-
Notifications
You must be signed in to change notification settings - Fork 17
Some scripts run when disabled #56
Comments
That's because uMatrix blocks javascripts by setting a CSP policy for javascript execution and doesn't disable them entirely, by-design behavior. CSP policy can only be set for webpages, not local html files. |
@gorhill when |
I wasn't clear here. The issue is valid for pages on web servers. |
which do you mean ? |
Duplicate of gorhill/uMatrix#589 See gorhill's reply - gorhill/uMatrix#589 (comment) |
So why not provide an actual URL -- as asked -- to such web page?
|
After more testing I found that I can't reproduce the bug on a clean profile (maybe I didn't realize that global settings can't be set using the GUI with the current beta version). The issue was a result of CanvasBlocker add-on installed alongside uMatrix. @gorhill You may want to warn people about the incompatibility. |
The issue is a Firefox bug which is broader than just with CanvasBlocker specifically. See https://bugzilla.mozilla.org/show_bug.cgi?id=1477696. |
CanvasBlocker uses CSP only for blocking data URIs. CanvasBlocker settings
|
Prerequisites
Description
Scripts can run on Firefox using onerror attributes of html tags, even when scripts are disabled.
A specific URL where the issue occurs
No URL - local test
Steps to Reproduce
Supporting evidence
No evidence due to privacy concerns
Your environment
The text was updated successfully, but these errors were encountered: