[BUG] Temporarily allow top-level sites and untrusted

Bug reports and enhancement requests
Post Reply
Alan Baxter
Ambassador
Posts: 1586
Joined: Fri Mar 20, 2009 4:47 am
Location: Colorado, USA

[BUG] Temporarily allow top-level sites and untrusted

Post by Alan Baxter »

Cannot merely remove another site from the whitelist if Temporarily allow top-level sites is checked. The site is marked untrusted too.

Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
NoScript 1.9.9.14, no other extensions, default theme.

Steps to reproduce:
1) Change the default settings as follows:
  • Temporarily allow top-level sites
  • Full addresses only
  • (under Contextual menu, which is not selected)
  • Base 2nd level Domains
  • Full Domains
  • Full Addresses
2) Load http://social.msdn.microsoft.com/Forums/
3) Click Allow social.microsoft.com
4) Click Forbid social.microsoft.com

Expected result: social.microsoft.com is removed from the whitelist and not marked untrusted.
Actual result: social.microsoft.com is marked untrusted
The expected behavior happens if I uncheck Temporarily allow top-level sites and temporarily allow social.msdn.microsoft.com manually.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
User avatar
therube
Ambassador
Posts: 7969
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: Bug: Temporarily allow top-level sites and untrusted problem

Post by therube »

Maybe it is intended behavior, similar to this:
when you use "Allow scripts globally", whatever you forbid from then on is automatically marked as untrusted and prevented from running.
In other words, you go in "Blacklist Mode". It's like YesScript, but with much more protection features (anti-XSS, anti-Clickjacking, ABE and so on)

http://forums.informaction.com/viewtopi ... 058#p13058
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.6pre) Gecko/20091114 SeaMonkey/2.0.1pre
tuggyne
Posts: 8
Joined: Thu Oct 15, 2009 6:24 am
Location: California
Contact:

Re: [BUG] Temporarily allow top-level sites and untrusted

Post by tuggyne »

I've seen this behavior too, but like therube I'm not sure if it's intended or not. I don't particularly like it, but it does seem like a potentially useful default.
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5 (.NET CLR 3.5.30729)
User avatar
GµårÐïåñ
Lieutenant Colonel
Posts: 3369
Joined: Fri Mar 20, 2009 5:19 am
Location: PST - USA
Contact:

Re: [BUG] Temporarily allow top-level sites and untrusted

Post by GµårÐïåñ »

I believe that it is intended because by having the top level temporary allowed, when you forbid it, it assumes you want it untrusted not just laying out and about. I am sure if its a bug that Giorgio will weigh in but I wouldn't worry about that, I think we discussed it a while back and it was said to be intentional. If I can find the link I will post it.
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
Alan Baxter
Ambassador
Posts: 1586
Joined: Fri Mar 20, 2009 4:47 am
Location: Colorado, USA

Re: [BUG] Temporarily allow top-level sites and untrusted

Post by Alan Baxter »

Thanks for the input, everyone. Unlike Globally Allowed mode, the only reason the site was Allowed is because it was explicitly whitelisted. I still don't see any reason for thinking it's intended behavior. I'm not worried about it in the slightest, but unintended behavior is often related to subtle bugs in other areas too. That's why it's important to bring it to Giorgio's attention.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: [BUG] Temporarily allow top-level sites and untrusted

Post by Giorgio Maone »

It's intended (for the reasons GµårÐïåñ guessed).
Debatable, but not a bug.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5 (.NET CLR 3.5.30729)
Alan Baxter
Ambassador
Posts: 1586
Joined: Fri Mar 20, 2009 4:47 am
Location: Colorado, USA

Re: [BUG] Temporarily allow top-level sites and untrusted

Post by Alan Baxter »

Giorgio Maone wrote:Debatable, but not a bug.
And easily worked around, thanks to the NoScript sticky menu.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
Post Reply