AdguardTeam / AdguardTeam/CoreLibs

Apply $removeparam rules to URLs updated via history.pushState / history.replaceState

Open
#2,071 0 comments 1 reaction 1 assignee Claimed by @sfionov View on GitHub
Feature request Priority: P4 Version: CoreLibs v1.24
Dominant language
No language data
Stars
52
Forks
10
PR merge metrics
No merged PRs in 30d

Description

### Issue Details

`$removeparam` is currently applied to real network requests, but not to URLs changed client-side via `history.pushState` or `history.replaceState` in single-page applications. Because of this, on sites like VK Video and Yandex Market, tracking parameters may remain visible in the address bar after in-app navigation without a full page reload. The same parameters also remain in the URL when copied from the address bar. This leads to inconsistent behavior between regular navigations and SPA-driven URL updates. Reference: #2070

### Proposed solution

Extend `$removeparam` handling so that it is also applied when a page updates the current URL through `history.pushState` or `history.replaceState`, without requiring a real network request or full page reload. When a SPA writes a new URL to browser history, AdGuard should sanitize that URL using matching `$removeparam` rules before it is shown in the address bar and before it can be copied. The implementation should preserve normal SPA navigation behavior and be validated across supported products, including extensions, to ensure consistent behavior.

### Alternative solution

_No response_

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.