2014-06-24 00:42:43 +02:00
|
|
|
/*******************************************************************************
|
|
|
|
|
2016-03-22 15:19:41 +01:00
|
|
|
uBlock Origin - a browser extension to block requests.
|
2018-01-03 05:06:16 +01:00
|
|
|
Copyright (C) 2014-2018 Raymond Hill
|
2014-06-24 00:42:43 +02:00
|
|
|
|
|
|
|
This program is free software: you can redistribute it and/or modify
|
|
|
|
it under the terms of the GNU General Public License as published by
|
|
|
|
the Free Software Foundation, either version 3 of the License, or
|
|
|
|
(at your option) any later version.
|
|
|
|
|
|
|
|
This program is distributed in the hope that it will be useful,
|
|
|
|
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
GNU General Public License for more details.
|
|
|
|
|
|
|
|
You should have received a copy of the GNU General Public License
|
|
|
|
along with this program. If not, see {http://www.gnu.org/licenses/}.
|
|
|
|
|
|
|
|
Home: https://github.com/gorhill/uBlock
|
|
|
|
*/
|
|
|
|
|
2016-07-01 04:03:29 +02:00
|
|
|
'use strict';
|
2014-06-24 00:42:43 +02:00
|
|
|
|
|
|
|
/******************************************************************************/
|
|
|
|
|
|
|
|
// Start isolation from global scope
|
|
|
|
|
|
|
|
µBlock.webRequest = (function() {
|
|
|
|
|
|
|
|
/******************************************************************************/
|
|
|
|
|
2015-03-26 00:28:22 +01:00
|
|
|
var exports = {};
|
|
|
|
|
2015-03-13 14:48:10 +01:00
|
|
|
/******************************************************************************/
|
|
|
|
|
2018-05-16 17:50:50 +02:00
|
|
|
// Platform-specific behavior.
|
|
|
|
|
|
|
|
// https://github.com/uBlockOrigin/uBlock-issues/issues/42
|
|
|
|
// https://bugzilla.mozilla.org/show_bug.cgi?id=1376932
|
|
|
|
// Add proper version number detection once issue is fixed in Firefox.
|
|
|
|
let dontCacheResponseHeaders =
|
|
|
|
vAPI.webextFlavor.soup.has('firefox');
|
|
|
|
|
|
|
|
// https://github.com/gorhill/uMatrix/issues/967#issuecomment-373002011
|
|
|
|
// This can be removed once Firefox 60 ESR is released.
|
|
|
|
let cantMergeCSPHeaders =
|
|
|
|
vAPI.webextFlavor.soup.has('firefox') && vAPI.webextFlavor.major < 59;
|
|
|
|
|
|
|
|
|
|
|
|
// The real actual webextFlavor value may not be set in stone, so listen
|
|
|
|
// for possible future changes.
|
|
|
|
window.addEventListener('webextFlavor', function() {
|
|
|
|
dontCacheResponseHeaders =
|
|
|
|
vAPI.webextFlavor.soup.has('firefox');
|
|
|
|
cantMergeCSPHeaders =
|
|
|
|
vAPI.webextFlavor.soup.has('firefox') && vAPI.webextFlavor.major < 59;
|
|
|
|
}, { once: true });
|
|
|
|
|
|
|
|
/******************************************************************************/
|
|
|
|
|
2016-11-04 04:42:03 +01:00
|
|
|
// https://github.com/gorhill/uBlock/issues/2067
|
2017-03-05 14:25:55 +01:00
|
|
|
// Experimental: Block everything until uBO is fully ready.
|
|
|
|
// TODO: re-work vAPI code to match more closely how listeners are
|
|
|
|
// registered with the webRequest API. This will simplify implementing
|
|
|
|
// the feature here: we could have a temporary onBeforeRequest listener
|
|
|
|
// which blocks everything until all is ready.
|
|
|
|
// This would allow to avoid the permanent special test at the top of
|
|
|
|
// the main onBeforeRequest just to implement this.
|
2017-11-16 06:34:01 +01:00
|
|
|
// https://github.com/gorhill/uBlock/issues/3130
|
|
|
|
// Don't block root frame.
|
|
|
|
|
2017-03-05 14:25:55 +01:00
|
|
|
var onBeforeReady = null;
|
|
|
|
|
2017-11-16 16:55:28 +01:00
|
|
|
µBlock.onStartCompletedQueue.push(function(callback) {
|
|
|
|
vAPI.onLoadAllCompleted();
|
|
|
|
callback();
|
|
|
|
});
|
|
|
|
|
2017-03-05 14:25:55 +01:00
|
|
|
if ( µBlock.hiddenSettings.suspendTabsUntilReady ) {
|
|
|
|
onBeforeReady = (function() {
|
|
|
|
var suspendedTabs = new Set();
|
|
|
|
µBlock.onStartCompletedQueue.push(function(callback) {
|
|
|
|
onBeforeReady = null;
|
2017-05-19 16:12:55 +02:00
|
|
|
for ( var tabId of suspendedTabs ) {
|
|
|
|
vAPI.tabs.reload(tabId);
|
2017-03-05 14:25:55 +01:00
|
|
|
}
|
|
|
|
callback();
|
|
|
|
});
|
2017-11-16 06:34:01 +01:00
|
|
|
return function(details) {
|
|
|
|
if (
|
|
|
|
details.type !== 'main_frame' &&
|
|
|
|
vAPI.isBehindTheSceneTabId(details.tabId) === false
|
|
|
|
) {
|
|
|
|
suspendedTabs.add(details.tabId);
|
|
|
|
return true;
|
|
|
|
}
|
2017-03-05 14:25:55 +01:00
|
|
|
};
|
|
|
|
})();
|
|
|
|
}
|
2016-11-04 04:42:03 +01:00
|
|
|
|
|
|
|
/******************************************************************************/
|
|
|
|
|
2014-07-26 15:55:12 +02:00
|
|
|
// Intercept and filter web requests.
|
2014-07-14 17:24:59 +02:00
|
|
|
|
2014-07-26 01:29:51 +02:00
|
|
|
var onBeforeRequest = function(details) {
|
2017-11-16 06:34:01 +01:00
|
|
|
if ( onBeforeReady !== null && onBeforeReady(details) ) {
|
2016-11-04 04:42:03 +01:00
|
|
|
return { cancel: true };
|
|
|
|
}
|
|
|
|
|
2014-07-26 01:29:51 +02:00
|
|
|
// Special handling for root document.
|
2015-04-07 03:26:05 +02:00
|
|
|
// https://github.com/chrisaljoudi/uBlock/issues/1001
|
2015-03-13 14:48:10 +01:00
|
|
|
// This must be executed regardless of whether the request is
|
|
|
|
// behind-the-scene
|
2015-03-21 21:52:35 +01:00
|
|
|
var requestType = details.type;
|
2015-03-13 15:20:33 +01:00
|
|
|
if ( requestType === 'main_frame' ) {
|
2015-03-21 21:52:35 +01:00
|
|
|
return onBeforeRootFrameRequest(details);
|
2014-07-14 17:24:59 +02:00
|
|
|
}
|
|
|
|
|
2015-03-13 14:48:10 +01:00
|
|
|
// Special treatment: behind-the-scene requests
|
2017-11-16 06:34:01 +01:00
|
|
|
var tabId = details.tabId;
|
2015-04-05 18:03:14 +02:00
|
|
|
if ( vAPI.isBehindTheSceneTabId(tabId) ) {
|
2015-03-13 14:48:10 +01:00
|
|
|
return onBeforeBehindTheSceneRequest(details);
|
|
|
|
}
|
|
|
|
|
2014-07-26 01:29:51 +02:00
|
|
|
// Lookup the page store associated with this tab id.
|
2016-10-14 16:06:34 +02:00
|
|
|
var µb = µBlock,
|
|
|
|
pageStore = µb.pageStoreFromTabId(tabId);
|
2014-07-26 01:29:51 +02:00
|
|
|
if ( !pageStore ) {
|
2015-12-02 06:59:51 +01:00
|
|
|
var tabContext = µb.tabContextManager.mustLookup(tabId);
|
2015-04-09 00:46:08 +02:00
|
|
|
if ( vAPI.isBehindTheSceneTabId(tabContext.tabId) ) {
|
2015-03-22 01:30:00 +01:00
|
|
|
return onBeforeBehindTheSceneRequest(details);
|
2015-03-13 14:48:10 +01:00
|
|
|
}
|
2015-04-09 00:46:08 +02:00
|
|
|
vAPI.tabs.onNavigation({ tabId: tabId, frameId: 0, url: tabContext.rawURL });
|
|
|
|
pageStore = µb.pageStoreFromTabId(tabId);
|
2014-07-14 20:40:40 +02:00
|
|
|
}
|
2014-07-15 13:38:34 +02:00
|
|
|
|
2015-04-07 03:26:05 +02:00
|
|
|
// https://github.com/chrisaljoudi/uBlock/issues/886
|
2015-02-25 20:15:36 +01:00
|
|
|
// For requests of type `sub_frame`, the parent frame id must be used
|
|
|
|
// to lookup the proper context:
|
|
|
|
// > If the document of a (sub-)frame is loaded (type is main_frame or
|
|
|
|
// > sub_frame), frameId indicates the ID of this frame, not the ID of
|
|
|
|
// > the outer frame.
