summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAge
...
* Add date to changelog; add bug # for 4.0.1 issue.Mike Perry2011-05-01
|
* Add changelog.Mike Perry2011-04-30
|
* Fix compatability issues ONCE AND FOR ALL!11Mike Perry2011-04-30
|
* Update torbutton translations.Mike Perry2011-04-30
|
* Move JS hooks to new JS1.8.5 hooking support.Mike Perry2011-04-16
| | | | | The new JS1.8.5 hooking method appear more stable than the old ways, but they're not perfect...
* Bug 2838: Make Cookie Protections always available.Mike Perry2011-04-15
| | | | Also fix a bug referencing an old component name. It seems to work now.
* Bug 2832: Update spoofed useragent.Mike Perry2011-04-15
| | | | | | This will make YouTube work for FF4 users if they opt-in to the HTML5 trial. We're not going to set the opt-in cookie for them just yet, on the assumption that there's a good chance the trial mode will become automatic soon.
* Update compiled html for design doc.Mike Perry2011-04-10
|
* Update date of design doc.Mike Perry2011-04-10
|
* Update Firefox Bug list.Mike Perry2011-04-10
| | | | | The changes reflect the planned move away from the Toggle Model in favor of Tor Browser Bundle.
* Add some info on highres timers to audit doc.Mike Perry2011-04-10
|
* Forgot to update the date...Mike Perry2011-04-04
|
* Update compiled HTML.Mike Perry2011-04-04
|
* Alter order of Security requirements.Mike Perry2011-04-04
| | | | | In the TBB use case, state separation is slightly more important than network isolation.
* Update the FF4 audit.Mike Perry2011-04-04
| | | | Reorganize issues by their vulnerability type.
* Clear out old Firefox bugs.Mike Perry2011-04-04
| | | | Also fix a couple typos found by arma.
* Update compiled html.Mike Perry2011-04-04
|
* speel Chekc.Mike Perry2011-04-04
|
* Update options that have changed.Mike Perry2011-04-04
|
* Update option documentation.Mike Perry2011-04-03
|
* Reorganize options into their tab groups.Mike Perry2011-04-03
|
* Reorganize, document observers, and fix gitweb urls.Mike Perry2011-04-03
| | | | I probably should have broken these into separate commits. Too late now.
* Bug #2777: Clear OCSP cache on toggle.Mike Perry2011-04-01
| | | | We do this by toggling the pref.
* Update compiled html.Mike Perry2011-03-25
|
* Add an item for TLS issues and APIs.Mike Perry2011-03-25
| | | | We don't have Bugzilla entries for this yet, but it should be listed.
* Update compiled xml.Mike Perry2011-03-25
|
* Update Firefox bugs.Mike Perry2011-03-25
|
* Merge remote branch 'origin/master'Mike Perry2011-03-21
|\
| * Fix locale paths.Mike Perry2011-03-21
| |
| * Add some validation scripts.Mike Perry2011-03-21
| |
| * Add two new helper scripts.Mike Perry2011-03-21
| |
| * Update po directory in mkmoz.sh.Mike Perry2011-03-21
| |
| * Update locales for torbutton-alpha from transifex.Mike Perry2011-03-21
| |
* | And I still can't get the year right.Mike Perry2011-03-21
|/
* Add a changelog and bump version.Mike Perry2011-03-20
|
* Remove an ancient fallback for the Cookie api for FF2.0.Mike Perry2011-03-20
| | | | | FF2.0 is no longer supported, and this cuts a lot of exception noise out of the javascript debugger.
* Bug 1624: Use nsIDOMCrypto::logout() if available.Mike Perry2011-03-12
| | | | This is the new official way of clearing SSL Session IDs and other TLS state.
* Fix bug #1999: Disable tor urls by defaultMike Perry2011-03-01
| | | | | | | Fixing these will be too problematic for 1.4.x. We'll block on this bug forever otherwise. We throw an unknown protocol exception if this pref is set to prevent fingerprinting with this technique: http://pseudo-flaw.net/tor/torbutton/scan-protocol-handlers.html
* Bug #1968: Reset window.name in the content window on toggleMike Perry2011-02-27
|
* Add plumbing that might've helped #1968, except it didn't.Mike Perry2011-02-27
| | | | Might end up useful in the future though.
* Bug #2148: Make the ref spoofing more uniform in behaviorMike Perry2011-02-27
| | | | | | | | | | This may not be the final form we want for it to take, see FIXME in the comments. Also fix a potential issue with unescaped .'s in regex match strings. I'm really not sure we can call this ref spoofing protection a real security feature, though, so it's not like this matters a whole bunch. But might as well fix it, too.
* Bug #2359: Fix XHTML DTD errors on FF4Mike Perry2011-02-23
| | | | Allow content sourcing of resource urls with a host of 'gre'.
* Bug #2465: Fix Javascript hooks+exception on FF4.0b11Mike Perry2011-02-23
| | | | | The javascript hooks work again, and we've removed a nasty popup exception on FF4.0b11 too.
* Fix bug #2458: Opt out of Firefox addon usage pings.Mike Perry2011-02-13
| | | | | | Hopefully this does not cause us to opt-out of updates as well. That seems to be a different pref, however: http://kb.mozillazine.org/Updating_extensions#Disabling_update_checks_for_individual_add-ons_-_Advanced_users
* Fix 2377: Limit the Google captcha cookies we copy between domains.Mike Perry2011-02-13
| | | | | I couldn't reproduce the issue with this fix, but reproduction seems random and erratic, so maybe it is not fixed still..
* Fix 2491: Clean up checks for when to jar cookies.Mike Perry2011-02-12
|
* Bug #1110: Fix typos caught by arma.Mike Perry2011-02-09
|
* Fix bug #1110: Provide a popup about English for intl users.Mike Perry2011-02-03
| | | | | We always ask this to intl users, because really it's quite fair for them to choose either option, depending on their use case.
* Bump version to 1.3.2pre.Mike Perry2011-02-03
|
* Bug #2421: Fix a popup-exception in FF4.0b10.Mike Perry2011-02-03
| | | | | This doesn't fix the root issue of our JS hooks being broken, but that has existed since at least FF4.0b8. See #2465 for that issue.