Hello,
The following, really annoying behavior, is shown by NoScript (at least here):
1. On a fresh session, go to the site https://testsp2.aai.dfn.de/
2. Mark dfn.de as trusted (trust me, they can be trusted ...)
3. Choose one of the "Shibboleth-geschützte Seiten"
4. On the wayf-Server, choose "DFN Test-IdP 2.x"
5. On the following site, enter staffuser/staffuser as username/password
After hitting the login button, Firefox hangs and a message box appears reporting the non-responding script.
This beavior is reproducible on different machines, also on fresh setups.
A second issue that appears after fiddling with this first problem, is the false positive XSS-alarm, if I trust the SP-site, but not the IdP.
Regards
skl
RequestWatchdog.js hangs (trusted -> trusted)
RequestWatchdog.js hangs (trusted -> trusted)
Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.1.2) Gecko/20090803 Ubuntu/9.04 (jaunty) Shiretoko/3.5.2
- Giorgio Maone
- Site Admin
- Posts: 9524
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: RequestWatchdog.js hangs (trusted -> trusted)
For the "unresponsive issue", please check latest development build 1.9.8.89.
Regarding the XSS warning, could you post here the exact message you get logged as a [NoScript XSS] line in Tools|Error Console?
Regarding the XSS warning, could you post here the exact message you get logged as a [NoScript XSS] line in Tools|Error Console?
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729)
Re: RequestWatchdog.js hangs (trusted -> trusted)
Hello,
thank you for this immediate response, and much better, this immediate solution.
To my second problem: I don't know if this behavior is intended, but using the scenario as above, but now only trusting the site https://testsp2.aai.dfn.de I get the following error (in german):
Regards
skl
thank you for this immediate response, and much better, this immediate solution.
To my second problem: I don't know if this behavior is intended, but using the scenario as above, but now only trusting the site https://testsp2.aai.dfn.de I get the following error (in german):
If I don't trust the SP, either, everything works fine (no XSS-warning). As far as I understand it, NoScript wants to block the injection of js-Code, but the base64-encoded string only contains the SAML-response.[NoScript XSS] Ein verdächtiger Upload zu [https://testsp2.aai.dfn.de/Shibboleth.sso/SAML2/POST] von [https://testidp2.aai.dfn.de/idp/Authn/UserPassword] wurde bereinigt und in eine GET-Anfrage (nur Download) umgewandelt.
Regards
skl
Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.1.2) Gecko/20090803 Ubuntu/9.04 (jaunty) Shiretoko/3.5.2
- Giorgio Maone
- Site Admin
- Posts: 9524
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: RequestWatchdog.js hangs (trusted -> trusted)
Do you mean that it happens only if the destination is trusted but the origin is not?
Then it's by design: all the POST requests from untrusted to trusted are blocked, no matter the payload, as an additional anti-CSRF countermeasure provided by the XSS filter.
Then it's by design: all the POST requests from untrusted to trusted are blocked, no matter the payload, as an additional anti-CSRF countermeasure provided by the XSS filter.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729)