|
|
|
|
// > (ref: https://developer.chrome.com/extensions/webRequest)
|
2015-03-21 21:52:35 +01:00
|
|
|
var isFrame = requestType === 'sub_frame';
|
2015-04-09 00:46:08 +02:00
|
|
|
|
|
|
|
// https://github.com/chrisaljoudi/uBlock/issues/114
|
2017-05-12 16:35:11 +02:00
|
|
|
var requestContext = pageStore.createContextFromFrameId(
|
|
|
|
isFrame ? details.parentFrameId : details.frameId
|
|
|
|
);
|
2014-07-30 07:05:35 +02:00
|
|
|
|
2014-12-28 16:07:43 +01:00
|
|
|
// Setup context and evaluate
|
2015-03-21 21:52:35 +01:00
|
|
|
var requestURL = details.url;
|
2014-12-28 16:07:43 +01:00
|
|
|
requestContext.requestURL = requestURL;
|
2016-01-22 17:13:29 +01:00
|
|
|
requestContext.requestHostname = µb.URI.hostnameFromURI(requestURL);
|
2014-12-28 16:07:43 +01:00
|
|
|
requestContext.requestType = requestType;
|
|
|
|
|
|
|
|
var result = pageStore.filterRequest(requestContext);
|
2014-07-14 17:24:59 +02:00
|
|
|
|
2016-10-08 16:15:31 +02:00
|
|
|
pageStore.journalAddRequest(requestContext.requestHostname, result);
|
2015-06-05 01:27:03 +02:00
|
|
|
|
|
|
|
if ( µb.logger.isEnabled() ) {
|
|
|
|
µb.logger.writeOne(
|
|
|
|
tabId,
|
|
|
|
'net',
|
2017-05-12 16:35:11 +02:00
|
|
|
pageStore.logData,
|
2015-06-05 01:27:03 +02:00
|
|
|
requestType,
|
|
|
|
requestURL,
|
|
|
|
requestContext.rootHostname,
|
|
|
|
requestContext.pageHostname
|
|
|
|
);
|
|
|
|
}
|
2015-04-09 00:46:08 +02:00
|
|
|
|
2014-09-14 22:20:40 +02:00
|
|
|
// Not blocked
|
2017-05-12 16:35:11 +02:00
|
|
|
if ( result !== 1 ) {
|
2015-04-07 03:26:05 +02:00
|
|
|
// https://github.com/chrisaljoudi/uBlock/issues/114
|
2016-08-16 04:50:24 +02:00
|
|
|
if ( details.parentFrameId !== -1 && isFrame ) {
|
|
|
|
pageStore.setFrame(details.frameId, requestURL);
|
2014-08-06 01:35:32 +02:00
|
|
|
}
|
2016-07-01 04:03:29 +02:00
|
|
|
requestContext.dispose();
|
2014-07-14 17:24:59 +02:00
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
2014-07-26 01:29:51 +02:00
|
|
|
// Blocked
|
2014-12-23 00:38:18 +01:00
|
|
|
|
2015-11-23 13:52:50 +01:00
|
|
|
// https://github.com/gorhill/uBlock/issues/949
|
|
|
|
// Redirect blocked request?
|
2016-11-03 16:20:47 +01:00
|
|
|
if ( µb.hiddenSettings.ignoreRedirectFilters !== true ) {
|
|
|
|
var url = µb.redirectEngine.toURL(requestContext);
|
|
|
|
if ( url !== undefined ) {
|
|
|
|
pageStore.internalRedirectionCount += 1;
|
|
|
|
if ( µb.logger.isEnabled() ) {
|
|
|
|
µb.logger.writeOne(
|
|
|
|
tabId,
|
|
|
|
'redirect',
|
2017-05-12 16:35:11 +02:00
|
|
|
{ source: 'redirect', raw: µb.redirectEngine.resourceNameRegister },
|
2016-11-03 16:20:47 +01:00
|
|
|
requestType,
|
|
|
|
requestURL,
|
|
|
|
requestContext.rootHostname,
|
|
|
|
requestContext.pageHostname
|
|
|
|
);
|
|
|
|
}
|
|
|
|
requestContext.dispose();
|
|
|
|
return { redirectUrl: url };
|
2016-01-07 23:30:56 +01:00
|
|
|
}
|
2015-11-23 13:52:50 +01:00
|
|
|
}
|
2014-07-14 17:24:59 +02:00
|
|
|
|
2016-07-01 04:03:29 +02:00
|
|
|
requestContext.dispose();
|
2015-03-26 00:28:22 +01:00
|
|
|
return { cancel: true };
|
2014-07-14 17:24:59 +02:00
|
|
|
};
|
|
|
|
|
|
|
|
/******************************************************************************/
|
|
|
|
|
2015-03-21 21:52:35 +01:00
|
|
|
var onBeforeRootFrameRequest = function(details) {
|
2016-11-03 16:20:47 +01:00
|
|
|
var tabId = details.tabId,
|
|
|
|
requestURL = details.url,
|
|
|
|
µb = µBlock;
|
2015-03-31 15:07:14 +02:00
|
|
|
|
2015-04-09 00:46:08 +02:00
|
|
|
µb.tabContextManager.push(tabId, requestURL);
|
2015-03-26 00:28:22 +01:00
|
|
|
|
2015-03-21 21:52:35 +01:00
|
|
|
// Special handling for root document.
|
2015-04-07 03:26:05 +02:00
|
|
|
// https://github.com/chrisaljoudi/uBlock/issues/1001
|
2015-03-21 21:52:35 +01:00
|
|
|
// This must be executed regardless of whether the request is
|
|
|
|
// behind-the-scene
|
2016-11-03 16:20:47 +01:00
|
|
|
var µburi = µb.URI,
|
|
|
|
requestHostname = µburi.hostnameFromURI(requestURL),
|
2017-05-12 16:35:11 +02:00
|
|
|
requestDomain = µburi.domainFromHostname(requestHostname) || requestHostname;
|
2015-03-26 00:28:22 +01:00
|
|
|
var context = {
|
|
|
|
rootHostname: requestHostname,
|
|
|
|
rootDomain: requestDomain,
|
|
|
|
pageHostname: requestHostname,
|
|
|
|
pageDomain: requestDomain,
|
|
|
|
requestURL: requestURL,
|
|
|
|
requestHostname: requestHostname,
|
2016-08-31 11:19:16 +02:00
|
|
|
requestType: 'main_frame'
|
2015-03-26 00:28:22 +01:00
|
|
|
};
|
2017-05-12 16:35:11 +02:00
|
|
|
var result = 0,
|
|
|
|
logData,
|
|
|
|
logEnabled = µb.logger.isEnabled();
|
2015-03-26 00:28:22 +01:00
|
|
|
|
2015-04-09 18:20:24 +02:00
|
|
|
// If the site is whitelisted, disregard strict blocking
|
|
|
|
if ( µb.getNetFilteringSwitch(requestURL) === false ) {
|
2017-05-12 16:35:11 +02:00
|
|
|
result = 2;
|
|
|
|
if ( logEnabled === true ) {
|
|
|
|
logData = { engine: 'u', result: 2, raw: 'whitelisted' };
|
|
|
|
}
|
2015-04-09 18:20:24 +02:00
|
|
|
}
|
|
|
|
|
2015-03-27 18:00:55 +01:00
|
|
|
// Permanently unrestricted?
|
2017-05-12 16:35:11 +02:00
|
|
|
if ( result === 0 && µb.hnSwitches.evaluateZ('no-strict-blocking', requestHostname) ) {
|
|
|
|
result = 2;
|
|
|
|
if ( logEnabled === true ) {
|
|
|
|
logData = { engine: 'u', result: 2, raw: 'no-strict-blocking: ' + µb.hnSwitches.z + ' true' };
|
|
|
|
}
|
2015-03-27 18:00:55 +01:00
|
|
|
}
|
|
|
|
|
2015-03-26 00:28:22 +01:00
|
|
|
// Temporarily whitelisted?
|
2017-05-12 16:35:11 +02:00
|
|
|
if ( result === 0 ) {
|
2015-04-09 18:20:24 +02:00
|
|
|
result = isTemporarilyWhitelisted(result, requestHostname);
|
2017-05-12 16:35:11 +02:00
|
|
|
if ( result === 2 && logEnabled === true ) {
|
|
|
|
logData = { engine: 'u', result: 2, raw: 'no-strict-blocking true (temporary)' };
|
2015-04-09 18:20:24 +02:00
|
|
|
}
|
2015-03-21 21:52:35 +01:00
|
|
|
}
|
2015-03-26 00:28:22 +01:00
|
|
|
|
2015-07-13 14:49:58 +02:00
|
|
|
// Static filtering: We always need the long-form result here.
