Repository navigation
uBlock Origin doesn’t honor noscript tags when blocking JS #308
Description
Activity
There is no good solution for this.
uBlock does not disable javascript in the browser, it prevents it from running using a
Content-Security-Policyheader, and in such case it appears the browser does not fall back onnoscripttags. Forcing thenoscripttags to render using some trickery leads to other issues.So there is no good solution. Maybe file an issue with the browser devs to ask them if the
noscripttags can become active whenever the browser can't executescripttags, for whatever reasons, not just just because javascript is disabled in the browser.So those annoying
<noscript><meta http-equiv="refresh" content="0" url=...></noscript>redirects don't function now? I hadn't noticed when that changed, but I'm glad.Reacted by Mike SmithJust for the record, e.g. NoScript honours noscript tags. NoScript also has options whether to allow META redirections inside them or to hide them completely.
Can we maybe use this technique?: http://kb.mozillazine.org/Allowing_only_certain_sites_to_use_JavaScript
That is, if all javascript is disabled for a site, can we set
user_pref("capability.policy.nojs.sites", "http://www.example.com http://www.example.net");
?This probably has to be carefully thought of as uMatrix can both function as a blacklist and as a whitelist, but still, even supporting the simplest most popular scenario would be awesome.
Reacted by ಚಿರಾಗ್ ನಟರಾಜ್I just ran into this when trying to ensure my site was accessible to users who don't have javascript. Do we know how NoScript manages to deal with the
<noscript>tag and can we do something similar?Gecko bug https://bugzilla.mozilla.org/show_bug.cgi?id=1392090 will make this work for "script-src 'none'" once fixed. For cases when some but not all scripts are blocked, the desired behavior of noscript tags is ... unclear at best.
will make this work for
script-src 'none'once fixedOk thanks. Well, a master javascript switch was an alternative solution, however it could not be implemented in Firefox due to
browser.contentSettingsnot being present.Between both solutions, I like the
script-src 'none'far better, because this matches exactly uBO's way of deciding on the fly as to whether something is blocked or not, while this is not possible with the essentially declarativechrome.contentSettingsAPI.A new per-site switch has been added to wholly disable/enable javascript.
noscripttags will be honoured if and only if javascript is wholly disabled through that new per-site switch.- added a commit that references this issue
on Oct 8, 2020 - added a commit that references this issue
on Jul 16, 2026
In advanced mode, when blocking some or all of the JS scripts on a page, the noscript tag following the script tag is never used.
Here is a simple testcase for this issue, the page should display either “Using <script/>” when using JS, or “Using <noscript/>” when blocking it, but it currently displays nothing when using uBlock Origin.
http://linkmauve.fr/files/ublock.xhtml