AdguardTeam / AdguardTeam/Scriptlets

Improve 'prevent-xhr' — modify 'statusText'

未关闭
#310 0 条评论 0 个 reaction 已指派 1 人 已指派给 @maximtop 在 GitHub 查看
enhancement Priority: P4
主要语言
JavaScript
星标
195
派生
33
PR 合并指标
30 天内没有已合并 PR

描述

In `prevent-xhr` scriptlet `statusText` always returns `OK` value:
https://github.com/AdguardTeam/Scriptlets/blob/091247665fb9e83d68fb16d63c5246fff70fb7c3/src/scriptlets/prevent-xhr.js#L148
but it looks like that this value depends on web browser and version of HTTP.

According to - https://developer.mozilla.org/en-US/docs/Web/API/XMLHttpRequest/statusText
>Note: Responses over an HTTP/2 connection will always have an empty string as status message as HTTP/2 does not support them.

This seems to be true for Chromium based browsers, but in Firefox it returns `OK` value (if I'm right).

So maybe we could add an additional argument to set `statusText` to `OK` value or to empty string.
Or it could be done basing on the web browser, for Firefox `OK` value and for Chrome/Chromium empty string (probably the same for Safari).

Steps to reproduce
1. Add this rule:
```adblock
fiddle.jshell.net#%#//scriptlet('prevent-xhr', '/')
```
2. Go to - https://jsfiddle.net/crwLnjz6/
Code

```js
const xhr = new XMLHttpRequest();
xhr.open('GET', '/', true);
xhr.onload = () => {
alert(`DONE, statusText: ${xhr.statusText}`);
};
xhr.send(null);
```

In Chrome without the rule `statusText` is empty, but with rule it shows `OK`.
In Firefox it always shows `OK`.

Screenshot - Chrome with scriptlet enabled

![image](https://user-images.githubusercontent.com/29142494/232312153-e9417415-3cb1-45e7-85c9-1f502b74f7c2.png)

Screenshot - Chrome with scriptlet disabled

![image](https://user-images.githubusercontent.com/29142494/232312172-95083030-57ab-4305-84da-9f557158dbc6.png)


Related issue - https://github.com/AdguardTeam/AdguardFilters/issues/148345
To reproduce it's necessary to go to - `https://extrogames.com/game/iron-world#download`, choose `Doodrive` link and it should redirects to `woowebtools.com`.
Their code is obfuscated, but as far as I understand, it looks like that one of the things which are checked is if `pagead2.googlesyndication.com/pagead/js/adsbygoogle.js` is blocked and value of `statusText` of this request.
And in this case, in Chrome `woowebtools.com#%#//scriptlet('prevent-xhr', 'pagead2.googlesyndication.com')` doesn't fix anti-adblock detection, because `statusText` is checked.

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。