|
2015-07-11 23:40:42 +02:00
|
|
|
var snfe = µb.staticNetFilteringEngine;
|
2015-07-13 14:49:58 +02:00
|
|
|
|
|
|
|
// Check for specific block
|
2017-05-12 16:35:11 +02:00
|
|
|
if ( result === 0 ) {
|
|
|
|
result = snfe.matchStringExactType(context, requestURL, 'main_frame');
|
2017-05-28 22:57:02 +02:00
|
|
|
if ( result !== 0 || logEnabled === true ) {
|
2017-05-12 16:35:11 +02:00
|
|
|
logData = snfe.toLogData();
|
|
|
|
}
|
2015-07-13 14:49:58 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
// Check for generic block
|
2017-05-12 16:35:11 +02:00
|
|
|
if ( result === 0 ) {
|
|
|
|
result = snfe.matchStringExactType(context, requestURL, 'no_type');
|
2017-05-28 22:57:02 +02:00
|
|
|
if ( result !== 0 || logEnabled === true ) {
|
|
|
|
logData = snfe.toLogData();
|
|
|
|
}
|
|
|
|
// https://github.com/chrisaljoudi/uBlock/issues/1128
|
|
|
|
// Do not block if the match begins after the hostname, except when
|
|
|
|
// the filter is specifically of type `other`.
|
|
|
|
// https://github.com/gorhill/uBlock/issues/490
|
|
|
|
// Removing this for the time being, will need a new, dedicated type.
|
|
|
|
if (
|
|
|
|
result === 1 &&
|
|
|
|
toBlockDocResult(requestURL, requestHostname, logData) === false
|
|
|
|
) {
|
|
|
|
result = 0;
|
|
|
|
logData = undefined;
|
2015-03-30 23:42:12 +02:00
|
|
|
}
|
2015-03-26 00:28:22 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
// Log
|
2015-04-09 00:46:08 +02:00
|
|
|
var pageStore = µb.bindTabToPageStats(tabId, 'beforeRequest');
|
2015-03-26 00:28:22 +01:00
|
|
|
if ( pageStore ) {
|
2016-10-08 16:15:31 +02:00
|
|
|
pageStore.journalAddRootFrame('uncommitted', requestURL);
|
|
|
|
pageStore.journalAddRequest(requestHostname, result);
|
2015-03-26 00:28:22 +01:00
|
|
|
}
|
2015-06-05 01:27:03 +02:00
|
|
|
|
2017-05-12 16:35:11 +02:00
|
|
|
if ( logEnabled ) {
|
2015-06-05 01:27:03 +02:00
|
|
|
µb.logger.writeOne(
|
|
|
|
tabId,
|
|
|
|
'net',
|
2017-05-12 16:35:11 +02:00
|
|
|
logData,
|
2015-06-05 01:27:03 +02:00
|
|
|
'main_frame',
|
|
|
|
requestURL,
|
|
|
|
requestHostname,
|
|
|
|
requestHostname
|
|
|
|
);
|
|
|
|
}
|
2015-03-26 00:28:22 +01:00
|
|
|
|
|
|
|
// Not blocked
|
2017-05-12 16:35:11 +02:00
|
|
|
if ( result !== 1 ) { return; }
|
2015-03-26 00:28:22 +01:00
|
|
|
|
2017-05-12 16:35:11 +02:00
|
|
|
// No log data means no strict blocking (because we need to report why
|
|
|
|
// the blocking occurs.
|
|
|
|
if ( logData === undefined ) { return; }
|
2015-06-12 01:33:30 +02:00
|
|
|
|
2015-03-26 00:28:22 +01:00
|
|
|
// Blocked
|
|
|
|
var query = btoa(JSON.stringify({
|
|
|
|
url: requestURL,
|
2015-03-30 19:10:29 +02:00
|
|
|
hn: requestHostname,
|
2015-04-06 16:26:32 +02:00
|
|
|
dn: requestDomain,
|
2017-05-12 16:35:11 +02:00
|
|
|
fc: logData.compiled,
|
|
|
|
fs: logData.raw
|
2015-03-26 00:28:22 +01:00
|
|
|
}));
|
2015-03-27 18:00:55 +01:00
|
|
|
|
2015-04-09 00:46:08 +02:00
|
|
|
vAPI.tabs.replace(tabId, vAPI.getURL('document-blocked.html?details=') + query);
|
2015-03-27 18:00:55 +01:00
|
|
|
|
|
|
|
return { cancel: true };
|
2015-03-21 21:52:35 +01:00
|
|
|
};
|
|
|
|
|
|
|
|
/******************************************************************************/
|
|
|
|
|
2017-11-08 19:29:04 +01:00
|
|
|
// https://github.com/gorhill/uBlock/issues/3208
|
|
|
|
// Mind case insensitivity.
|
2017-11-09 21:46:25 +01:00
|
|
|
|
2017-05-12 16:35:11 +02:00
|
|
|
var toBlockDocResult = function(url, hostname, logData) {
|
2017-11-09 21:46:25 +01:00
|
|
|
if ( typeof logData.regex !== 'string' ) { return false; }
|
2017-11-08 19:29:04 +01:00
|
|
|
var re = new RegExp(logData.regex, 'i'),
|
2017-05-12 16:35:11 +02:00
|
|
|
match = re.exec(url.toLowerCase());
|
2017-11-08 19:29:04 +01:00
|
|
|
if ( match === null ) { return false; }
|
2015-03-30 23:42:12 +02:00
|
|
|
|
2015-04-08 13:04:29 +02:00
|
|
|
// https://github.com/chrisaljoudi/uBlock/issues/1128
|
|
|
|
// https://github.com/chrisaljoudi/uBlock/issues/1212
|
|
|
|
// Relax the rule: verify that the match is completely before the path part
|
2017-11-09 21:46:25 +01:00
|
|
|
return (match.index + match[0].length) <=
|
|
|
|
(url.indexOf(hostname) + hostname.length + 1);
|
2015-03-30 23:42:12 +02:00
|
|
|
};
|
|
|
|
|
|
|
|
/******************************************************************************/
|
|
|
|
|
2016-10-14 16:06:34 +02:00
|
|
|
// Intercept and filter behind-the-scene requests.
|
|
|
|
|
2016-03-22 15:19:41 +01:00
|
|
|
// https://github.com/gorhill/uBlock/issues/870
|
|
|
|
// Finally, Chromium 49+ gained the ability to report network request of type
|
|
|
|
// `beacon`, so now we can block them according to the state of the
|
|
|
|
// "Disable hyperlink auditing/beacon" setting.
|
|
|
|
|
2015-01-24 18:06:22 +01:00
|
|
|
var onBeforeBehindTheSceneRequest = function(details) {
|
2016-10-14 16:06:34 +02:00
|
|
|
var µb = µBlock,
|
2018-02-26 19:59:16 +01:00
|
|
|
pageStore = µb.pageStoreFromTabId(details.tabId);
|
|
|
|
if ( pageStore === null ) { return; }
|
2016-10-14 16:06:34 +02:00
|
|
|
|
2018-04-02 15:10:38 +02:00
|
|
|
var µburi = µb.URI,
|
|
|
|
context = pageStore.createContextFromPage(),
|
2016-10-14 16:06:34 +02:00
|
|
|
requestType = details.type,
|
|
|
|
requestURL = details.url;
|
2015-01-24 18:06:22 +01:00
|
|
|
|
2016-01-22 17:13:29 +01:00
|
|
|
context.requestURL = requestURL;
|
2018-04-02 15:10:38 +02:00
|
|
|
context.requestHostname = µburi.hostnameFromURI(requestURL);
|
2016-10-14 16:06:34 +02:00
|
|
|
context.requestType = requestType;
|
|
|
|
|
2018-04-02 15:10:38 +02:00
|
|
|
var normalURL;
|
2018-02-26 19:59:16 +01:00
|
|
|
if ( details.tabId === vAPI.anyTabId && context.pageHostname === '' ) {
|
2018-04-02 15:10:38 +02:00
|
|
|
normalURL = µb.normalizePageURL(0, details.documentUrl);
|
|
|
|
context.pageHostname = µburi.hostnameFromURI(normalURL);
|
|
|
|
context.pageDomain = µburi.domainFromHostname(context.pageHostname);
|
2018-02-26 19:59:16 +01:00
|
|
|
context.rootHostname = context.pageHostname;
|
|
|
|
context.rootDomain = context.pageDomain;
|
|
|
|
}
|
|
|
|
|
2018-04-02 15:10:38 +02:00
|
|
|
pageStore.logData = undefined;
|
|
|
|
|
2016-10-17 15:37:59 +02:00
|
|
|
// https://bugs.chromium.org/p/chromium/issues/detail?id=637577#c15
|
|
|
|
// Do not filter behind-the-scene network request of type `beacon`: there
|
|
|
|
// is no point. In any case, this will become a non-issue once
|
|
|
|
// <https://bugs.chromium.org/p/chromium/issues/detail?id=522129> is
|
|
|
|
// fixed.
