[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-bugs] #16620 [Tor Browser]: Transform window.name handling into Firefox patch



#16620: Transform window.name handling into Firefox patch
-------------------------------------------------+-------------------------
 Reporter:  mikeperry                            |          Owner:  mcs
     Type:  defect                               |         Status:
 Priority:  Medium                               |  needs_review
Component:  Tor Browser                          |      Milestone:
 Severity:  Normal                               |        Version:
 Keywords:  tbb-torbutton-conversion,            |     Resolution:
  TorBrowserTeam201510R                          |  Actual Points:
Parent ID:                                       |         Points:
  Sponsor:  SponsorU                             |
-------------------------------------------------+-------------------------

Comment (by gk):

 Could you try testing with
 http://www.thomasfrank.se/sessvarsTestPage1.html? I am currently
 recompiling my build to be absolutely sure I tested your patches but it
 seems your patch does not handle this testcase (see #3414 for context).

 There seem to be in fact two issues:

 1) If I understand this correctly then caching might bypass the
 protections in your patch.
 2) But even if I disable caching and disable sending the Referer header
 your code behaves differently than the one in 5.0.3.

 (I think I made sure I used a Torbutton version with your Torbutton patch
 applied to, too).

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/16620#comment:14>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs