AdguardTeam / AdguardTeam/Scriptlets

Improve 'prevent-xhr' — modify 'statusText'

Aberta
#310 0 comentários 0 reações 1 responsável Atribuída a @maximtop Ver no GitHub
enhancement Priority: P4
Linguagem predominante
JavaScript
Estrelas
195
Forks
33
Métricas de merge de PRs
Nenhum PR com merge em 30d

Descrição

In `prevent-xhr` scriptlet `statusText` always returns `OK` value:
https://github.com/AdguardTeam/Scriptlets/blob/091247665fb9e83d68fb16d63c5246fff70fb7c3/src/scriptlets/prevent-xhr.js#L148
but it looks like that this value depends on web browser and version of HTTP.

According to - https://developer.mozilla.org/en-US/docs/Web/API/XMLHttpRequest/statusText
>Note: Responses over an HTTP/2 connection will always have an empty string as status message as HTTP/2 does not support them.

This seems to be true for Chromium based browsers, but in Firefox it returns `OK` value (if I'm right).

So maybe we could add an additional argument to set `statusText` to `OK` value or to empty string.
Or it could be done basing on the web browser, for Firefox `OK` value and for Chrome/Chromium empty string (probably the same for Safari).

Steps to reproduce
1. Add this rule:
```adblock
fiddle.jshell.net#%#//scriptlet('prevent-xhr', '/')
```
2. Go to - https://jsfiddle.net/crwLnjz6/
Code

```js
const xhr = new XMLHttpRequest();
xhr.open('GET', '/', true);
xhr.onload = () => {
alert(`DONE, statusText: ${xhr.statusText}`);
};
xhr.send(null);
```

In Chrome without the rule `statusText` is empty, but with rule it shows `OK`.
In Firefox it always shows `OK`.

Screenshot - Chrome with scriptlet enabled

![image](https://user-images.githubusercontent.com/29142494/232312153-e9417415-3cb1-45e7-85c9-1f502b74f7c2.png)

Screenshot - Chrome with scriptlet disabled

![image](https://user-images.githubusercontent.com/29142494/232312172-95083030-57ab-4305-84da-9f557158dbc6.png)


Related issue - https://github.com/AdguardTeam/AdguardFilters/issues/148345
To reproduce it's necessary to go to - `https://extrogames.com/game/iron-world#download`, choose `Doodrive` link and it should redirects to `woowebtools.com`.
Their code is obfuscated, but as far as I understand, it looks like that one of the things which are checked is if `pagead2.googlesyndication.com/pagead/js/adsbygoogle.js` is blocked and value of `statusText` of this request.
And in this case, in Chrome `woowebtools.com#%#//scriptlet('prevent-xhr', 'pagead2.googlesyndication.com')` doesn't fix anti-adblock detection, because `statusText` is checked.

Guia de contribuição

Nenhum guia de contribuição indexado para este repositório

Avaliação

Esta issue ainda não foi avaliada.

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.