|
2015-01-24 18:06:22 +01:00
|
|
|
|
|
|
|
// Blocking behind-the-scene requests can break a lot of stuff: prevent
|
|
|
|
// browser updates, prevent extension updates, prevent extensions from
|
|
|
|
// working properly, etc.
|
2017-10-19 15:35:28 +02:00
|
|
|
// So we filter if and only if the "advanced user" mode is selected.
|
|
|
|
// https://github.com/gorhill/uBlock/issues/3150
|
|
|
|
// Ability to globally block CSP reports MUST also apply to
|
|
|
|
// behind-the-scene network requests.
|
2018-03-30 14:55:51 +02:00
|
|
|
|
|
|
|
// 2018-03-30:
|
|
|
|
// Filter all behind-the-scene network requests like any other network
|
|
|
|
// requests. Hopefully this will not break stuff as it used to be the
|
|
|
|
// case.
|
|
|
|
|
2018-04-02 15:10:38 +02:00
|
|
|
var result = 0;
|
|
|
|
|
|
|
|
if (
|
|
|
|
µburi.isNetworkURI(details.documentUrl) ||
|
|
|
|
µb.userSettings.advancedUserEnabled ||
|
|
|
|
requestType === 'csp_report'
|
|
|
|
) {
|
|
|
|
result = pageStore.filterRequest(context);
|
|
|
|
|
|
|
|
// The "any-tab" scope is not whitelist-able, and in such case we must
|
|
|
|
// use the origin URL as the scope. Most such requests aren't going to
|
|
|
|
// be blocked, so we further test for whitelisting and modify the
|
|
|
|
// result only when the request is being blocked.
|
|
|
|
if (
|
|
|
|
result === 1 &&
|
|
|
|
normalURL !== undefined &&
|
|
|
|
µb.getNetFilteringSwitch(normalURL) === false
|
|
|
|
) {
|
|
|
|
result = 2;
|
|
|
|
pageStore.logData = { engine: 'u', result: 2, raw: 'whitelisted' };
|
|
|
|
}
|
|
|
|
}
|
2015-01-24 18:06:22 +01:00
|
|
|
|
2016-10-08 16:15:31 +02:00
|
|
|
pageStore.journalAddRequest(context.requestHostname, result);
|
2015-06-05 01:27:03 +02:00
|
|
|
|
|
|
|
if ( µb.logger.isEnabled() ) {
|
|
|
|
µb.logger.writeOne(
|
2018-02-26 19:59:16 +01:00
|
|
|
details.tabId,
|
2015-06-05 01:27:03 +02:00
|
|
|
'net',
|
2017-05-28 16:53:13 +02:00
|
|
|
pageStore.logData,
|
2016-10-14 16:06:34 +02:00
|
|
|
requestType,
|
2016-01-22 17:13:29 +01:00
|
|
|
requestURL,
|
2015-06-05 01:27:03 +02:00
|
|
|
context.rootHostname,
|
|
|
|
context.rootHostname
|
|
|
|
);
|
|
|
|
}
|
2015-01-24 18:06:22 +01:00
|
|
|
|
2016-07-01 04:03:29 +02:00
|
|
|
context.dispose();
|
|
|
|
|
2017-05-28 19:32:08 +02:00
|
|
|
// Blocked?
|
|
|
|
if ( result === 1 ) {
|
|
|
|
return { 'cancel': true };
|
|
|
|
}
|
2015-01-24 18:06:22 +01:00
|
|
|
};
|
|
|
|
|
|
|
|
/******************************************************************************/
|
|
|
|
|
2017-10-18 21:00:22 +02:00
|
|
|
// https://github.com/gorhill/uBlock/issues/3140
|
|
|
|
|
|
|
|
var onBeforeMaybeSpuriousCSPReport = function(details) {
|
|
|
|
var tabId = details.tabId;
|
|
|
|
|
|
|
|
// Ignore behind-the-scene requests.
|
|
|
|
if ( vAPI.isBehindTheSceneTabId(tabId) ) { return; }
|
|
|
|
|
|
|
|
// Lookup the page store associated with this tab id.
|
|
|
|
var µb = µBlock,
|
|
|
|
pageStore = µb.pageStoreFromTabId(tabId);
|
|
|
|
if ( pageStore === null ) { return; }
|
|
|
|
|
|
|
|
// If uBO is disabled for the page, it can't possibly causes CSP reports
|
|
|
|
// to be triggered.
|
|
|
|
if ( pageStore.getNetFilteringSwitch() === false ) { return; }
|
|
|
|
|
|
|
|
// A resource was redirected to a neutered one?
|
|
|
|
// TODO: mind injected scripts/styles as well.
|
|
|
|
if ( pageStore.internalRedirectionCount === 0 ) { return; }
|
|
|
|
|
|
|
|
var textDecoder = onBeforeMaybeSpuriousCSPReport.textDecoder;
|
|
|
|
if (
|
|
|
|
textDecoder === undefined &&
|
|
|
|
typeof self.TextDecoder === 'function'
|
|
|
|
) {
|
|
|
|
textDecoder =
|
|
|
|
onBeforeMaybeSpuriousCSPReport.textDecoder = new TextDecoder();
|
|
|
|
}
|
|
|
|
|
|
|
|
// Find out whether the CSP report is a potentially spurious CSP report.
|
|
|
|
// If from this point on we are unable to parse the CSP report data, the
|
|
|
|
// safest assumption to protect users is to assume the CSP report is
|
|
|
|
// spurious.
|
|
|
|
if (
|
|
|
|
textDecoder !== undefined &&
|
|
|
|
details.method === 'POST'
|
|
|
|
) {
|
|
|
|
var raw = details.requestBody && details.requestBody.raw;
|
|
|
|
if (
|
|
|
|
Array.isArray(raw) &&
|
|
|
|
raw.length !== 0 &&
|
|
|
|
raw[0] instanceof Object &&
|
|
|
|
raw[0].bytes instanceof ArrayBuffer
|
|
|
|
) {
|
|
|
|
var data;
|
|
|
|
try {
|
|
|
|
data = JSON.parse(textDecoder.decode(raw[0].bytes));
|
|
|
|
} catch (ex) {
|
|
|
|
}
|
|
|
|
if ( data instanceof Object ) {
|
|
|
|
var report = data['csp-report'];
|
|
|
|
if ( report instanceof Object ) {
|
2017-10-19 14:07:00 +02:00
|
|
|
var blocked = report['blocked-uri'] || report['blockedURI'],
|
|
|
|
validBlocked = typeof blocked === 'string',
|
|
|
|
source = report['source-file'] || report['sourceFile'],
|
|
|
|
validSource = typeof source === 'string';
|
2017-10-18 21:00:22 +02:00
|
|
|
if (
|
2017-10-19 14:07:00 +02:00
|
|
|
(validBlocked || validSource) &&
|
|
|
|
(!validBlocked || !blocked.startsWith('data')) &&
|
|
|
|
(!validSource || !source.startsWith('data'))
|
2017-10-18 21:00:22 +02:00
|
|
|
) {
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// Potentially spurious CSP report.
|
|
|
|
if ( µb.logger.isEnabled() ) {
|
|
|
|
var hostname = µb.URI.hostnameFromURI(details.url);
|
|
|
|
µb.logger.writeOne(
|
|
|
|
tabId,
|
|
|
|
'net',
|
|
|
|
{ result: 1, source: 'global', raw: 'no-spurious-csp-report' },
|
|
|
|
'csp_report',
|
|
|
|
details.url,
|
|
|
|
hostname,
|
|
|
|
hostname
|
|
|
|
);
|
|
|
|
}
|
|
|
|
|
|
|
|
return { cancel: true };
|
|
|
|
};
|
|
|
|
|
|
|
|
onBeforeMaybeSpuriousCSPReport.textDecoder = undefined;
|
|
|
|
|
|
|
|
/******************************************************************************/
|
|
|
|
|
2016-01-17 19:30:43 +01:00
|
|
|
// To handle:
|
2017-12-28 19:49:02 +01:00
|
|
|
// - Media elements larger than n kB
|
|
|
|
// - Scriptlet injection (requires ability to modify response body)
|
|
|
|
// - HTML filtering (requires ability to modify response body)
|
|
|
|
// - CSP injection
|
2014-09-24 23:38:22 +02:00
|
|
|
|
|
|
|
var onHeadersReceived = function(details) {
|
|
|
|
// Do not interfere with behind-the-scene requests.
