Skip to content

HTML filters occasionally lost effectiveness #42

Description

@Crystal-RainSlide

Prerequisites

  • I verified that this is not a filter issue
  • This is not a support issue or a question
  • I performed a cursory search of the issue tracker to avoid opening a duplicate issue
  • I tried to reproduce the issue when...
    • uBlock Origin is the only extension
    • uBlock Origin with default lists/settings
    • using a new, unmodified browser profile
  • I am running the latest version of uBlock Origin
  • I checked the documentation to understand that the issue I report is not a normal behavior

Description

An ad script in https://www.baidu.com/s?wd=%E7%9A%AE%E9%9E%8B

<script id="ecomScript">
...
<script>

I tried to remove it with www.baidu.com##^script#ecomScript, but I found that only script:contains() is supported.

Then I took some time with the code and got 'setAdsHeight' in the js outline from Firefox's dev tools, then everything works fine, but the time has gone.

Certainly CSS Selector don't support this, but adblocks may support it for simplifing the rules&filtering.

A specific URL where the issue occurs

All website equipped with <script foo="bar">

Steps to Reproduce

Descripted↑

Expected behavior:

example.com##script#id

Actual behavior:

Nothing happens & desired filter don't work

Your environment

  • uBlock Origin version: Newest
  • Browser Name and version: Firefox Developer Edition 61.0
  • Operating System and version: Windows 7 Customed.

Activity

  1. Crystal-RainSlide commented on May 15, 2018

    @Crystal-RainSlide
    Author

    One other thing...

    I mistaked the outdated fork source of fang5566/uBlock , which is the offical Chinese (中文) introduction&wiki , and posted uBlock-LLC/uBlock#1767 .

    Then I got a ban at https://github.com/gorhill/uBlock/issues/new for that misposted issue.

    WHY???

  2. gorhill commented on May 15, 2018

    @gorhill
    Member

    There is no ban on https://github.com/gorhill/uBlock/issues/new, it's just reserved to contributors. Here is the proper issue tracker.

  3. gorhill commented on May 15, 2018

    @gorhill
    Member

    I answered to you on uBlockAdmin (which is a scammy fork by the way):

    When I view-source your URL https://www.baidu.com/s?wd=%E7%9A%AE%E9%9E%8B, I get:

    <!DOCTYPE html>
    <!--STATUS OK-->

    No script in there.

  4. gorhill commented on May 15, 2018

    @gorhill
    Member

    Duh, sorry, I didn't realize I could scroll. I will investigate.

  5. gorhill commented on May 15, 2018

    @gorhill
    Member

    Ok, again, when I view-source your URL https://www.baidu.com/s?wd=%E7%9A%AE%E9%9E%8B, I can't find any instance of ecomScript in the source.

  6. gorhill commented on May 15, 2018

    @gorhill
    Member

    @Crystal-RainSlide HTML filtering will only match what is in seen in view-source:, not what is dynamically added afterward.

  7. gorhill commented on May 15, 2018

    @gorhill
    Member

    @gwarser Yes, cofirmed it works fine with www.baidu.com##^script#head_script, the script element is present in view-source:, and I confirmed it was properly removed by the above filter, so the syntax works, it's just a matter of filtering what is present in the source data as per view-source:.

  8. uBlock-user commented on May 15, 2018

    @uBlock-user
    Member

    When I tested this earlier ecomScript was present, but disappeared after refresh or two.

    Still there on my end - https://i.imgur.com/xZr5QIe.jpg Can't reproduce though, it blocks just as expected.

  9. uBlock-user commented on May 15, 2018

    @uBlock-user
    Member

    script:contains() is only supported on Firefox-legacy branch, you must have installed that build instead of WebExtension build.

  10. gorhill commented on May 15, 2018

    @gorhill
    Member

    ##script:contains() is deprecated syntax, it is internally converted to ##^script:has-text() -- true for either Firefox legacy or webext.

  11. 10 remaining items

  12. changed the title [-]HTML filters (example.com##^.badstuff) occasionally lost effectiveness (reproducing...)[/-] [+]HTML filters (example.com##^.badstuff) occasionally lost effectiveness[/+] on May 16, 2018
  13. changed the title [-]HTML filters (example.com##^.badstuff) occasionally lost effectiveness[/-] [+]HTML filters occasionally lost effectiveness[/+] on May 16, 2018
  14. gorhill commented on May 16, 2018

    @gorhill
    Member

    I can reproduce every time and #head appears in the view-source of both tabs -- original and duplicate.

    view-source: is to be used to find out what can be filtered, not what has been filtered. Firefox bypasses uBO when requesting a page via view-source:.

  15. uBlock-user commented on May 16, 2018

    @uBlock-user
    Member

    You're right, I just tested ##.cr-content with baidu.com##^.cr-content and it works as expected.

  16. gorhill commented on May 16, 2018

    @gorhill
    Member

    Then, Chrome... Note that I'm using Cent Browser, not offical Chrome.

    HTML filtering is not supported on Chromium-based browsers, it's missing the proper API.

  17. gorhill commented on May 16, 2018

    @gorhill
    Member

    I can reproduce sporadically when using the "duplicate tab" trick. When the issue occurs, the HTML filter is not reported in the logger. I will keep investigating.

  18. gorhill commented on May 16, 2018

    @gorhill
    Member

    Yes, I was looking at this: https://bugzilla.mozilla.org/show_bug.cgi?id=1376932.

    I confirm that when the issue occurs, uBO's onHeadersReceived listener is not being called at all, Firefox bypasses uBO, hence uBO can't do its job.

  19. uBlock-user commented on May 16, 2018

    @uBlock-user
    Member

    So this is a browser bug ?

  20. gorhill commented on May 16, 2018

    @gorhill
    Member

    Yes, but I need to provide a workaround given the seriousness of it: one main use of HTML filtering is to remove unwanted specific inline script tag, and the issue here means this could lead to unwanted inline script code being executed. Beside, this should also solve the issue described in https://bugzilla.mozilla.org/show_bug.cgi?id=1376932 -- NoScript is being mentioned but uBO does also suffers from it (also uMatrix: gorhill/uMatrix#893).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Firefoxspecific to Firefoxfixedissue has been addressed

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions