AdguardTeam / AdguardTeam/Scriptlets

Improve 'prevent-xhr' — modify 'statusText'

オープン
#310 コメント 0 件 リアクション 0 件 担当者 1 名 @maximtop に割り当て済み GitHub で見る
enhancement Priority: P4
主要言語
JavaScript
スター
195
フォーク
33
PR マージ指標
30日以内にマージされた PR はありません

説明

In `prevent-xhr` scriptlet `statusText` always returns `OK` value:
https://github.com/AdguardTeam/Scriptlets/blob/091247665fb9e83d68fb16d63c5246fff70fb7c3/src/scriptlets/prevent-xhr.js#L148
but it looks like that this value depends on web browser and version of HTTP.

According to - https://developer.mozilla.org/en-US/docs/Web/API/XMLHttpRequest/statusText
>Note: Responses over an HTTP/2 connection will always have an empty string as status message as HTTP/2 does not support them.

This seems to be true for Chromium based browsers, but in Firefox it returns `OK` value (if I'm right).

So maybe we could add an additional argument to set `statusText` to `OK` value or to empty string.
Or it could be done basing on the web browser, for Firefox `OK` value and for Chrome/Chromium empty string (probably the same for Safari).

Steps to reproduce
1. Add this rule:
```adblock
fiddle.jshell.net#%#//scriptlet('prevent-xhr', '/')
```
2. Go to - https://jsfiddle.net/crwLnjz6/
Code

```js
const xhr = new XMLHttpRequest();
xhr.open('GET', '/', true);
xhr.onload = () => {
alert(`DONE, statusText: ${xhr.statusText}`);
};
xhr.send(null);
```

In Chrome without the rule `statusText` is empty, but with rule it shows `OK`.
In Firefox it always shows `OK`.

Screenshot - Chrome with scriptlet enabled

![image](https://user-images.githubusercontent.com/29142494/232312153-e9417415-3cb1-45e7-85c9-1f502b74f7c2.png)

Screenshot - Chrome with scriptlet disabled

![image](https://user-images.githubusercontent.com/29142494/232312172-95083030-57ab-4305-84da-9f557158dbc6.png)


Related issue - https://github.com/AdguardTeam/AdguardFilters/issues/148345
To reproduce it's necessary to go to - `https://extrogames.com/game/iron-world#download`, choose `Doodrive` link and it should redirects to `woowebtools.com`.
Their code is obfuscated, but as far as I understand, it looks like that one of the things which are checked is if `pagead2.googlesyndication.com/pagead/js/adsbygoogle.js` is blocked and value of `statusText` of this request.
And in this case, in Chrome `woowebtools.com#%#//scriptlet('prevent-xhr', 'pagead2.googlesyndication.com')` doesn't fix anti-adblock detection, because `statusText` is checked.

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。