|
2018-05-16 17:50:50 +02:00
|
|
|
let tabId = details.tabId;
|
2017-01-18 00:18:28 +01:00
|
|
|
if ( vAPI.isBehindTheSceneTabId(tabId) ) { return; }
|
2014-09-24 23:38:22 +02:00
|
|
|
|
2018-05-16 17:50:50 +02:00
|
|
|
let µb = µBlock,
|
2017-12-28 19:49:02 +01:00
|
|
|
requestType = details.type,
|
|
|
|
isRootDoc = requestType === 'main_frame',
|
|
|
|
isDoc = isRootDoc || requestType === 'sub_frame';
|
2015-11-09 23:59:19 +01:00
|
|
|
|
2017-12-28 19:49:02 +01:00
|
|
|
if ( isRootDoc ) {
|
2017-01-18 00:18:28 +01:00
|
|
|
µb.tabContextManager.push(tabId, details.url);
|
2015-06-11 21:11:01 +02:00
|
|
|
}
|
2016-01-17 19:30:43 +01:00
|
|
|
|
2018-05-16 17:50:50 +02:00
|
|
|
let pageStore = µb.pageStoreFromTabId(tabId);
|
2017-01-18 00:18:28 +01:00
|
|
|
if ( pageStore === null ) {
|
2017-12-28 19:49:02 +01:00
|
|
|
if ( isRootDoc === false ) { return; }
|
2015-11-09 23:59:19 +01:00
|
|
|
pageStore = µb.bindTabToPageStats(tabId, 'beforeRequest');
|
2014-09-24 23:38:22 +02:00
|
|
|
}
|
2017-01-18 00:18:28 +01:00
|
|
|
if ( pageStore.getNetFilteringSwitch() === false ) { return; }
|
2015-04-09 00:46:08 +02:00
|
|
|
|
2017-01-18 00:18:28 +01:00
|
|
|
if ( requestType === 'image' || requestType === 'media' ) {
|
|
|
|
return foilLargeMediaElement(pageStore, details);
|
2015-04-09 00:46:08 +02:00
|
|
|
}
|
|
|
|
|
2018-05-16 17:50:50 +02:00
|
|
|
if ( isDoc === false ) { return; }
|
|
|
|
|
|
|
|
// Keep in mind response headers will be modified in-place if needed, so
|
|
|
|
// `details.responseHeaders` will always point to the modified response
|
|
|
|
// headers.
|
|
|
|
let responseHeaders = details.responseHeaders;
|
2017-12-28 19:49:02 +01:00
|
|
|
|
2017-07-22 22:58:08 +02:00
|
|
|
// https://github.com/gorhill/uBlock/issues/2813
|
|
|
|
// Disable the blocking of large media elements if the document is itself
|
|
|
|
// a media element: the resource was not prevented from loading so no
|
|
|
|
// point to further block large media elements for the current document.
|
2017-12-28 19:49:02 +01:00
|
|
|
if ( isRootDoc ) {
|
2018-05-16 17:50:50 +02:00
|
|
|
let contentType = headerValueFromName('content-type', responseHeaders);
|
|
|
|
if ( reMediaContentTypes.test(contentType) ) {
|
2017-07-22 22:58:08 +02:00
|
|
|
pageStore.allowLargeMediaElementsUntil = Date.now() + 86400000;
|
2018-05-16 17:50:50 +02:00
|
|
|
return;
|
2017-07-22 22:58:08 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2018-05-16 17:50:50 +02:00
|
|
|
// At this point we have a HTML document.
|
|
|
|
|
|
|
|
let filteredHTML = µb.canFilterResponseBody &&
|
|
|
|
filterDocument(pageStore, details) === true;
|
|
|
|
|
|
|
|
let modifiedHeaders = injectCSP(pageStore, details) === true;
|
|
|
|
|
|
|
|
// https://bugzilla.mozilla.org/show_bug.cgi?id=1376932
|
|
|
|
// Prevent document from being cached by the browser if we modified it,
|
|
|
|
// either through HTML filtering and/or modified response headers.
|
|
|
|
if ( (filteredHTML || modifiedHeaders) && dontCacheResponseHeaders ) {
|
|
|
|
let i = headerIndexFromName('cache-control', responseHeaders);
|
|
|
|
if ( i !== -1 ) {
|
|
|
|
responseHeaders[i].value = 'no-cache, no-store, must-revalidate';
|
|
|
|
} else {
|
|
|
|
responseHeaders[responseHeaders.length] = {
|
|
|
|
name: 'Cache-Control',
|
|
|
|
value: 'no-cache, no-store, must-revalidate'
|
|
|
|
};
|
|
|
|
}
|
|
|
|
modifiedHeaders = true;
|
|
|
|
}
|
|
|
|
|
|
|
|
if ( modifiedHeaders ) {
|
|
|
|
return { responseHeaders: responseHeaders };
|
2017-01-18 00:18:28 +01:00
|
|
|
}
|
2016-08-27 17:08:56 +02:00
|
|
|
};
|
|
|
|
|
2017-07-22 22:58:08 +02:00
|
|
|
var reMediaContentTypes = /^(?:audio|image|video)\//;
|
|
|
|
|
2017-12-28 19:49:02 +01:00
|
|
|
/*******************************************************************************
|
|
|
|
|
|
|
|
The response body filterer is responsible for:
|
|
|
|
|
|
|
|
- HTML filtering
|
|
|
|
|
|
|
|
In the spirit of efficiency, the response body filterer works this way:
|
|
|
|
|
|
|
|
If:
|
|
|
|
- HTML filtering: no.
|
|
|
|
Then:
|
|
|
|
No response body filtering is initiated.
|
|
|
|
|
|
|
|
If:
|
|
|
|
- HTML filtering: yes.
|
|
|
|
Then:
|
|
|
|
Assemble all response body data into a single buffer. Once all the
|
|
|
|
response data has been received, create a document from it. Then:
|
|
|
|
- Remove all DOM elements matching HTML filters.
|
|
|
|
Then serialize the resulting modified document as the new response
|
|
|
|
body.
|
|
|
|
|
|
|
|
**/
|
|
|
|
|
|
|
|
var filterDocument = (function() {
|
|
|
|
var µb = µBlock,
|
|
|
|
filterers = new Map(),
|
|
|
|
domParser, xmlSerializer,
|
2018-01-05 19:15:56 +01:00
|
|
|
utf8TextDecoder, textDecoder, textEncoder;
|
2017-12-28 19:49:02 +01:00
|
|
|
|
2018-02-18 13:16:10 +01:00
|
|
|
var textDecode = function(encoding, buffer) {
|
|
|
|
if (
|
|
|
|
textDecoder !== undefined &&
|
|
|
|
textDecoder.encoding !== encoding
|
|
|
|
) {
|
|
|
|
textDecoder = undefined;
|
|
|
|
}
|
|
|
|
if ( textDecoder === undefined ) {
|
|
|
|
textDecoder = new TextDecoder(encoding);
|
|
|
|
}
|
|
|
|
return textDecoder.decode(buffer);
|
|
|
|
};
|
|
|
|
|
2018-03-01 20:12:16 +01:00
|
|
|
var reContentTypeDocument = /^(?:text\/html|application\/xhtml\+xml)/i,
|
2018-01-03 19:59:38 +01:00
|
|
|
reContentTypeCharset = /charset=['"]?([^'" ]+)/i;
|
|
|
|
|
2018-03-01 20:12:16 +01:00
|
|
|
var mimeFromContentType = function(contentType) {
|
|
|
|
var match = reContentTypeDocument.exec(contentType);
|
|
|
|
if ( match !== null ) {
|
|
|
|
return match[0].toLowerCase();
|
|
|
|
}
|
|
|
|
};
|
|
|
|
|
2018-01-05 00:26:52 +01:00
|
|
|
var charsetFromContentType = function(contentType) {
|
|
|
|
var match = reContentTypeCharset.exec(contentType);
|
|
|
|
if ( match !== null ) {
|
|
|
|
return match[1].toLowerCase();
|
|
|
|
}
|
|
|
|
};
|
|
|
|
|
|
|
|
var charsetFromDoc = function(doc) {
|
|
|
|
var meta = doc.querySelector('meta[charset]');
|
|
|
|
if ( meta !== null ) {
|
|
|
|
return meta.getAttribute('charset').toLowerCase();
|
|
|
|
}
|
|
|
|
meta = doc.querySelector(
|
|
|
|
'meta[http-equiv="content-type" i][content]'
|
|
|
|
);
|
|
|
|
if ( meta !== null ) {
|
|
|
|
return charsetFromContentType(meta.getAttribute('content'));
|
|
|
|
}
|
|
|
|
};
|
|
|
|
|
2017-12-28 19:49:02 +01:00
|
|
|
var streamClose = function(filterer, buffer) {
|
|
|
|
if ( buffer !== undefined ) {
|
|
|
|
filterer.stream.write(buffer);
|
|
|
|
} else if ( filterer.buffer !== undefined ) {
|
|
|
|
filterer.stream.write(filterer.buffer);
|
|
|
|
}
|
|
|
|
filterer.stream.close();
|
|
|
|
};
|
|
|
|
|
|
|
|
var onStreamData = function(ev) {
|
|
|
|
var filterer = filterers.get(this);
|
|
|
|
if ( filterer === undefined ) {
|
|
|
|
this.write(ev.data);
|
|
|
|
this.disconnect();
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
if (
|
|
|
|
this.status !== 'transferringdata' &&
|
|
|
|
this.status !== 'finishedtransferringdata'
|
|
|
|
) {
|
|
|
|
filterers.delete(this);
|
|
|
|
this.disconnect();
|
|
|
|
return;
|
|
|
|
}
|
2017-12-30 17:21:23 +01:00
|
|
|
// TODO:
|
|
|
|
// - Possibly improve buffer growth, if benchmarking shows it's worth
|
|
|
|
// it.
