I notice the XSS warning when opening multiple pages from bookmarks, but when opened individually, it's okay. This is reflected in yet someone?
FF 57.0.4, NoScript 10.1.6.3 (same as 10.1.6.2)
"GOOGLE translation" English is not my native language
Addition: Not all pages, just some.
XSS warnings when bulk opening bookmarks
XSS warnings when bulk opening bookmarks
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0
- Giorgio Maone
- Site Admin
- Posts: 9454
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: XSS warnings when bulk opening bookmarks
Could you copy-paste the actual content of the XSS warning(s) you get?
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0
Re: XSS warnings when bulk opening bookmarks
I'm not IT skillful.
Examples of window preview and more specific features:
a1)Open FF, clean default page.
a2)Open multiple pages from bookmark folder - XSS alert window opens.
but
b1)Open FF, clean default page.
b2)Open a random one page
b3)Open multiple pages from the bookmark folder - XSS okay, no alert.
Is it possible to replicate?
Examples of window preview and more specific features:
a1)Open FF, clean default page.
a2)Open multiple pages from bookmark folder - XSS alert window opens.
but
b1)Open FF, clean default page.
b2)Open a random one page
b3)Open multiple pages from the bookmark folder - XSS okay, no alert.
Is it possible to replicate?
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0
- Giorgio Maone
- Site Admin
- Posts: 9454
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: XSS warnings when bulk opening bookmarks
More than enough to help herehalfapple wrote:I'm not IT skillful.
This looks an initialization problem: the XSS filter, which is instantiated lazily on first page load not to slow down browser startup, seems not to be fully initialized and chokes at the multiple loads.
Investigating a fix, thanks.
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0
Re: XSS warnings when bulk opening bookmarks
I got the issue too. A few remarks:
1. it first showed with the December 31 update if I remember correctly (Firefox beta channel).
2. I was getting an issue for pretty much all the sites being opened (I didn't count to see if it was all of them or not), which I temporarily accepted (3rd choice) for the first couple of days.
3. Eventually I grew tired of it so I accepted all of them permanently (4th choice). And since, I'm only getting the warning occasionally and only for the first tab.
3) makes my think it is (was?) not just a lazy initialization or at least, that there are several places that are affected.
Before doing 3, I tried waiting a bit (~30s) after opening firefox before loading my bookmarks and that didn't work. I think I did one try to loading the bookmarks after opening a few tab first and that then I didn't get the warnings.
1. it first showed with the December 31 update if I remember correctly (Firefox beta channel).
2. I was getting an issue for pretty much all the sites being opened (I didn't count to see if it was all of them or not), which I temporarily accepted (3rd choice) for the first couple of days.
3. Eventually I grew tired of it so I accepted all of them permanently (4th choice). And since, I'm only getting the warning occasionally and only for the first tab.
3) makes my think it is (was?) not just a lazy initialization or at least, that there are several places that are affected.
Before doing 3, I tried waiting a bit (~30s) after opening firefox before loading my bookmarks and that didn't work. I think I did one try to loading the bookmarks after opening a few tab first and that then I didn't get the warnings.
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:58.0) Gecko/20100101 Firefox/58.0