Page 1 of 1

NOOB Q: blog comments, clickjacking & NS

Posted: Wed May 12, 2010 7:36 pm
by John
Newbie question: When accessing the comment manager "disqus" to enter a comment on a popular blog site and I start to type, NS sometimes pops up a "Potential Clickjacking / UI Redressing Attempt!" warning (with almost unintelligible deep jargon and options), sometimes not. What am I to make of that? Obviously, it needs my keystroke input to get my comment, but is NS seeing something beyond that and how am I to know? Thanks in advance.

Re: NOOB Q: blog comments, clickjacking & NS

Posted: Wed May 12, 2010 8:37 pm
by Giorgio Maone
NoScript has a specific ClearClick exception for Disqus.
Maybe they recently changed something in your system which doesn't match this exception anymore.
Could you please send a report from the ClearClick dialog and tell me the assigned ID?

Re: NOOB Q: blog comments, clickjacking & NS

Posted: Thu May 13, 2010 11:23 am
by John
[quote= ...send a report from the ClearClick dialog and tell me the assigned ID?[/quote]

Report sent - Report ID = 897523 --- apologies, I forgot to mention that I was working through an anonymzer service and through their cascade of servers - but, I've been doing that for some time and this has never been a problem before so I suspect something changed on the Disqus side.

Re: NOOB Q: blog comments, clickjacking & NS

Posted: Sun May 16, 2010 8:37 am
by Giorgio Maone
Thanks.

I couldn't reproduce this ClearClick warning in anyway, trying to comment on the blog referenced by your report, but anyway this should be worked around by adding

Code: Select all

*.disqus.com/*/reply.html?*
to your noscript.clearClick.subexceptions about:config preference.

Re: NOOB Q: blog comments, clickjacking & NS

Posted: Fri May 28, 2010 12:27 pm
by John
G. - Thanks much for the manual fix and change in the recent update to NS. Works fine now. - J.