MozillaZine

Javascript.allow.mailnews

From MozillaZine Knowledge Base

Contents

Background

Newsgroup messages and e-mail can be in HTML format and HTML can include JavaScript, so e-mail messages can include executable code. This preference controls whether to allow JavaScript in newsgroup messages and e-mails to execute.

Possible values and their effects

True

JavaScript in newsgroup messages and e-mails can execute.

False

JavaScript in newsgroup messages and e-mails cannot execute. (Default)

UI

Mozilla Suite

A checkbox labeled “Mail & Newsgroups” is located under “Edit → Preferences → Advanced → Scripts & Plug-ins → Enable JavaScript for”.

Recommended settings

While Mozilla products are secure, JavaScript in e-mails is a common attack vector and is rarely used legitimitely. It is recommended that this value be left at false unless there are compelling reasons not to.

First checked in

2000-01-08 by Norris Boyd.

Has an effect in

  • Mozilla Suite (all versions since M13)
  • Thunderbird (all versions)
  • SeaMonkey (all versions)

Related bugs

Related preferences