Page 2 of 2

Re: [RESOLVED] Mendeley Importer and NoScript

Posted: Thu Aug 27, 2015 7:22 pm
by ace28
Thank you barbaz.

I trust that Mendeley is save enough to add an XSS exeption for it.

Could you please tell me what to write? I could click on 'unsafe reloading' every time (Idk if it is like this in the english version, I just translated it from the german edition). But it would be much more convenient to have an exeption.

Re: [RESOLVED] Mendeley Importer and NoScript

Posted: Thu Aug 27, 2015 8:27 pm
by barbaz
This should do:

Code: Select all

^https://www\.mendeley\.com/import/
NoScript Options > Advanced > XSS

Re: [RESOLVED] Mendeley Importer and NoScript

Posted: Thu Aug 27, 2015 10:56 pm
by Thrawn
ace28 wrote:I trust that Mendeley is save enough to add an XSS exeption for it.
I'm not sure what you're basing that on; lots of services, including some far more popular than Mendeley, have XSS holes.

However, depending on what Mendeley actually does, there might not be much sensitive data on that domain to attack?

Re: [RESOLVED] Mendeley Importer and NoScript

Posted: Fri Aug 28, 2015 7:49 am
by ace28
Thank you barbaz. The exception works this way!
Thrawn wrote:depending on what Mendeley actually does, there might not be much sensitive data on that domain to attack?
Exactly. Mendeley is only saving references and scholarly PDF files. I use it to save my searches in google scholar and later it helps me to cite, applying the correct citation style. There is no sensitive data included as far as I know.

Re: [RESOLVED] Mendeley Importer and NoScript

Posted: Fri Aug 28, 2015 2:40 pm
by barbaz
You're welcome.

BTW, would you like your guest posts in this thread put under your account?

Re: [RESOLVED] Mendeley Importer and NoScript

Posted: Fri Aug 28, 2015 9:33 pm
by ace28
Sure why not. I made this account in order to be able to edit my posts if I made a mistake again ^^' Maybe I can contribute another time in the future.

Re: [RESOLVED] Mendeley Importer and NoScript

Posted: Fri Aug 28, 2015 9:49 pm
by barbaz
Done.