From 595009a71659ce3d7f7bd9b39979f9ee75518a7c Mon Sep 17 00:00:00 2001 From: Thorin-Oakenpants Date: Mon, 26 Mar 2018 17:01:18 +0000 Subject: [PATCH] tweaks --- user.js | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/user.js b/user.js index 8c86498..85df823 100644 --- a/user.js +++ b/user.js @@ -1067,12 +1067,13 @@ user_pref("dom.disable_window_open_feature.toolbar", true); user_pref("dom.allow_scripts_to_close_windows", false); // default: false user_pref("dom.disable_window_flip", true); // window z-order - default: true user_pref("dom.disable_window_move_resize", true); -/* 2203: open links targeting new windows in a new tab instead +/* 2203: enforce links targeting new windows to open in a new tab instead * This stops malicious window sizes and some screen resolution leaks. * You can still right-click a link and open in a new window. + * [NOTE] RFP (4500) already resizes new windows to cover screen resolution leaks * [TEST] https://people.torproject.org/~gk/misc/entire_desktop.html * [1] https://trac.torproject.org/projects/tor/ticket/9881 ***/ -user_pref("browser.link.open_newwindow", 3); +user_pref("browser.link.open_newwindow", 3); // 1=current, 2=new, 3=most recent user_pref("browser.link.open_newwindow.restriction", 0); /* 2204: disable Fullscreen API to prevent screen-resolution leaks [SETUP] * [NOTE] You can still manually toggle the browser's fullscreen state (F11),