XSS warning is too intrusive.What about denying it by defaut

Bug reports and enhancement requests
Post Reply
sylwester
Posts: 2
Joined: Mon Nov 27, 2017 9:14 am

XSS warning is too intrusive.What about denying it by defaut

Post by sylwester »

I switched to FF57 and I'm getting XSS-warnings all the time!

I'm very used to NoScript so when things on a new site doesn't work it's because I need to look at the icon and behold there are scripts that NoScript hasn't allowed and I might allow some of them temporary and make it permanent for next session.
Very often I get a large modal saying it has detected a potential XSS attack. I think this is very intrusive since I would like NoScript to behave like I don't want that and rather have a indication in the icon that something was blocked. The modal that appears when you press the icon could have the XSS listed alongside scripts and you could allow XSS on this side from there and reload.

This choice is the default but one must always see the modal and press OK. Eg everytime I load the page https://www.nissan.no/biler/nye-biler/leaf-2018.html I get the XSS warning for facebook.com. I have no option to "Always deny requests from nissan.no to facebook.com" which should be the default!
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:57.0) Gecko/20100101 Firefox/57.0
Post Reply