Rietveld Code Review Tool
Help | Bug tracker | Discussion group | Source code

Unified Diff: lib/content/snippets.js

Issue 29886700: Issue 6969 - Implement abort-on-property-read snippet (Closed) Base URL: https://hg.adblockplus.org/adblockpluscore/
Patch Set: Split out the property wrap Created Oct. 23, 2018, 6:22 p.m.
Use n/p to move between diff chunks; N/P to move between comments.
Jump to:
View side-by-side diff with in-line comments
Download patch
« no previous file with comments | « no previous file | no next file » | no next file with comments »
Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
Index: lib/content/snippets.js
===================================================================
--- a/lib/content/snippets.js
+++ b/lib/content/snippets.js
@@ -486,8 +486,73 @@
{
event.preventDefault();
}
},
true);
}
exports["prevent-inline-scripts"] = preventInlineScripts;
+
+function randomId()
+{
+ // 2176782336 is 36^6 which mean 6 chars [a-z0-9]
+ // 60466176 is 36^5
+ // 2176782336 - 60466176 = 2116316160. This ensure always 6 chars
+ // for when Math.random() returns 0.0
Manish Jethani 2018/10/24 20:47:45 The last line of the comment here, it's a bit misl
hub 2018/10/24 22:17:38 reworded the comments. Also added a proper JSDoc a
+ return Math.floor(Math.random() * 2116316160 + 60466176).toString(36);
+}
+
+function wrapPropertyAccess(object, property, desc)
Manish Jethani 2018/10/24 20:47:44 At least for function parameters, let's stick with
hub 2018/10/24 22:17:37 Done.
+{
+ // simple property
+ let d = Object.getOwnPropertyDescriptor(object, property);
Manish Jethani 2018/10/24 20:47:45 Maybe we should call it "currentDescriptor" instea
hub 2018/10/24 22:17:38 Done.
+ if (!d)
+ d = {};
+ if (typeof desc.get != "undefined")
+ {
+ if (d.get != desc.get)
+ d.get = desc.get;
+ }
+ if (typeof desc.set != "undefined")
+ {
+ if (d.set != desc.set)
+ d.set = desc.set;
+ }
+ Object.defineProperty(object, property, d);
+}
+/**
Manish Jethani 2018/10/24 20:47:45 Nit: We should leave a blank line here.
hub 2018/10/24 22:17:38 Done.
+ * Will patch a property on the window object to abort when read.
Manish Jethani 2018/10/24 20:47:44 Regarding the JSDoc comment for this snippet, my t
hub 2018/10/24 22:17:37 I disagree. This is documenting this code. It is e
Manish Jethani 2018/10/24 23:02:09 Alright, so we need to credit uBlock Origin for th
hub 2018/10/25 14:32:25 Added a link to uBlock.
+ * It will intercept the onerror callback and block it if tagged.
+ *
+ * @todo handle properties of properties.
+ *
+ * @param {string} prop the name of the property.
+ */
+function abortOnPropertyRead(prop)
Manish Jethani 2018/10/24 20:47:45 Let's rename "prop" to "property" since we are usi
hub 2018/10/24 22:17:37 Done.
+{
+ if (!prop)
+ return;
+
+ let rid = randomId();
+
+ function canceller()
Manish Jethani 2018/10/24 20:47:45 How about we just call this function "abort", whic
hub 2018/10/24 22:17:38 Done.
+ {
+ throw new ReferenceError(rid);
+ }
+
+ let {onerror} = window;
Manish Jethani 2018/10/24 21:01:48 Hmm ... I think we're going to need to repeat this
Manish Jethani 2018/10/24 21:12:28 Looking at the other patch, yeah I think we should
hub 2018/10/24 22:17:38 I think it is.
hub 2018/10/24 22:17:38 All of this make the whole thing more complicated,
Manish Jethani 2018/10/24 23:02:09 So you intend to repeat this window.onerror boiler
+ window.onerror = (message, ...rest) =>
+ {
+ if (typeof message == "string" && message.includes(rid))
Manish Jethani 2018/10/24 23:02:09 I think we should check specifically for "Referenc
hub 2018/10/25 14:32:26 No. Because the message format isn't part of any s
Manish Jethani 2018/10/25 16:12:15 Well it's OK for this to not work and for an error
hub 2018/10/25 20:26:09 I'll make 5 times these. Should be random enough.
+ return true;
+ if (onerror && typeof onerror == "function")
Manish Jethani 2018/10/24 20:47:45 I don't think the first condition here is necessar
hub 2018/10/24 22:17:37 Done.
+ return onerror.call(this, message, ...rest);
Manish Jethani 2018/10/24 20:47:45 I just realized that you can have a function that
hub 2018/10/24 22:17:38 Actually I think I went a bit overboard. I don't e
Manish Jethani 2018/10/24 23:02:09 You did not go overboard, because in strict mode t
hub 2018/10/25 14:32:25 No. If the original handler is bound to something,
Manish Jethani 2018/10/25 16:12:15 How can we assume that the original handler will b
hub 2018/10/25 20:26:09 So call it is. BTW if the function object has no `
Manish Jethani 2018/10/25 21:32:25 The call method is a feature of the API, it is not
hub 2018/10/26 15:19:05 Done.
+ };
+
+ let d = {get: canceller, set() {}};
Manish Jethani 2018/10/24 20:47:44 We don't need this temporary variable, in my opini
Manish Jethani 2018/10/24 20:47:45 I feel like we're going to need this noop function
hub 2018/10/24 22:17:38 Done.
hub 2018/10/24 22:17:38 I don't think this make it any clearer.
Manish Jethani 2018/10/24 23:02:09 Acknowledged.
+
+ wrapPropertyAccess(window, prop, d);
+}
+
+exports["abort-on-property-read"] = makeInjector(abortOnPropertyRead,
+ wrapPropertyAccess,
+ randomId);
« no previous file with comments | « no previous file | no next file » | no next file with comments »

Powered by Google App Engine
This is Rietveld