Page 1 of 1

Whitelisted @font-face provider, fonts still blocked

Posted: Mon May 13, 2013 4:15 pm
by a1tsal
Let's say that I trust that Typekit will not serve malware fonts.

I have whitelisted typekit.com and typekit.net (The .net site seems to be their CDN or something.)

I go to a site that is new to me (example: http://schoolguide.co.uk/) and untrusted by default.

NoScript blocks loading the typekit fonts that are @font-face included by schoolguide.co.uk. (Turning off "Forbid @font-face" in the NoScript Options makes them appear.)

This seems wrong to me.

Is this the intended behavior? Or a bug? Or do I need to do something extra to make it work as I expect?

Thanks!

Re: Whitelisted @font-face provider, fonts still blocked

Posted: Tue May 14, 2013 2:24 am
by Thrawn
Under Options - Embeddings, have you enabled 'Apply these restrictions to whitelisted sites too'? If so, then this is expected behavior.

Also, are these fonts coming from typekit.net, or are they coming from schoolguide.co.uk? What does the Blocked Objects submenu show?

Re: Whitelisted @font-face provider, fonts still blocked

Posted: Tue May 14, 2013 4:46 am
by a1tsal
My mistake—the site uses the Typekit Javascript, but it serves the fonts itself. (I don't know why—this is not the usual Typekit practice.)

No bug here, PEBCAT only :-)

Thanks & sorry!

Re: Whitelisted @font-face provider, fonts still blocked

Posted: Tue May 14, 2013 6:17 am
by Thrawn
No worries :).

Btw, if you don't whitelist the main site, then JavaScript will be blocked on all third-party sites, regardless of whether you whitelisted them. Blocked Objects are different, but it's something to keep in mind.