Opened 8 years ago

Closed 8 years ago

#4194 closed defect (fixed)

Https everywhere 1.03 and 2.0 dev 2 blocking webfonts

Reported by: eilegz Owned by: pde
Priority: High Milestone:
Component: HTTPS Everywhere/EFF-HTTPS Everywhere Version:
Severity: Keywords: webfonts
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

it seems that https everywhere its blocking the text in a forum that i visit in latest version at least (1.03 and 2.0 dev 2), currently using 2.0 dev 1 because of this issues, i asked the website admin it says that https everywhere its blocking webfonts. Im not using tor, and i will put my addon list

Application: Firefox 7.0.1 (20110928134238)
Operating System: WINNT (x86-msvc)

  • Abduction! 3.0.10
  • Adblock Plus 1.3.10
  • Adblock Plus Pop-up Addon 0.2.9
  • Add-on Compatibility Reporter 0.9.2
  • Back/forward dropmarker 1.0
  • CHM Reader 0.2.3 (Incompatible)
  • ChromEdit Plus 2.9.6
  • ColorZilla 2.6.2
  • Ctrl-Tab 0.21.1
  • Diccionario de Español/España 1.5
  • Diccionario español Argentina 2.5
  • Diccionario español Mexico 1.1.2
  • Dictionary Switcher 1.3.1
  • Download Manager Tweak 0.9.5
  • DownloadHelper 4.9.5
  • Element Hiding Helper for Adblock Plus 1.1.2
  • Extension List Dumper 1.15.2
  • FastestTube 1.6.0
  • FAYT 2.0.5
  • Firefox 4 UI Fixer 1.4.3
  • Firesizer 1.5
  • Flagfox 4.1.7
  • FlashGot 1.3.2
  • gTranslator 1.0.4
  • HTML5 Extension for Windows Media Player Plug-in 1.0 (Incompatible)
  • HTTPS-Everywhere 2.0development.1
  • iReader 1.0.7
  • Less Spam, please 0.7.2
  • LogMeIn, Inc. Remote Access Plugin 1.0.0.664
  • Menu Editor 1.2.7
  • Nightly Tester Tools 3.1.5.1
  • Organize Status Bar 0.6.4 (Incompatible)
  • Personal Menu 5.0.6
  • Readability 1.8
  • RSS Icon In Awesombar 1.4
  • Scrollbar Search Highlighter 1.50
  • SkipScreen 0.6.1.2
  • Status-4-Evar 2011.07.20.21
  • Stratiform 1.2b2 (Incompatible)
  • Stylish 1.2.3
  • Tab Mix Plus 0.3.8.6
  • Tab Scope 1.1.3
  • TACO with Abine 4.31
  • Toolbar Buttons 1.0
  • Twitter Address Bar Search 1
  • United States English Spellchecker 5.0.1
  • UrlbarExt 1.8.1 (Incompatible)
  • User Agent Switcher 0.7.3
  • Vacuum Places Improved 1.2
  • VTzilla 1.1
  • Webmail Ad Blocker 3.4.2
  • Yet Another Smooth Scrolling 3.0.19

website with the issue: http://foros.slot-1.net/

Child Tickets

Attachments (2)

HkCCa.png (240.8 KB) - added by eilegz 8 years ago.
No text using latest https everywhere
ZEPup.png (276.6 KB) - added by eilegz 8 years ago.
what it should appear

Download all attachments as: .zip

Change History (5)

Changed 8 years ago by eilegz

Attachment: HkCCa.png added

No text using latest https everywhere

Changed 8 years ago by eilegz

Attachment: ZEPup.png added

what it should appear

comment:1 Changed 8 years ago by pde

This is another nsIContentPolicy disablement bug (from the fix to #3882). Requests like this one aren't happening in 1.0.3 / 2.0development.1

https://themes.googleusercontent.com/static/fonts/marvel/v1/L2PPfTze83vDMefumW3xvw.woff

GET /static/fonts/marvel/v1/L2PPfTze83vDMefumW3xvw.woff HTTP/1.1
Host: themes.googleusercontent.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1 Iceweasel/7.0.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Connection: keep-alive
Referer: http://foros.slot-1.net/style.php?id=4&lang=en&sid=bcca3908c342e92b21e3adb16845c818
Origin: http://foros.slot-1.net

HTTP/1.1 200 OK
Content-Type: font/woff
Last-Modified: Wed, 03 Aug 2011 19:01:01 GMT
Date: Thu, 06 Oct 2011 17:26:48 GMT
Expires: Fri, 05 Oct 2012 17:26:48 GMT
Access-Control-Allow-Origin: *
X-Content-Type-Options: nosniff
Server: sffe
Content-Length: 20544
X-XSS-Protection: 1; mode=block
Cache-Control: public, max-age=31536000
Age: 1

comment:2 Changed 8 years ago by pde

Priority: normalmajor

comment:3 Changed 8 years ago by pde

Resolution: fixed
Status: newclosed

This bug should be fixed in the 1.1 stable and 2.0development.3 releases.

Note: See TracTickets for help on using tickets.