Skip to content

GitLab

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
Trac
Trac
  • Project overview
    • Project overview
    • Details
    • Activity
  • Issues 246
    • Issues 246
    • List
    • Boards
    • Labels
    • Service Desk
    • Milestones
  • Operations
    • Operations
    • Metrics
    • Incidents
  • Analytics
    • Analytics
    • Value Stream
  • Wiki
    • Wiki
  • Members
    • Members
  • Activity
  • Create a new issue
  • Issue Boards
Collapse sidebar

GitLab is used only for code review, issue tracking and project management. Canonical locations for source code are still https://gitweb.torproject.org/ https://git.torproject.org/ and git-rw.torproject.org.

  • Legacy
  • TracTrac
  • Issues
  • #23216

Closed (moved)
Open
Opened Aug 11, 2017 by Georg Koppen@gk

The `languagechange` event is noticeable on all open tabs

It turns out that there is the languagechange event which is noticeable on all open tabs allowing to correlate activity of a user cross-domain and bypassing our unlinkability requirement.

Now, triggering that one can't be done remotely and is probably not done very often. But still we should find a way to make it much less obvious to third party scripts that a particular user made language related changes and has been on website A, B, and C.

Reported on HackerOne by tomvg.

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
None
Due date
None
Reference: legacy/trac#23216