Page 1 of 1

10: Bookmarklets Don't Work unless Site is Allowed

Posted: Tue Nov 28, 2017 6:30 am
by therube
Bookmarklets Don't Work unless Site is Allowed

Code: Select all

javascript:alert("Hello, World!");
http://forums.mozillazine.org/viewtopic ... &t=3035967


(Who knows, maybe this lil' 'ol bug is involved, Bug 866522 Bookmarklets affected by CSP?)

Re: 10: Bookmarklets Don't Work unless Site is Allowed

Posted: Tue Nov 28, 2017 8:26 am
by oldmoz
Confirmed in a few linux systems.
It looks like mozco's dropped the ball on this.....again.

The W3 working draft spec on CSP wrt extensions is clear:]Leave them the heck alone. Extensions are for giving the user control over a page. CSP is part of defence in depth, not the monolithic firewall it's being wielded as by mozco.

The noise in bugzilla over CSP and extensions will overwhelm the project - if it hasn't already.

Re: 10: Bookmarklets Don't Work unless Site is Allowed

Posted: Tue Jan 09, 2018 1:37 am
by therube

Re: 10: Bookmarklets Don't Work unless Site is Allowed

Posted: Thu Jul 26, 2018 6:09 pm
by therube

Re: 10: Bookmarklets Don't Work unless Site is Allowed

Posted: Thu Jul 26, 2018 10:18 pm
by Giorgio Maone
Partially, arguably for the easiest part.
therube wrote: What is a "subresources" ?
Anything that gets loaded by the page, e.g. 3rd party scripts or frames.