|
|
|
|
// - Also evaluate whether keeping a list of buffers and then decoding
|
|
|
|
// them in sequence using TextDecoder's "stream" option is more
|
|
|
|
// efficient. Can the data buffers be safely kept around for later
|
|
|
|
// use?
|
|
|
|
// - Informal, quick benchmarks seem to show most of the overhead is
|
|
|
|
// from calling TextDecoder.decode() and TextEncoder.encode(), and if
|
|
|
|
// confirmed, there is nothing which can be done uBO-side to reduce
|
|
|
|
// overhead.
|
2017-12-28 19:49:02 +01:00
|
|
|
if ( filterer.buffer === null ) {
|
|
|
|
filterer.buffer = new Uint8Array(ev.data);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
var buffer = new Uint8Array(
|
|
|
|
filterer.buffer.byteLength +
|
|
|
|
ev.data.byteLength
|
|
|
|
);
|
|
|
|
buffer.set(filterer.buffer);
|
|
|
|
buffer.set(new Uint8Array(ev.data), filterer.buffer.byteLength);
|
|
|
|
filterer.buffer = buffer;
|
|
|
|
};
|
|
|
|
|
|
|
|
var onStreamStop = function() {
|
|
|
|
var filterer = filterers.get(this);
|
|
|
|
filterers.delete(this);
|
|
|
|
if ( filterer === undefined || filterer.buffer === null ) {
|
|
|
|
this.close();
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
if ( this.status !== 'finishedtransferringdata' ) { return; }
|
|
|
|
|
|
|
|
if ( domParser === undefined ) {
|
|
|
|
domParser = new DOMParser();
|
|
|
|
xmlSerializer = new XMLSerializer();
|
|
|
|
}
|
|
|
|
if ( textEncoder === undefined ) {
|
|
|
|
textEncoder = new TextEncoder();
|
|
|
|
}
|
|
|
|
|
2018-01-05 19:15:56 +01:00
|
|
|
var doc;
|
|
|
|
|
|
|
|
// If stream encoding is still unknnown, try to extract from document.
|
2018-02-18 13:16:10 +01:00
|
|
|
var charsetFound = filterer.charset,
|
|
|
|
charsetUsed = charsetFound;
|
|
|
|
if ( charsetFound === undefined ) {
|
2018-01-05 19:15:56 +01:00
|
|
|
if ( utf8TextDecoder === undefined ) {
|
|
|
|
utf8TextDecoder = new TextDecoder();
|
|
|
|
}
|
|
|
|
doc = domParser.parseFromString(
|
2018-02-18 13:16:10 +01:00
|
|
|
utf8TextDecoder.decode(filterer.buffer.slice(0, 1024)),
|
2018-03-01 20:12:16 +01:00
|
|
|
filterer.mime
|
2018-01-05 19:15:56 +01:00
|
|
|
);
|
2018-02-18 13:16:10 +01:00
|
|
|
charsetFound = charsetFromDoc(doc);
|
|
|
|
charsetUsed = µb.textEncode.normalizeCharset(charsetFound);
|
|
|
|
if ( charsetUsed === undefined ) {
|
|
|
|
return streamClose(filterer);
|
2018-01-05 19:15:56 +01:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
doc = domParser.parseFromString(
|
2018-02-18 13:16:10 +01:00
|
|
|
textDecode(charsetUsed, filterer.buffer),
|
2018-03-01 20:12:16 +01:00
|
|
|
filterer.mime
|
2017-12-28 19:49:02 +01:00
|
|
|
);
|
|
|
|
|
2018-02-18 13:16:10 +01:00
|
|
|
// https://github.com/gorhill/uBlock/issues/3507
|
|
|
|
// In case of no explicit charset found, try to find one again, but
|
|
|
|
// this time with the whole document parsed.
|
|
|
|
if ( charsetFound === undefined ) {
|
|
|
|
charsetFound = µb.textEncode.normalizeCharset(charsetFromDoc(doc));
|
|
|
|
if ( charsetFound !== charsetUsed ) {
|
|
|
|
if ( charsetFound === undefined ) {
|
|
|
|
return streamClose(filterer);
|
|
|
|
}
|
|
|
|
charsetUsed = charsetFound;
|
|
|
|
doc = domParser.parseFromString(
|
|
|
|
textDecode(charsetFound, filterer.buffer),
|
2018-03-01 20:12:16 +01:00
|
|
|
filterer.mime
|
2018-02-18 13:16:10 +01:00
|
|
|
);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2017-12-28 19:49:02 +01:00
|
|
|
var modified = false;
|
|
|
|
if ( filterer.selectors !== undefined ) {
|
|
|
|
if ( µb.htmlFilteringEngine.apply(doc, filterer) ) {
|
|
|
|
modified = true;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if ( modified === false ) {
|
2018-02-18 13:16:10 +01:00
|
|
|
return streamClose(filterer);
|
2017-12-28 19:49:02 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
// https://stackoverflow.com/questions/6088972/get-doctype-of-an-html-as-string-with-javascript/10162353#10162353
|
|
|
|
var doctypeStr = doc.doctype instanceof Object ?
|
|
|
|
xmlSerializer.serializeToString(doc.doctype) + '\n' :
|
|
|
|
'';
|
|
|
|
|
2018-01-03 05:06:16 +01:00
|
|
|
// https://github.com/gorhill/uBlock/issues/3391
|
|
|
|
var encodedStream = textEncoder.encode(
|
|
|
|
doctypeStr +
|
|
|
|
doc.documentElement.outerHTML
|
2017-12-28 19:49:02 +01:00
|
|
|
);
|
2018-02-18 13:16:10 +01:00
|
|
|
if ( charsetUsed !== 'utf-8' ) {
|
2018-01-03 05:06:16 +01:00
|
|
|
encodedStream = µb.textEncode.encode(
|
2018-02-18 13:16:10 +01:00
|
|
|
charsetUsed,
|
2018-01-03 05:06:16 +01:00
|
|
|
encodedStream
|
|
|
|
);
|
|
|
|
}
|
|
|
|
|
|
|
|
streamClose(filterer, encodedStream);
|
2017-12-28 19:49:02 +01:00
|
|
|
};
|
|
|
|
|
|
|
|
var onStreamError = function() {
|
|
|
|
filterers.delete(this);
|
|
|
|
};
|
|
|
|
|
2018-01-03 19:59:38 +01:00
|
|
|
return function(pageStore, details) {
|
2018-02-03 15:34:27 +01:00
|
|
|
// https://github.com/gorhill/uBlock/issues/3478
|
|
|
|
var statusCode = details.statusCode || 0;
|
|
|
|
if ( statusCode !== 0 && (statusCode < 200 || statusCode >= 300) ) {
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
2017-12-28 19:49:02 +01:00
|
|
|
var hostname = µb.URI.hostnameFromURI(details.url);
|
|
|
|
if ( hostname === '' ) { return; }
|
|
|
|
|
|
|
|
var domain = µb.URI.domainFromHostname(hostname);
|
|
|
|
|
|
|
|
var request = {
|
|
|
|
stream: undefined,
|
|
|
|
tabId: details.tabId,
|
|
|
|
url: details.url,
|
|
|
|
hostname: hostname,
|
|
|
|
domain: domain,
|
|
|
|
entity: µb.URI.entityFromDomain(domain),
|
|
|
|
selectors: undefined,
|
|
|
|
buffer: null,
|
2018-04-03 00:40:29 +02:00
|
|
|
mime: 'text/html',
|
2017-12-28 19:49:02 +01:00
|
|
|
charset: undefined
|
|
|
|
};
|
2018-02-21 14:19:43 +01:00
|
|
|
|
2018-02-23 15:45:51 +01:00
|
|
|
request.selectors = µb.htmlFilteringEngine.retrieve(request);
|
2018-04-24 23:12:41 +02:00
|
|
|
if ( request.selectors === undefined ) { return; }
|
2017-12-28 19:49:02 +01:00
|
|
|
|
|
|
|
var headers = details.responseHeaders,
|
|
|
|
contentType = headerValueFromName('content-type', headers);
|
|
|
|
if ( contentType !== '' ) {
|
2018-03-01 20:12:16 +01:00
|
|
|
request.mime = mimeFromContentType(contentType);
|
|
|
|
if ( request.mime === undefined ) { return; }
|
2018-01-05 00:26:52 +01:00
