Skip to content

Prevent tracking injection over history API: = (equals sign) at the tail of URLs when anchors are clicked #198

Description

@grahamperrin

Steps

  1. Enable ClearURLs 1.24.1 and Display #Anchors 1.3
  2. visit e.g. https://github.com/Dr-Noob/gpufetch
  3. click the Display #Anchors button
  4. point at the anchor to the right of README.md
  5. bottom left, observe the URL hint https://github.com/Dr-Noob/gpufetch#readme
  6. click the anchor
  7. observe the correct URL in the address bar

Issue

  1. a moment after appearance of the correct URL, there appears # at its tail

Workaround

Disable:

  • Prevent tracking injection over history API

Notes

A minor issue, this probably began a few weeks ago (I'm not sure when, sorry).

2022-04-08.00.35.26.screen.recording.mp4

A frame from the screen recording:

tail

With logging enabled, I can't see anything (logged) that might help. The issue is reproducible with my test profile, in the screen recording above, so I guess that it'll be reproducible elsewhere.

Activity

  1. grahamperrin commented on Apr 8, 2022

    @grahamperrin
    Author

    Simpler steps to reproduce

    With ClearURLs alone enabled:

    1. at this page (in this issue), click the timestamp of my opening comment

    image

    Result:

    • https://github.com/ClearURLs/Addon/issues/198#issue-1196674509= with the superfluous =
  2. changed the title [-]Prevent tracking injection over history API: = (equals sign) at the tail of URLs when Display #Anchors (extension) is used[/-] [+]Prevent tracking injection over history API: = (equals sign) at the tail of URLs when anchors are clicked[/+] on Apr 8, 2022
  3. kevinoid commented on May 25, 2022

    @kevinoid

    It appears that the issue was introduced by 63b557c. extractFragments now parses the URL fragment into URLSearchParams which doesn't distinguish between a parameter with nothing after the =, and a parameter that doesn't have a = altogether (which seems unlikely to change, e.g. whatwg/url#427) causing = to be appended to fragments which do not contain any. For example:

    new URLSearchParams('issue-1196674509').toString() === 'issue-1196674509='

    Would it be acceptable to revert to parsing the URL fragment into an array of strings using the previous regex?

  4. arnetheduck commented on Jul 18, 2022

    @arnetheduck

    +1 - the extra = breaks anchors, preventing them from being opened correctly when copy-pasting

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions