NoScript 2.6.9.30rc4 added wrong item to default whitelist

Bug reports and enhancement requests
Post Reply
DJ-Leith
Senior Member
Posts: 152
Joined: Thu Aug 04, 2011 4:23 pm

NoScript 2.6.9.30rc4 added wrong item to default whitelist

Post by DJ-Leith »

Giorgio, I think a single character typo has crept into 2.6.9.30rc4

I have updated several Profiles, from AMO, to test this.

Recent all builds from noscript.net
https://noscript.net/feed?c=200&t=a

Includes:

NoScript 2.6.9.30rc4
07 July 2015 14:04

+ Added about:pocket-save and about:pocket-signup to the
default whitelist


Expected
about:pocket-save (and about:pocket-signup) added to whitelist.

Actual
about:packet-save WRONG
(and about:pocket-signup - correct) added to whitelist.

Both new items, in the NoScript whitelist, are black (not grey) - so users can remove them.

For all readers information, even with Pocket disabled, the whitelist is updated
(I'm happy with that - if I did want to use Pocket then NoScript would not
throw up an additional hurdle).

DJ-Leith
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:41.0) Gecko/20100101 Firefox/41.0
DJ-Leith
Senior Member
Posts: 152
Joined: Thu Aug 04, 2011 4:23 pm

Re: NoScript 2.6.9.30rc4 added wrong item to default whiteli

Post by DJ-Leith »

What is Pocket?

tl;dr

There used to be an 'external program' / Addon / "Read It Later" that became "Pocket"
https://en.wikipedia.org/wiki/Pocket_%28application%29

In Firefox 38.0.5 (2015-06-02) a lot of this was included as part of the Browser:
internal to Firefox.

https://www.mozilla.org/en-US/firefox/3 ... easenotes/

What is Pocket?
http://forums.mozillazine.org/viewtopic ... &t=2938589
48 posts in that thread.

DJ-Leith
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:41.0) Gecko/20100101 Firefox/41.0
DJ-Leith
Senior Member
Posts: 152
Joined: Thu Aug 04, 2011 4:23 pm

Re: NoScript 2.6.9.30rc4 added wrong item to default whiteli

Post by DJ-Leith »

Background

I maintain more than 30 profiles for several Users.
Some profiles are only used for 'specific sites' e.g. ONLY for web email, ONLY for Bank.
Most profiles are Fx 39.0
I personally browse with Fx 41.0a2 (Developer Edition).

All Profiles have NoScript, RequestPolicy Continued and
Classic Theme Restorer (CTR). Some Profile have other Extensions.

ALL Profiles have 'Pocket off':

Code: Select all

user_pref("browser.pocket.enabled", false);
I personally don't want Pocket (nor do the Users I support).

On 2015-07-07 I updated many Profiles:

A.
NoScript 2.6.9.30rc3 (or older) to NoScript 2.6.9.30rc4

Result:
about:packet-save and about:pocket-signup added to whitelist.

Then (on 2015-07-08),
NoScript 2.6.9.30rc4 to NoScript 2.6.9.30rc5

Result:
about:pocket-save and about:pocket-signup added to whitelist.

B.
NoScript 2.6.9.30rc3 (or older) to NoScript 2.6.9.30rc5

Result:
Only about:pocket-signup added to whitelist.

So,
I can manually remove the about:packet-save that was added by 2.6.9.30rc4
and converted to the correct about:pocket-save by 2.6.9.30rc5.

I can manually remove about:pocket-signup added to whitelist.


Given that Mozilla have 'added Pocket to Firefox' I do think it is
reasonable to add about:pocket-signup and about:pocket-save to the default
whitelist (they are in the noscript.default preference).

I also think it is reasonable to 'update the Profile whitelist'
where noscript.allowWhitelistUpdates is true.

If the noscript.allowWhitelistUpdates is false then it is up to the
User to add the entry manually. You do document the changes in
the feed.

On the other hand, if 'Pocket was an Addon', like e.g. RequestPolicy Continued,
it would be 'up to the Users' to manually add to the NoScript whitelist
(add about:requestpolicy - in this example - to get the RPC working with NoScript).

Giorgio, I don't think you need to try and fix this (the left over whitelist entries).
I am very grateful for all you do for us.
NoScript is the most important Extension that I use.


DJ-Leith
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:41.0) Gecko/20100101 Firefox/41.0
DJ-Leith
Senior Member
Posts: 152
Joined: Thu Aug 04, 2011 4:23 pm

Re: NoScript 2.6.9.30rc4 added wrong item to default whiteli

Post by DJ-Leith »

Giorgio Maone said in another thread:
Giorgio Maone wrote:BTW, in case you're wondering, about:pocket-xyz stuff is treated as a dependency of about:blank as a trick to ensure that it doesn't get added if user has been paranoid enough to remove about:blank from his whitelist.
Two of my Profiles have 'just the grey items', which you can't remove (e.g. about:certerror),
plus ONLY addons.mozilla.org and about:requestpolicy in their NoScript whitelist.

So, NO about:blank

When these Profiles are updated to 2.6.9.30rc5 (from 2.6.9.30rc3)
they did not get the about:pocket-signup added to the whitelist.

Expected, in light of Giorgio's comment (quoted in this post).

DJ-Leith
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:41.0) Gecko/20100101 Firefox/41.0
Post Reply