified (diff)

Sorry, the "Restart browser" step must be before the demonstration step

I edited it for you

comment:3 Changed 12 months ago by pili

Cc: ma1 added

comment:4 Changed 12 months ago by ma1

Thank you for your report.
I cannot reproduce with NoScript 11.0.8. Can you?

comment:5 Changed 12 months ago by pf.team

I also couldn't reproduce it after NoScript 11.0.8 was installed.

comment:6 Changed 12 months ago by gk

Actual Points: 0.1
Resolution: fixed
Status: newclosed

Thanks. I bumped Noscript to 11.0.8 (commit a750c9303469cd524c9091bbebca95a7905de912 and a8066f0972088860ac44ebb66da5b3c036f47135 on tor-browser-build's master and maint-9.0).

Note: See TracTickets for help on using tickets.