Page 1 of 1

Feature Request: allow *.domain.tld inside one url

Posted: Mon Dec 18, 2017 8:43 am
by SpoonOfDoom
I have a feature request: I'd like to be able to allow all subdomains of a certain domain if they're loaded by a certain site. To make clear what I mean, my use case is the following:

I use the AWS web console quite a bit. That site loads some of its scripts from cloudfront, which apparently uses a procedurally generated url, e.g. d1idiovbex4hy4.cloudfront.net.
My problem is, every few days/weeks these cloudfront urls seem to be regenerated, and the page content stays blank. I need to allow these new urls by hand, and my whitelist slowly fills up with random cloudfront urls. But I don't want to just generally allow everything from cloudfront, because that might also be used by less trustworthy sites.
What I'd like to be able to do is: allow *.cloudfront.net if I'm on console.aws.amazon.com, but not automatically on other domains.
I'm not sure how the old NoScript versions handled this, but I'm pretty sure I didn't need to deal with this back then, once I had allowed everything for console.aws.amazon.com.

Re: Feature Request: allow *.domain.tld inside one url

Posted: Mon Dec 18, 2017 11:41 am
by Tomatix
I think your suggestion belongs here: https://forums.informaction.com/viewtop ... =7&t=24023

Re: Feature Request: allow *.domain.tld inside one url

Posted: Mon Dec 18, 2017 4:02 pm
by barbaz
SpoonOfDoom wrote:What I'd like to be able to do is: allow *.cloudfront.net if I'm on console.aws.amazon.com, but not automatically on other domains.
So you are asking two things -

1) Bring back ability to allow entire TLDs (see the thread Tomatix linked)

2) Per-site permissions (already planned)
SpoonOfDoom wrote:I'm not sure how the old NoScript versions handled this, but I'm pretty sure I didn't need to deal with this back then, once I had allowed everything for console.aws.amazon.com.
Old NoScript versions were able to allow *.cloudfront.net, and per-site permissions were possible using ABE.