[Unrelated] NoScript and americanexpress.com
Posted: Tue Jul 28, 2015 8:32 pm
I'm unable to download statements... after individually disabling addons, NS is involved...
Fx 39.0, NS 2.6.9.32, ABP 2.6.10, RP 1.0.beta10, Win8.1
URL: https://online.americanexpress.com/myca ... statements
Click-URL: https://online.americanexpress.com/myca ... tatements#
NS domain Settings: americanexpress.com, ensighten.com, aexp-static.com, liveperson.com all enabled (no domains shown blocked)
Steps: americanexpress.com, [login], click billing statements, click item from dated list for PDF download
Results: adobe icon (as circle) spins 3-5 times, no popup, no new tab, no new browser, no statement! Fx download manager shows no downloads...
Browser console (Net,CSS,JS,Security,Logging) immediately after clicking statement link:
TypeError: gBrowser.contentWindow is undefined overlay.js:40:0
about:blank : Unable to run script because scripts are blocked internally. <unknown>
This site makes use of a SHA-1 Certificate; it's recommended you use certificates with signature algorithms that use hash functions stronger than SHA-1.[Learn More] 46734947
Debugging attempts:
NS: Options: added americanexpress.com to white-list -Joy
NS: Options: XSS: added exception ^https://www.americanexpress.com+$ -Joy
NS: Options: General: changed temporarily allow 'Base 2nd level Domains' (from Full Addresses) -Joy
NS: Options: Whitelist: added https://online.americanexpress.com/myca ... timage/us/ (did NOT appear?) -Joy
NS: Options: "temporarily enable all this page" -Joy
NS: Options: General: Full URL, Whitelist: enable -all previously set, Embeddings: NOT apply to whitelisted, Block untrusted -Joy
NS: Options: ABE: added exception "# AmericanExpress CRLF Site .americanexpress.com CRLF Accept" -Joy
NS: Options: XSS: added exception ^https://online.americanexpress.com+$ -Joy
NS: Options: Trusted: checked 'cascade scripts' -Joy
NS: Options: XSS: added exception ^https://aexp-static.com+$ -Joy
Net results: cannot download statement(s) while NS active.
AXP tech support: use iE or don't use NS
Fx 39.0, NS 2.6.9.32, ABP 2.6.10, RP 1.0.beta10, Win8.1
URL: https://online.americanexpress.com/myca ... statements
Click-URL: https://online.americanexpress.com/myca ... tatements#
NS domain Settings: americanexpress.com, ensighten.com, aexp-static.com, liveperson.com all enabled (no domains shown blocked)
Steps: americanexpress.com, [login], click billing statements, click item from dated list for PDF download
Results: adobe icon (as circle) spins 3-5 times, no popup, no new tab, no new browser, no statement! Fx download manager shows no downloads...
Browser console (Net,CSS,JS,Security,Logging) immediately after clicking statement link:
TypeError: gBrowser.contentWindow is undefined overlay.js:40:0
about:blank : Unable to run script because scripts are blocked internally. <unknown>
This site makes use of a SHA-1 Certificate; it's recommended you use certificates with signature algorithms that use hash functions stronger than SHA-1.[Learn More] 46734947
Debugging attempts:
NS: Options: added americanexpress.com to white-list -Joy
NS: Options: XSS: added exception ^https://www.americanexpress.com+$ -Joy
NS: Options: General: changed temporarily allow 'Base 2nd level Domains' (from Full Addresses) -Joy
NS: Options: Whitelist: added https://online.americanexpress.com/myca ... timage/us/ (did NOT appear?) -Joy
NS: Options: "temporarily enable all this page" -Joy
NS: Options: General: Full URL, Whitelist: enable -all previously set, Embeddings: NOT apply to whitelisted, Block untrusted -Joy
NS: Options: ABE: added exception "# AmericanExpress CRLF Site .americanexpress.com CRLF Accept" -Joy
NS: Options: XSS: added exception ^https://online.americanexpress.com+$ -Joy
NS: Options: Trusted: checked 'cascade scripts' -Joy
NS: Options: XSS: added exception ^https://aexp-static.com+$ -Joy
Net results: cannot download statement(s) while NS active.
AXP tech support: use iE or don't use NS