|
|
|
var charset = charsetFromContentType(contentType);
|
|
|
|
if ( charset !== undefined ) {
|
|
|
|
charset = µb.textEncode.normalizeCharset(charset);
|
2018-01-03 19:59:38 +01:00
|
|
|
if ( charset === undefined ) { return; }
|
2018-01-05 00:26:52 +01:00
|
|
|
request.charset = charset;
|
2017-12-28 19:49:02 +01:00
|
|
|
}
|
|
|
|
}
|
|
|
|
// https://bugzilla.mozilla.org/show_bug.cgi?id=1426789
|
|
|
|
if ( headerValueFromName('content-disposition', headers) ) { return; }
|
|
|
|
|
|
|
|
var stream = request.stream =
|
|
|
|
vAPI.net.webRequest.filterResponseData(details.requestId);
|
|
|
|
stream.ondata = onStreamData;
|
|
|
|
stream.onstop = onStreamStop;
|
|
|
|
stream.onerror = onStreamError;
|
|
|
|
filterers.set(stream, request);
|
2018-05-16 17:50:50 +02:00
|
|
|
|
|
|
|
return true;
|
2017-12-28 19:49:02 +01:00
|
|
|
};
|
|
|
|
})();
|
|
|
|
|
2016-08-27 17:08:56 +02:00
|
|
|
/******************************************************************************/
|
|
|
|
|
2017-05-12 16:35:11 +02:00
|
|
|
var injectCSP = function(pageStore, details) {
|
2018-05-16 17:50:50 +02:00
|
|
|
let µb = µBlock,
|
2016-08-27 17:08:56 +02:00
|
|
|
tabId = details.tabId,
|
|
|
|
requestURL = details.url,
|
2017-05-12 16:35:11 +02:00
|
|
|
loggerEnabled = µb.logger.isEnabled(),
|
|
|
|
logger = µb.logger,
|
|
|
|
cspSubsets = [];
|
2016-08-27 17:08:56 +02:00
|
|
|
|
2018-05-16 17:50:50 +02:00
|
|
|
let context = pageStore.createContextFromPage();
|
2016-01-22 17:13:29 +01:00
|
|
|
context.requestHostname = µb.URI.hostnameFromURI(requestURL);
|
2017-01-18 00:18:28 +01:00
|
|
|
if ( details.type !== 'main_frame' ) {
|
|
|
|
context.pageHostname = context.pageDomain = context.requestHostname;
|
|
|
|
}
|
2017-09-11 15:53:42 +02:00
|
|
|
context.requestURL = requestURL;
|
2015-01-24 18:06:22 +01:00
|
|
|
|
2017-05-12 16:35:11 +02:00
|
|
|
// Start collecting policies >>>>>>>>
|
|
|
|
|
|
|
|
// ======== built-in policies
|
|
|
|
|
2018-05-16 17:50:50 +02:00
|
|
|
let builtinDirectives = [];
|
2017-09-11 15:53:42 +02:00
|
|
|
|
2017-05-12 16:35:11 +02:00
|
|
|
context.requestType = 'inline-script';
|
2017-08-03 16:18:05 +02:00
|
|
|
if ( pageStore.filterRequest(context) === 1 ) {
|
2017-09-11 15:53:42 +02:00
|
|
|
builtinDirectives.push("script-src 'unsafe-eval' * blob: data:");
|
2017-05-12 16:35:11 +02:00
|
|
|
}
|
|
|
|
if ( loggerEnabled === true ) {
|
|
|
|
logger.writeOne(
|
|
|
|
tabId,
|
|
|
|
'net',
|
|
|
|
pageStore.logData,
|
|
|
|
'inline-script',
|
|
|
|
requestURL,
|
|
|
|
context.rootHostname,
|
|
|
|
context.pageHostname
|
2016-08-27 17:08:56 +02:00
|
|
|
);
|
|
|
|
}
|
2015-06-05 01:27:03 +02:00
|
|
|
|
2017-09-11 15:53:42 +02:00
|
|
|
// https://github.com/gorhill/uBlock/issues/1539
|
|
|
|
// - Use a CSP to also forbid inline fonts if remote fonts are blocked.
|
|
|
|
context.requestType = 'inline-font';
|
|
|
|
if ( pageStore.filterRequest(context) === 1 ) {
|
|
|
|
builtinDirectives.push('font-src *');
|
|
|
|
if ( loggerEnabled === true ) {
|
|
|
|
logger.writeOne(
|
|
|
|
tabId,
|
|
|
|
'net',
|
|
|
|
pageStore.logData,
|
|
|
|
'inline-font',
|
|
|
|
requestURL,
|
|
|
|
context.rootHostname,
|
|
|
|
context.pageHostname
|
|
|
|
);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if ( builtinDirectives.length !== 0 ) {
|
|
|
|
cspSubsets[0] = builtinDirectives.join('; ');
|
|
|
|
}
|
|
|
|
|
2017-05-12 16:35:11 +02:00
|
|
|
// ======== filter-based policies
|
|
|
|
|
|
|
|
// Static filtering.
|
|
|
|
|
2018-05-16 17:50:50 +02:00
|
|
|
let logDataEntries = [];
|
2017-05-12 16:35:11 +02:00
|
|
|
|
|
|
|
µb.staticNetFilteringEngine.matchAndFetchData(
|
|
|
|
'csp',
|
|
|
|
requestURL,
|
|
|
|
cspSubsets,
|
2017-05-17 15:25:11 +02:00
|
|
|
loggerEnabled === true ? logDataEntries : undefined
|
2017-05-12 16:35:11 +02:00
|
|
|
);
|
|
|
|
|
|
|
|
// URL filtering `allow` rules override static filtering.
|
|
|
|
if (
|
|
|
|
cspSubsets.length !== 0 &&
|
|
|
|
µb.sessionURLFiltering.evaluateZ(context.rootHostname, requestURL, 'csp') === 2
|
|
|
|
) {
|
|
|
|
if ( loggerEnabled === true ) {
|
|
|
|
logger.writeOne(
|
2017-01-18 00:18:28 +01:00
|
|
|
tabId,
|
|
|
|
'net',
|
2017-05-12 16:35:11 +02:00
|
|
|
µb.sessionURLFiltering.toLogData(),
|
|
|
|
'csp',
|
2017-01-18 00:18:28 +01:00
|
|
|
requestURL,
|
|
|
|
context.rootHostname,
|
|
|
|
context.pageHostname
|
|
|
|
);
|
|
|
|
}
|
2017-05-17 15:25:11 +02:00
|
|
|
context.dispose();
|
2017-05-12 16:35:11 +02:00
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
2017-05-17 15:25:11 +02:00
|
|
|
// Dynamic filtering `allow` rules override static filtering.
|
2017-05-12 16:35:11 +02:00
|
|
|
if (
|
|
|
|
cspSubsets.length !== 0 &&
|
|
|
|
µb.userSettings.advancedUserEnabled &&
|
|
|
|
µb.sessionFirewall.evaluateCellZY(context.rootHostname, context.rootHostname, '*') === 2
|
|
|
|
) {
|
|
|
|
if ( loggerEnabled === true ) {
|
|
|
|
logger.writeOne(
|
2017-02-06 21:34:31 +01:00
|
|
|
tabId,
|
|
|
|
'net',
|
2017-05-12 16:35:11 +02:00
|
|
|
µb.sessionFirewall.toLogData(),
|
|
|
|
'csp',
|
2017-02-06 21:34:31 +01:00
|
|
|
requestURL,
|
|
|
|
context.rootHostname,
|
|
|
|
context.pageHostname
|
|
|
|
);
|
|
|
|
}
|
2017-05-17 15:25:11 +02:00
|
|
|
context.dispose();
|
2017-05-12 16:35:11 +02:00
|
|
|
return;
|
2016-08-27 17:08:56 +02:00
|
|
|
}
|
|
|
|
|
2017-05-17 15:25:11 +02:00
|
|
|
// <<<<<<<< All policies have been collected
|
|
|
|
|
2017-05-12 16:35:11 +02:00
|
|
|
// Static CSP policies will be applied.
|
2018-05-16 17:50:50 +02:00
|
|
|
for ( let entry of logDataEntries ) {
|
2017-05-12 16:35:11 +02:00
|
|
|
logger.writeOne(
|
|
|
|
tabId,
|
|
|
|
'net',
|
2017-05-17 15:25:11 +02:00
|
|
|
entry,
|
2017-05-12 16:35:11 +02:00
|
|
|
'csp',
|
|
|
|
requestURL,
|
|
|
|
context.rootHostname,
|
|
|
|
context.pageHostname
|
|
|
|
);
|
|
|
|
}
|
2016-07-01 04:03:29 +02:00
|
|
|
|
2017-05-17 15:25:11 +02:00
|
|
|
context.dispose();
|
|
|
|
|
2017-05-12 16:35:11 +02:00
|
|
|
if ( cspSubsets.length === 0 ) {
|
|
|
|
return;
|
|
|
|
}
|
2014-09-24 23:38:22 +02:00
|
|
|
|
2018-05-08 15:43:25 +02:00
|
|
|
µb.updateToolbarIcon(tabId, 0x02);
|
2014-09-24 23:38:22 +02:00
|
|
|
|
2018-03-13 22:24:07 +01:00
|
|
|
// Use comma to merge CSP directives.
