Posted April 27, 2016

Rimmu
Demolitions Guy
GOG.com Team
Registered: Oct 2012
From Poland

Johny.GOG
☕️
GOG.com Team
Registered: Dec 2014
From Poland
Posted April 29, 2016
I'm sorry, but I guess there are no news on that topic. It's not as important as things we're currently working on - in my opinion.

Johny.GOG
☕️
GOG.com Team
Registered: Dec 2014
From Poland
Posted May 10, 2016
Yes, we're using external service to measure and improve our performance and track errors on your (user) side.
In current moment I don't know whether it's possible for website to work with it blocked by noScript.
You could enable scripts from these domains to prevent JavaScript from crashing + help us improve performance and track errors.
In current moment I don't know whether it's possible for website to work with it blocked by noScript.
You could enable scripts from these domains to prevent JavaScript from crashing + help us improve performance and track errors.
Post edited May 10, 2016 by Johny.

Johny.GOG
☕️
GOG.com Team
Registered: Dec 2014
From Poland
Posted May 10, 2016
Right, account menu disappears on forum pages regardless of the browser/noScript/adBlock (works if cached) - we'll fix it very soon.
Probably noScript will not affect website then in any new way. It's a different bug - sorry!
Probably noScript will not affect website then in any new way. It's a different bug - sorry!
Post edited May 10, 2016 by Johny.

Litek
Old User
GOG.com Team
Registered: Sep 2009
From Kosovo
Posted May 10, 2016
It's fixed now.

Litek
Old User
GOG.com Team
Registered: Sep 2009
From Kosovo
Posted May 10, 2016

Johny.GOG
☕️
GOG.com Team
Registered: Dec 2014
From Poland
Posted May 11, 2016

First of all - it's not sending anything to cloudfront - it's downloading a script from there, just as we would host this script on GOG.com - no difference here.
Secondly - Cloudfront is a "cloud" service to store assets and a lot of developers use it. GOG.com may have a lot more dependencies from external domains in the future, because why not?
Third thing is log-in doesn't work because whole JavaScript init crashes, not because exactly "log in" function needs this cloudfront script.
I'd advise you to not block it. :)
About "Attach images" button - I see it's broken and I know why. We'll fix it.

Johny.GOG
☕️
GOG.com Team
Registered: Dec 2014
From Poland

Litek
Old User
GOG.com Team
Registered: Sep 2009
From Kosovo

Johny.GOG
☕️
GOG.com Team
Registered: Dec 2014
From Poland
Posted May 11, 2016

Secondly - Cloudfront is a "cloud" service to store assets and a lot of developers use it. GOG.com may have a lot more dependencies from external domains in the future, because why not?
[...].

Here, with this single one, the difference is just the domain on which it is hosted.
(it's considered faster to load assets asynchronously from common domains, but not everybody agrees on that)

Third thing is log-in doesn't work because whole JavaScript init crashes, not because exactly "log in" function needs this cloudfront script.
[...]

Do you have an ETA for fixing this?
Logging in (opening the modal) requires javascript to run properly, and they'll crash if you block part of them.

If you decide to block scripts, you should know that you won't be able to use any scripts until you unblock them.
edit: If you wish, you can always chat me about that.
Post edited May 11, 2016 by Johny.

Johny.GOG
☕️
GOG.com Team
Registered: Dec 2014
From Poland
Posted May 12, 2016
You can try following:
Go to NoScript settings -> Advanced tab -> Trusted tab,
then enable checkbox "Cascade top document's permissions to 3rd party scripts"
Then you would trust what we embed ourselves without permitting couldfront globally.
I don't see an option to add file or file regex (only domain regex) to whitelist, unfortunately.
Go to NoScript settings -> Advanced tab -> Trusted tab,
then enable checkbox "Cascade top document's permissions to 3rd party scripts"
Then you would trust what we embed ourselves without permitting couldfront globally.
I don't see an option to add file or file regex (only domain regex) to whitelist, unfortunately.

Johny.GOG
☕️
GOG.com Team
Registered: Dec 2014
From Poland
Posted May 12, 2016
I'd like to add something:
- JavaScript can't install malware on your computer.
- JS running on www.gog.com can't get your login credentials on GOG.com too, because it's done on a separate domain (login.gog.com) - no JS that is running by the main page can access what's inside. Unless you are running - let's say - old Internet Explorer with some security settings disabled.
- It can't get your session cookie too, because it's "HTTP only".
What's interesting - for example Adalia Fundamentals, other userscripts, or browser addons (like NoScript :D ), potentially can get your password as you type, or your session cookie in the next update with no problem at all. ;)
Consider that popular userscript or browser addon creator is hacked, or NoScript/GreaseMonkey gets sold to evil company. Good that browser is asking for camera permiossions. ;) Security is important.
- JavaScript can't install malware on your computer.
- JS running on www.gog.com can't get your login credentials on GOG.com too, because it's done on a separate domain (login.gog.com) - no JS that is running by the main page can access what's inside. Unless you are running - let's say - old Internet Explorer with some security settings disabled.
- It can't get your session cookie too, because it's "HTTP only".
What's interesting - for example Adalia Fundamentals, other userscripts, or browser addons (like NoScript :D ), potentially can get your password as you type, or your session cookie in the next update with no problem at all. ;)
Consider that popular userscript or browser addon creator is hacked, or NoScript/GreaseMonkey gets sold to evil company. Good that browser is asking for camera permiossions. ;) Security is important.
Post edited May 12, 2016 by Johny.

Johny.GOG
☕️
GOG.com Team
Registered: Dec 2014
From Poland
Posted May 12, 2016

Stay safe!
Did someone try the NoScript settings I suggested, or have bad opinion about them? ;)

Johny.GOG
☕️
GOG.com Team
Registered: Dec 2014
From Poland
Posted May 12, 2016
Could you please tell what browser are you using?

JudasIscariot
Thievin' Bastard
GOG.com Team
Registered: Oct 2008
From Poland