Script execution allowed (from icon shown) but login fails

Bug reports and enhancement requests
Post Reply
MarkR
Posts: 1
Joined: Tue Sep 05, 2017 8:21 am

Script execution allowed (from icon shown) but login fails

Post by MarkR »

When I try to login to Sophos Community via the Sophos ID (Okta) authentication (https://id.sophos.com/) I have to first allow 'sophos.com' and then 'oktacdn.com'. After that, the icon shows no problems however the form will still fail with the message 'We found some errors. Please review the form and make corrections.' (which implies the email and/or password is wrong).

The icon, at this stage, shows no problems (no alert). If I zoom the browser smaller (Ctrl + -) once the icon then refreshes to show a no entry symbol and hence I am then alerted that I need to further allow 'okta.com'. Once I do that I can log in without any error. Note: The NoScript menu always shows the requirement to allow 'okta.com', it's just the icon doesn't alert this is required and hence it initially looks like the username and password are wrong and not that NoScript is blocking without alerting to that fact.

Since the icon does not show accurately until the browser is zoomed smaller, is this accepted as a bug?
Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: Script execution allowed (from icon shown) but login fai

Post by Thrawn »

Hmm. It looks like the page doesn't make any attempt to contact okta.com until you try to log in, and then it never actually reloads. Which would be why the icon doesn't change.

Technically I guess this can be considered a bug. When NoScript blocks the dynamic call to okta.com, it could update the icon. Up to Giorgio.
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.

True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:45.0) Gecko/20100101 Firefox/45.0
Post Reply