Page 1 of 1
[FIXED 2.9.0.6] 2.9.0.5 broke access to google fonts
Posted: Thu Mar 17, 2016 1:55 pm
by pastic
NoScript (great extension!!) just updated and it broke access to googlefonts for a site I am developing locally. I have been working on it for a week and the font has loaded all the time. Now after working several hours this morning I restarted Firefox and was greeted by the update info page for NoScript. And suddenly the googlefont can't be downloaded anymore. If I disable NoScript the font is downloaded.
Was this an intentional change?
Inspection message:
Code: Select all
Cross-Origin Request Blocked: The Same Origin Policy disallows reading the remote resource at http://fonts.gstatic.com/s/librebaskerville/v4/pR0sBQVcY0JZc_ciXjFsK6Ucnt8gjcHpqyffjHeZWDA.woff2. (Reason: CORS header 'Access-Control-Allow-Origin' missing).
downloadable font: download failed (font-family: "Libre Baskerville" style:normal weight:normal stretch:normal src index:2): bad URI or cross-site access not allowed source: http://fonts.gstatic.com/s/librebaskerville/v4/pR0sBQVcY0JZc_ciXjFsK6Ucnt8gjcHpqyffjHeZWDA.woff2
Re: 2.9.0.5 broke access to google fonts
Posted: Thu Mar 17, 2016 3:42 pm
by OldLodgeSkins
I've just noticed the exact same behavior, also with a Google font... I've been working on that website for a week now and the two Google fonts I'm using in it were working just fine. NoScript says it blocked an XSS attempt.
I'm trying to add an XSS exception but I'm no good with regex...
Re: 2.9.0.5 broke access to google fonts
Posted: Thu Mar 17, 2016 4:22 pm
by pastic
I just disabled NoScript.
I probably wont re-enable it until I am done with the site in question.
Which is sad, because I like to browse the web with NoScript when I am not coding.
I hope the devs will chime on with a word on this issue.
Re: 2.9.0.5 broke access to google fonts
Posted: Thu Mar 17, 2016 4:41 pm
by sonicsix
Same issue here, killed Google fonts. Please re-enable or give us the option to.
Re: 2.9.0.5 broke access to google fonts
Posted: Thu Mar 17, 2016 4:57 pm
by jbob12
Same here, google fonts only load with noscript disabled
Re: 2.9.0.5 broke access to google fonts
Posted: Thu Mar 17, 2016 5:06 pm
by barbaz
Does downgrading NoScript to a version where this was known to work, actually get it back working?
If so, what is the last working rc version?
Old NoScript @
https://addons.mozilla.org/addon/noscript/versions
*or*
https://noscript.net/feed?c=100&t=a
Re: 2.9.0.5 broke access to google fonts
Posted: Thu Mar 17, 2016 5:12 pm
by Final
Same error here. I just updated NoScript today (never had any prior issues with Google Fonts). Both of my websites use custome Google Fonts, however they will not load at all anymore unless I disable NoScript entirely (not something I feel comfortable doing when browsing the internet). Any chance of a hotfix?
Re: 2.9.0.5 broke access to google fonts
Posted: Thu Mar 17, 2016 5:30 pm
by pastic
barbaz wrote:Does downgrading NoScript to a version where this was known to work, actually get it back working?
If so, what is the last working rc version?
Just tried rolling back.
Version 2.9.0.5rc2 is that last one that works.
Version 2.9.0.5rc3 breaks google fonts.
Re: 2.9.0.5 broke access to google fonts
Posted: Thu Mar 17, 2016 5:41 pm
by barbaz
Thank you for reporting your findings. We have a lot of threads here about 2.9.0.5 breaking things...
NoScript 2.9.0.5 breaks Google Fonts
Posted: Fri Mar 18, 2016 12:41 am
by vpoint
build 2.9.0.5 breaks many large sites that use Google Fonts
Browser console shows Firefox bad URI for fonts.gstatic.com even with NoScript XSS turned off
No Google Fonts load
Fix: downgrade to 2.9.0.4 and turn off auto-update.
Re: 2.9.0.5 broke access to google fonts
Posted: Fri Mar 18, 2016 8:37 am
by PPNSteve
Its breaking other Google API calls as well thus breaking my WP post editing and page viewing ability.
[NoScript InjectionChecker] JavaScript Injection in ///u/0/se/0/_/ 1/fastbutton?usegapi=1&size=medium&hl=en&origin=http://www.[website].com&url=http://www.[website].com/?p=31917&gsrc=3p&ic=1&jsh=m;/_/scs/apps-static/_/js/k=oz.gapi.en.W5w9FDjqfRM.O/m=__features__/am=AQ/rt=j/d=1/rs=AGLTcCNDePu8MnLgpAM5USOnhNImDn9cnA#_methods=onPlusOne,_ready,_close,_open,_resizeMe,_renderstart,oncircled,drefresh,erefresh,onload&id=I0_1458288817041&parent=http://www.[website].com&pfname=&rpctoken=20719038
(function anonymous() {
_methods=onPlusOne,_ready,_close,_open,_resizeMe,_renderstart,oncircled,drefresh,erefresh,onload /* COMMENT_TERMINATOR */
DUMMY_EXPR
})
[NoScript XSS] Sanitized suspicious request. Original URL [https://apis.google.com/u/0/se/0/_/+1/fastbutton?usegapi=1&size=medium&hl=en&origin=http%3A%2F%2Fwww.[website].com&url=http%3A%2F%2Fwww.[website].com%2F%3Fp%3D31917&gsrc=3p&ic=1&jsh=m%3B%2F_%2Fscs%2Fapps-static%2F_%2Fjs%2Fk%3Doz.gapi.en.W5w9FDjqfRM.O%2Fm%3D__features__%2Fam%3DAQ%2Frt%3Dj%2Fd%3D1%2Frs%3DAGLTcCNDePu8MnLgpAM5USOnhNImDn9cnA#_methods=onPlusOne%2C_ready%2C_close%2C_open%2C_resizeMe%2C_renderstart%2Concircled%2Cdrefresh%2Cerefresh%2Conload&id=I0_1458288817041&parent=http%3A%2F%2Fwww.[website].com&pfname=&rpctoken=20719038] requested from [http://www.[website].com/?p=31917&pagefrog_preview=fbia&preview=true]. Sanitized URL: [https://apis.google.com/#1731787890023957460].
Re: 2.9.0.5 broke access to google fonts
Posted: Fri Mar 18, 2016 11:04 am
by Giorgio Maone
Please check
latest development build 2.9.0.6rc1, thanks.
Re: 2.9.0.5 broke access to google fonts
Posted: Fri Mar 18, 2016 11:44 am
by JPL
For my websites at least, the Google fonts problem in 2.9.0.5 has been fixed in 2.9.0.6rc1.
Many thanks for prompt response.
JPL
Re: 2.9.0.5 broke access to google fonts
Posted: Fri Mar 18, 2016 3:18 pm
by vpoint
fixed in 2.9.0.6 for me ( Firefox ESR 38.7.1)
Re: 2.9.0.5 broke access to google fonts
Posted: Fri Mar 18, 2016 7:14 pm
by pastic
2.9.0.6 works here as well.
Ottimo!
Thanks for the quick fix!