For all settings where this makes sense, the setting should be configurable per domain (or probably even protocol/domain/port triple). This will make a lot of things easier: - NoScript is essentially done then - RequestPolicy is a lot easier - etc.