Page 1 of 1

XSS help needed

Posted: Sat Jun 18, 2016 3:50 pm
by expeditionist
I'd like to trust XSS requests from https://keepa.com to https://www.amazon.co.uk/ but I can't work out what regular expressions to put in the XSS filter box. I tried ^@https?://([^/]+\.)?keepa\.com/ and ^https://([^/]+\.)?amazon\.co.uk/ but it doesn't work.

Be glad of help please?

Also, an easier way to whitelist XSS for certain domains might benefit non-tech users maybe?

Thanks.

Re: XSS help needed

Posted: Sat Jun 18, 2016 4:55 pm
by barbaz
Image Either of those entries would accomplish exactly what you're asking about...

Can you please check the Browser Console (Ctrl-Shift-J) when this XSS issue happens and post here any messages related to NoScript?
(related messages usually start with either "[NoScript" or "[ABE]"; if you don't know what's related, turn off CSS warnings and post everything else you see)