Skip to content

uBlock Origin doesn’t honor noscript tags when blocking JS #308

Description

@linkmauve

In advanced mode, when blocking some or all of the JS scripts on a page, the noscript tag following the script tag is never used.

Here is a simple testcase for this issue, the page should display either “Using <script/>” when using JS, or “Using <noscript/>” when blocking it, but it currently displays nothing when using uBlock Origin.

http://linkmauve.fr/files/ublock.xhtml

Activity

  1. gorhill commented on Jun 7, 2015

    @gorhill
    Owner

    There is no good solution for this.

    uBlock does not disable javascript in the browser, it prevents it from running using a Content-Security-Policy header, and in such case it appears the browser does not fall back on noscript tags. Forcing the noscript tags to render using some trickery leads to other issues.

    So there is no good solution. Maybe file an issue with the browser devs to ask them if the noscript tags can become active whenever the browser can't execute script tags, for whatever reasons, not just just because javascript is disabled in the browser.

  2. luxoflux commented on Jun 7, 2015

    @luxoflux

    So those annoying <noscript><meta http-equiv="refresh" content="0" url=...></noscript> redirects don't function now? I hadn't noticed when that changed, but I'm glad.

  3. gitarra commented on Jun 7, 2015

    @gitarra

    Just for the record, e.g. NoScript honours noscript tags. NoScript also has options whether to allow META redirections inside them or to hide them completely.

  4. vn971 commented on Jun 21, 2017

    @vn971

    Can we maybe use this technique?: http://kb.mozillazine.org/Allowing_only_certain_sites_to_use_JavaScript

    That is, if all javascript is disabled for a site, can we set
    user_pref("capability.policy.nojs.sites", "http://www.example.com http://www.example.net");
    ?

    This probably has to be carefully thought of as uMatrix can both function as a blacklist and as a whitelist, but still, even supporting the simplest most popular scenario would be awesome.

  5. chiraag-nataraj commented on Aug 5, 2017

    @chiraag-nataraj

    I just ran into this when trying to ensure my site was accessible to users who don't have javascript. Do we know how NoScript manages to deal with the <noscript> tag and can we do something similar?

  6. bzbarsky commented on Nov 15, 2017

    @bzbarsky

    Gecko bug https://bugzilla.mozilla.org/show_bug.cgi?id=1392090 will make this work for "script-src 'none'" once fixed. For cases when some but not all scripts are blocked, the desired behavior of noscript tags is ... unclear at best.

  7. gorhill commented on Nov 15, 2017

    @gorhill
    Owner

    will make this work for script-src 'none' once fixed

    Ok thanks. Well, a master javascript switch was an alternative solution, however it could not be implemented in Firefox due to browser.contentSettings not being present.

    Between both solutions, I like the script-src 'none' far better, because this matches exactly uBO's way of deciding on the fly as to whether something is blocked or not, while this is not possible with the essentially declarative chrome.contentSettings API.

  8. gorhill commented on Aug 31, 2018

    @gorhill
    Owner

    A new per-site switch has been added to wholly disable/enable javascript. noscript tags will be honoured if and only if javascript is wholly disabled through that new per-site switch.

  9. added a commit that references this issue on Oct 8, 2020
    5b73cea
  10. added a commit that references this issue on Jul 16, 2026
    14e9fdc
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions