Yellowlist cdn.lib.newsvine.com#1570
Conversation
|
As you recommended in the meeting today, these debug functions will be added to the background once #1430 is merged |
|
It actually looks like newsvine and msnbc are owned by the same conglomerate link. And the domain seems to only appear on msnbc.com link. So it would probably be better to add this to the multidomainfirstparties. You should add an entry like this |
|
@eenblam How'd you print that cookie info? I'm asking because the " It isn't private in this case, it is just a tracking token. |
|
I just included the same info from the example yellowlist PR.
Copypasta meant that I had to manually reformat it to get the style in the code block. So, people who do the same and know to be alarmed by sharing a token might notice it then, but it doesn't protect arbitrary users by any means. An aside: to find this information, users have to do this: And to get the rest of the debugging instructions, they have to follow an additional link out of the repo. The last link is fixed by the PR that makes the function available in the background page by default, but overall the documentation structure makes it a bit hard to find. |
|
@eenblam I agree. The intention of #1221 and #1430 is to streamline this process. Eventually the contributing.md or possibly an issue template will refer to these more explicitly. In the meantime, I'll add a link in the contributing document to the relevant gist. I super super want to avoid having a user accidentally post a cookie with an authentication token, so I'll probably remove that part until #1430 is merged, which avoids that problem. |
Fixes #1293 by yellowlisting the cdn, as suggested.
Debug data from Privacy Badger:
Cookie set by newsvine.com lasts for twenty years; obvious tracker.