Full NS addon disable for website login

Ask for help about NoScript, no registration needed to post
jamest

Full NS addon disable for website login

Post by jamest »

Greetings.

This is a report of an issue involving the website http://www.wix.com. For login the website uses a combination of visual overlay / popup but the overlay is the only element that registers even when global scripting is allowed through the NoScript toolbar buttons. I have done a on/off addon check and a full disable of the NS addon appears to solve this issue.
That said I do not know if an advanced option in NS is in conflict with this particular website's script(s) or perhaps there is a inter-addon issue happening on my end. :oops:

Firefox 40.0.3

List of running addons;
Adblock Plus
Copy Plain Text 2
DuckDuckGo Plus
Ghostery
Hard Refresh
LastPass
NoScript
Reddit Enhancement Suite
ReloadEvery
Thumbnail Zoom Plus

Happy to supply logs or other info as needed. :)

I've done a preliminary search for this issue but either I've overlooked a result or I am not knowledge enough about NoScript to recognize the larger issue. Apologies in advance if this has been covered elsewhere.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0
User avatar
therube
Ambassador
Posts: 7979
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: Full NS addon disable for website login

Post by therube »

(A start, & not that I know what it means ...)

Code: Select all

[NoScript] Blocking cross-site Javascript served from http://static.parastorage.com/services/wix-users/2.564.0/login-dialog/locale/messages_en.jsonp with wrong type info application/octet-stream and included by http://www.wix.com/

Code: Select all

[NoScript HTTPS] AUTOMATIC SECURE on https://sslusers.wix.com: userType=ANONYMOUS; domain=.wix.com; path=/; Secure

Code: Select all

[NoScript HTTPS] AUTOMATIC SECURE on https://apis.google.com: NID=71=KdfkjefkWvM-EVER5df-N8V4rJ5eYDC6xYCpMANk5uZonelhOmosKBtodpns0fZsOP08RYHk15Ycs4_7w6xW-HxFrMOv6tmfJJGgUEKreiQ9oGJb-XqJJvouXcYGjVEd; domain=.google.com; path=/; HttpOnly; Secure
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 5.1; rv:38.0) Gecko/20100101 SeaMonkey/2.35
barbaz
Senior Member
Posts: 11142
Joined: Sat Aug 03, 2013 5:45 pm

Re: Full NS addon disable for website login

Post by barbaz »

jamest wrote:perhaps there is a inter-addon issue happening on my end
Have you tested this by disabling all addons other than NS and checking it in that configuration?

If so, it's probably the first message posted by therube, contact the relevant webmasters to get this fixed. It looks to NoScript like a binary file is being attempted to run as JavaScript, either the MIME type needs to be fixed or the file copied & hosted elsewhere (& served with the correct MIME type).
*Always* check the changelogs BEFORE updating that important software!
-
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: Full NS addon disable for website login

Post by Thrawn »

It is possible to add an exception to the cross-site inclusion filter, noscript.inclusionTypeChecking.exceptions
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.

True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:40.0) Gecko/20100101 Firefox/40.0
xtct

Re: Full NS addon disable for website login

Post by xtct »

XSS exception has no influence on this, and also turning off ABE. The only thing that "works" so far is to disable noscript and restart firefox
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:38.0) Gecko/20100101 Firefox/38.0
barbaz
Senior Member
Posts: 11142
Joined: Sat Aug 03, 2013 5:45 pm

Re: Full NS addon disable for website login

Post by barbaz »

xtct wrote:XSS exception has no influence on this, and also turning off ABE.
Yes, bcause neither is involved here, it's most likely the cross-site inclusion MIME type checker. Please see above
*Always* check the changelogs BEFORE updating that important software!
-
Post Reply