|
2017-05-12 16:35:11 +02:00
|
|
|
// Ref.: https://www.w3.org/TR/CSP2/#implementation-considerations
|
2018-03-13 22:24:07 +01:00
|
|
|
//
|
|
|
|
// https://github.com/gorhill/uMatrix/issues/967
|
2018-03-14 17:06:49 +01:00
|
|
|
// Inject a new CSP header rather than modify an existing one, except
|
|
|
|
// if the current environment does not support merging headers:
|
|
|
|
// Firefox 58/webext and less can't merge CSP headers, so we will merge
|
|
|
|
// them here.
|
2018-05-16 17:50:50 +02:00
|
|
|
let headers = details.responseHeaders;
|
2018-03-14 17:06:49 +01:00
|
|
|
|
|
|
|
if ( cantMergeCSPHeaders ) {
|
2018-05-16 17:50:50 +02:00
|
|
|
let i = headerIndexFromName('content-security-policy', headers);
|
2018-03-14 17:06:49 +01:00
|
|
|
if ( i !== -1 ) {
|
|
|
|
cspSubsets.unshift(headers[i].value.trim());
|
|
|
|
headers.splice(i, 1);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
headers.push({
|
2017-05-12 16:35:11 +02:00
|
|
|
name: 'Content-Security-Policy',
|
2018-03-13 22:24:07 +01:00
|
|
|
value: cspSubsets.join(', ')
|
2017-05-12 16:35:11 +02:00
|
|
|
});
|
|
|
|
|
2018-05-16 17:50:50 +02:00
|
|
|
return true;
|
2018-04-04 18:42:01 +02:00
|
|
|
};
|
|
|
|
|
2015-08-13 22:03:37 +02:00
|
|
|
/******************************************************************************/
|
|
|
|
|
2016-01-17 19:30:43 +01:00
|
|
|
// https://github.com/gorhill/uBlock/issues/1163
|
2016-11-08 21:53:08 +01:00
|
|
|
// "Block elements by size"
|
2016-01-17 19:30:43 +01:00
|
|
|
|
2017-01-18 00:18:28 +01:00
|
|
|
var foilLargeMediaElement = function(pageStore, details) {
|
2016-01-17 19:30:43 +01:00
|
|
|
var µb = µBlock;
|
2016-11-08 21:53:08 +01:00
|
|
|
|
2016-01-18 06:26:29 +01:00
|
|
|
var i = headerIndexFromName('content-length', details.responseHeaders);
|
2016-11-08 21:53:08 +01:00
|
|
|
if ( i === -1 ) { return; }
|
|
|
|
|
|
|
|
var tabId = details.tabId,
|
2017-01-18 00:18:28 +01:00
|
|
|
size = parseInt(details.responseHeaders[i].value, 10) || 0,
|
2016-11-08 21:53:08 +01:00
|
|
|
result = pageStore.filterLargeMediaElement(size);
|
2017-05-12 16:35:11 +02:00
|
|
|
if ( result === 0 ) { return; }
|
2016-01-17 19:30:43 +01:00
|
|
|
|
|
|
|
if ( µb.logger.isEnabled() ) {
|
|
|
|
µb.logger.writeOne(
|
|
|
|
tabId,
|
|
|
|
'net',
|
2017-05-12 16:35:11 +02:00
|
|
|
pageStore.logData,
|
2016-01-17 19:30:43 +01:00
|
|
|
details.type,
|
|
|
|
details.url,
|
|
|
|
pageStore.tabHostname,
|
|
|
|
pageStore.tabHostname
|
|
|
|
);
|
|
|
|
}
|
|
|
|
|
|
|
|
return { cancel: true };
|
|
|
|
};
|
|
|
|
|
|
|
|
/******************************************************************************/
|
|
|
|
|
2015-08-13 22:03:37 +02:00
|
|
|
// Caller must ensure headerName is normalized to lower case.
|
|
|
|
|
|
|
|
var headerIndexFromName = function(headerName, headers) {
|
|
|
|
var i = headers.length;
|
|
|
|
while ( i-- ) {
|
|
|
|
if ( headers[i].name.toLowerCase() === headerName ) {
|
|
|
|
return i;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return -1;
|
2014-09-24 23:38:22 +02:00
|
|
|
};
|
|
|
|
|
2017-07-22 22:58:08 +02:00
|
|
|
var headerValueFromName = function(headerName, headers) {
|
|
|
|
var i = headerIndexFromName(headerName, headers);
|
|
|
|
return i !== -1 ? headers[i].value : '';
|
|
|
|
};
|
|
|
|
|
2014-09-24 23:38:22 +02:00
|
|
|
/******************************************************************************/
|
|
|
|
|
2014-10-17 21:44:19 +02:00
|
|
|
vAPI.net.onBeforeRequest = {
|
|
|
|
urls: [
|
|
|
|
'http://*/*',
|
2017-03-06 23:53:25 +01:00
|
|
|
'https://*/*'
|
2014-10-17 21:44:19 +02:00
|
|
|
],
|
|
|
|
extra: [ 'blocking' ],
|
|
|
|
callback: onBeforeRequest
|
|
|
|
};
|
|
|
|
|
2017-10-18 21:00:22 +02:00
|
|
|
vAPI.net.onBeforeMaybeSpuriousCSPReport = {
|
|
|
|
callback: onBeforeMaybeSpuriousCSPReport
|
|
|
|
};
|
|
|
|
|
2014-10-17 21:44:19 +02:00
|
|
|
vAPI.net.onHeadersReceived = {
|
|
|
|
urls: [
|
|
|
|
'http://*/*',
|
|
|
|
'https://*/*'
|
|
|
|
],
|
|
|
|
types: [
|
2016-01-17 19:30:43 +01:00
|
|
|
'main_frame',
|
|
|
|
'sub_frame',
|
|
|
|
'image',
|
2017-05-12 16:35:11 +02:00
|
|
|
'media'
|
2014-10-17 21:44:19 +02:00
|
|
|
],
|
|
|
|
extra: [ 'blocking', 'responseHeaders' ],
|
|
|
|
callback: onHeadersReceived
|
|
|
|
};
|
|
|
|
|
|
|
|
vAPI.net.registerListeners();
|
2014-09-24 23:38:22 +02:00
|
|
|
|
2014-06-24 00:42:43 +02:00
|
|
|
/******************************************************************************/
|
|
|
|
|
2015-04-06 16:26:32 +02:00
|
|
|
var isTemporarilyWhitelisted = function(result, hostname) {
|
|
|
|
var obsolete, pos;
|
|
|
|
|
|
|
|
for (;;) {
|
|
|
|
obsolete = documentWhitelists[hostname];
|
|
|
|
if ( obsolete !== undefined ) {
|
|
|
|
if ( obsolete > Date.now() ) {
|
2017-05-12 16:35:11 +02:00
|
|
|
if ( result === 0 ) {
|
|
|
|
return 2;
|
2015-04-06 16:26:32 +02:00
|
|
|
}
|
|
|
|
} else {
|
|
|
|
delete documentWhitelists[hostname];
|
|
|
|
}
|
|
|
|
}
|
|
|
|
pos = hostname.indexOf('.');
|
2017-05-12 16:35:11 +02:00
|
|
|
if ( pos === -1 ) { break; }
|
2015-04-06 16:26:32 +02:00
|
|
|
hostname = hostname.slice(pos + 1);
|
|
|
|
}
|
|
|
|
return result;
|
|
|
|
};
|
|
|
|
|
2015-04-09 00:46:08 +02:00
|
|
|
var documentWhitelists = Object.create(null);
|
|
|
|
|
2015-04-06 16:26:32 +02:00
|
|
|
/******************************************************************************/
|
|
|
|
|
|
|
|
exports.temporarilyWhitelistDocument = function(hostname) {
|
|
|
|
if ( typeof hostname !== 'string' || hostname === '' ) {
|
2015-03-26 00:28:22 +01:00
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
documentWhitelists[hostname] = Date.now() + 60 * 1000;
|
|
|
|
};
|
|
|
|
|
|
|
|
/******************************************************************************/
|
|
|
|
|
|
|
|
return exports;
|
|
|
|
|
|
|
|
/******************************************************************************/
|
|
|
|
|
2014-06-24 00:42:43 +02:00
|
|
|
})();
|
|
|
|
|
|
|
|
/******************************************************************************/
|