New ajax API url breaks search/forum posting w/ NoScript

Avatar image for def
DeF

5450

Forum Posts

208181

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

So I just came to the site, wanted to add some wiki thing. Typed my game name into the search bar, nothing happened. I'm using NoScript (Firefox) to protect me from shitty sites using shitty things, I'm sure you're familiar. So far, I've had everything on GB whitelisted to ensure normal, full functionality. Now I take a peek out of curiosity to find the cause of the problem and see a new "ajax.googleapis.com" url that it's blocking. I whitelist it and boom, site's back to normal.

So this new thing is gonna cause problems for everyone running NoScript (or similar) and not checking their exceptions. Oh and it also affects the text entry window I'm typing this into now. I tested it by blocking it again and then opened this "create new topic" window and could not enter any text in the main entry field until I whitelisted ajax.googleapis.com again. And the window is also completely white, by the way.

So, again, this is more of a helpful warning/hint to those who experience the same thing and forgot to check their script blocking plugins.

No Caption Provided
No Caption Provided

Avatar image for doublezero
doublezero

230

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

You must be new to using NoScript.

ajax.googleapis.com is a very common requirement for a lot of modern websites to work at all.

I think it sucks that you have all these websites loading resources from Google, but that's just how it is.

If your concern is privacy, I would suggest using Policeman (or uMatrix) in addition to NoScript, or perhaps even instead of it if you want less work.

But as with NoScript, it basically breaks modern websites by default and you will have to figure out your white-listing until they work.

Even sites like Giant Bomb—and even when logged in as a paying subscriber—are loading a ton of external tracking resources:

No Caption Provided

Welcome to the modern internet. It sucks.

Avatar image for chaser324
chaser324

9415

Forum Posts

14945

Wiki Points

0

Followers

Reviews: 1

User Lists: 15

#3  Edited By chaser324  Moderator

@00 said:

I think it sucks that you have all these websites loading resources from Google, but that's just how it is.

I actually think pulling scripts from CDNs like Google's is preferable - they're a known reliable source, great for performance/caching, and often encourage the use of HTTPS.

Avatar image for doublezero
doublezero

230

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#4  Edited By doublezero

@00 said:

I think it sucks that you have all these websites loading resources from Google, but that's just how it is.

I actually think pulling scripts from CDNs like Google's is preferable - they're a known reliable source, great for performance/caching, and often encourage the use of HTTPS.

I'd rather all my traffic to a website was constrained to that website instead of hitting Google.

Though I suppose I prefer that most of the tracking that goes on happens via third-party requests, since it makes it easier to block.

Avatar image for def
DeF

5450

Forum Posts

208181

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

@00: I'm not new to NoScript at all, I can't even remember how long I've used it (better part of a decade at least).

I only made this topic because the issue randomly popped up that day and never before. I assumed some change was made on the site that triggered this.

Avatar image for thunderslash
ThunderSlash

2606

Forum Posts

630

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Thanks for the heads up. I think I whitelist most Google scripts just cus most sites are so reliant on them. This stuff is pretty much the norm for NoScript users though. Gotta play the "which scripts to enable" minigame whenever you visit a new site.

Avatar image for jslack
jslack

1186

Forum Posts

1165

Wiki Points

0

Followers

Reviews: 1

User Lists: 6

#7  Edited By jslack

NoScript, Ghostery and things like HTTPEverywhere will break a lot of things on the site, unfortunately.

Avatar image for wcarle
wcarle

447

Forum Posts

54

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Yeah man ajax.googleapis.com is google's hosted libraries CDN which we use for jQuery. If you block that site you're gonna have a bad time, tons of sites use google's CDN for hosting things like jQuery because it makes things faster for you the consumer!

Avatar image for def
DeF

5450

Forum Posts

208181

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

@wcarle: Like I said, the weird thing was that I've been using the site for years without issues and had made 0 changes in what NoScript blocks and doesn't block. It just suddenly became an issue, hence the thread. :)

But since it's apparently a random thing that just happened to me then it's cool.

Avatar image for jslack
jslack

1186

Forum Posts

1165

Wiki Points

0

Followers

Reviews: 1

User Lists: 6

@dudeglove: Ya, Unfortunately. You have to whitelist a lot of stuff. As far as HTTPS Everywhere, we are attempting to serve more and more on https as we can. The biggest issue is dealing with 3rd parties.