Skip to main content


!Friendica Support
Ein anderer Friendica-User hat in irgend einem Thread von Problemen von Friendica mit No-Script berichtet...

Da erinnerte ich mich, dass ich vor laaaaanger Zeit Noscript deaktiviert hatte. DESWEGEN...
... und aktivierte es wieder.

Und tatsΓ€chlich:

Das ist sehr unschΓΆn.
Kann man das nicht anders lΓΆsen? Kann ja nicht sein, dass blockierte Scripts anderer Seiten die Darstellung von Friendica in ihren Grundfesten so derartig erschΓΌttert...

in reply to jakob πŸ‡¦πŸ‡Ή βœ…

@jakob πŸ‡¦πŸ‡Ή βœ…

Yep. Das ist echt sehr unschΓΆn.
WΓ€re echt gut, wenn ein aktiviertes Noscript Friendica nicht so beeinflussen und damit ubedienbar machen wΓΌrde.
Wobei das irgendwie nur beim mobilen Browser (hier Firefox) passiert.
Am Desktop ist bei mir auch Noscript aktiviert, und da passiert das nicht 🀷

in reply to alfredb

@alfredb @jakob πŸ‡¦πŸ‡Ή βœ…

Die Frage ist, was nun das kleinere Übel ist:
Friendica in Chrome nutzen, den ich sonst aus GrΓΌnden meide und deshalb da auch kein Noscript installiert ist, oder im Firefox NoScript deaktivieren, aber zumindest eben Firefox mit uBlock Origin zu nutzen.

Ich fΓΌr meinen Teil denke, lieber Firefox.

in reply to Crazy-to-Bike

@Crazy-to-Bike @alfredb

Ich hab auch ublock aktiv und noscript deaktiviert... im firefox.

Chrome(ium) nutze ich wirklich nur alle paar heiligen Zeiten, wenn ich einen Gegenchrck fΓΌr FunktionalitΓ€t benΓΆtige.

contrachrome.com/comic/279/

in reply to jakob πŸ‡¦πŸ‡Ή βœ…

@jakob πŸ‡¦πŸ‡Ή βœ… I'm not aware of a platform as complex as Friendica without a dependency on Javascript. A while ago I started writing a nojs frontend for Friendica as a thought experiment but there just are too many features to account for, many of which designed to only work with Javascript enabled.
in reply to Hypolite Petovan

@Hypolite Petovan
i can imagine... this is difficult...

But what don't understand... why are content from other fediservers are loaded... i thought, in fediverse is only shown, what's on "my" server.

And why can content from a mastodon-server has influence on z-variables... so parts of the content is viewed over the topbars?

in reply to Hypolite Petovan

@Hypolite Petovan I understand, and I think nobody wants to completely disable JavaScript. What I don't understand: Why have I to accept and run JavaScript that comes along in a discussion thread from any foreign node. Sorry to say that: For me, this smells like a design weakness of Friendica. Without any knowledge of the internals, it's my instance that renders the posts, IMHO there is no need to running scripts from unknown sources.

@jakob πŸ‡¦πŸ‡Ή βœ…

in reply to alfredb

@alfredb @jakob πŸ‡¦πŸ‡Ή βœ… I haven't seen the exact situation where we run third-party scripts but I know of one Internet protocol that allows this: OEmbed. This is meant to embed third-party HTML snippets inside a webpage to display a summary representation of a remote resource.

It's not very popular because of the security risks and the release of platform-specific embed JS libraries that can be served locally to display an embedded tweet or Instagram post.

in reply to Hypolite Petovan

The question is, does it help allowing scripts from the Friendica Server only? In that case I would'nt consider it to be a huge issue because I have to trust my Instance anyway.

If disabling 3rd party scripts causes an issue, it's a different story though..

I haven't used NoScript for a while now, so thats why I'm asking.

in reply to AndiS 🌞🍷πŸ‡ͺπŸ‡Ί

@AndiS 🌞🍷πŸ‡ͺπŸ‡Ί I forgot NoScript can be tweaked to allow disallow third-party scripts. It's possible we use them to display specific resources like embedded Youtube videos.
in reply to jakob πŸ‡¦πŸ‡Ή βœ…

@jakob πŸ‡¦πŸ‡Ή βœ… @AndiS 🌞🍷πŸ‡ͺπŸ‡Ί Thank you for the elaboration, so far I have not been able to witness third-party Mastodon script included in my timeline so I'd have a hard time telling you why it's happening at the moment.
⇧