11.4.32rc1 breaks meta refresh on script-disabled pages

Ask for help about NoScript, no registration needed to post
User avatar
therube
Ambassador
Posts: 7969
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

11.4.32rc1 breaks meta refresh on script-disabled pages

Post by therube »

Might 11.4.32rc1 be breaking things in a Private Window? [or more?]
FF 115 ESR

google.com is set to Default (in NoScript, so, disabled)
gstatic.com is left at its default, Trusted

Today, having issues with Google Search not showing search results.
Pretty sure ?? that happened in both regular & Private windows.
Yes, definitely, both regular & Private windows - at times.


The search would proceed (depending on how you went about it), & the URL displayed as expected, but the page was "blank".


SeaMonkey (& NoScript) continued to work.
Caused me to think it was a useragent issue.
Dicked around with UA extensions in FF (what a PITA) to no avail.

Then I'm thinking, screw Google, I'll use duckduckgo.

So I type in, https://duckduckgo.com/ (which, by default, is not allowed in NoScript), & the page comes up - blank.
Do the same in SeaMonkey, & the page automatically rolls over to https://html.duckduckgo.com/html.

Like, huh?
So both Google & DDG searches break on the same day?


Disable NoScript
Set, javascript.enabled;false
- so disabling JavaScript - globally in the browser, not through NoScript


Type in https://duckduckgo.com/ & it (automatically) rolls over to, https://html.duckduckgo.com/html (which displays & on where a search searches, as expected).

At first, I thought it was a Google Search issue, but now I'm not so sure?
mozillazine, Is Google Search Broken in FF 115 - when JS is disabled?


Drop back down to noscript-11.4.30rc2.xpi (or noscript-11.4.31rc3.xpi)
type in, https://duckduckgo.com/
& it automatically rolls over to, https://html.duckduckgo.com/html ...
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:91.0) Gecko/20100101 Firefox/91.0 SeaMonkey/2.53.20
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Might 11.4.32rc1 be breaking things in a Private Window?

Post by Giorgio Maone »

Hum, yes, it seems an unfortunate side effect of
[nscl] Use the sandbox directive in addition to script-src for CSP-based script blocking
per https://bugzilla.mozilla.org/show_bug.cgi?id=1156059 :(

I made this change to fix https://gitlab.torproject.org/tpo/appli ... sues/42805, and possibly other bugs due mismatch between NoScript's script blocking implementation and W3C's definition of "disabled scripts", but clearly this is in itself a source of surprises and must be considered more carefully before general deployment.

Thanks for reporting.
Mozilla/5.0 (X11; Linux x86_64; rv:129.0) Gecko/20100101 Firefox/129.0
barbaz
Senior Member
Posts: 11064
Joined: Sat Aug 03, 2013 5:45 pm

Re: 11.4.32rc1 breaks meta refresh on script-disabled pages

Post by barbaz »

It's not just meta refresh. On https://www.hirensbootcd.org/old-versions/, with NoScript 11.4.32rc1, left-clicking the link to archive.hirensbootcd.org doesn't work, nothing happens when trying.
*Always* check the changelogs BEFORE updating that important software!
Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0
Post Reply