From 95fb100b238f80a970b83aa90bab0200f627e313 Mon Sep 17 00:00:00 2001 From: Thorin-Oakenpants <Thorin-Oakenpants@users.noreply.github.com> Date: Tue, 25 Aug 2020 13:54:25 +0000 Subject: [PATCH] https-only mode --- user.js | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/user.js b/user.js index 0eccd71..01fae6f 100644 --- a/user.js +++ b/user.js @@ -735,11 +735,12 @@ user_pref("security.mixed_content.block_display_content", true); * [1] https://bugzilla.mozilla.org/1190623 ***/ user_pref("security.mixed_content.block_object_subrequest", true); /* 1244: enable HTTPS-Only mode [FF76+] - * [NOTE] This is experimental + * When "https_only_mode" (all) is true, "https_only_mode_pbm" (Private Browsing Mode) is ignored * [SETTING] to add site exceptions: Page Info>Permissions>Use insecure HTTP (FF80+) - * [SETTING] Privacy & Security>HTTPS-Only Mode (FF81+) + * [SETTING] Privacy & Security>HTTPS-Only Mode (FF80+ with browser.preferences.exposeHTTPSOnly = true) * [1] https://bugzilla.mozilla.org/1613063 */ // user_pref("dom.security.https_only_mode", true); // [FF76+] + // user_pref("dom.security.https_only_mode_pbm", true); // [FF80+] // user_pref("dom.security.https_only_mode.upgrade_local", true); // [FF77+] /** CIPHERS [WARNING: do not meddle with your cipher suite: see the section 1200 intro]