fix(1.0.8): strip cliqz adblocker preload — breaks CSP-strict sites
cliqz/adblocker-electron registers its preload at session level via
session.setPreloads([...preloads, PRELOAD_PATH]) inside
enableBlockingInSession. That preload injects inline <script> elements
via doc.createElement('script') + script.appendChild(textNode) +
parent.appendChild(script). On modern strict-CSP sites this breaks:
- Trusted Types (YouTube, Gmail): "An HTMLScriptElement was directly
modified and will not be executed" — 52+ console errors.
- Nonce-required CSP (kinogo via Cloudflare): "Refused to execute inline
script ... script-src 'nonce-...'" — competing with Cloudflare's
challenge JS, likely the proximate cause of the 403 we see on kinogo
(CF treats the broken page as bot).
Remove the cliqz preload from each session immediately after
enableBlockingInSession. The network/CSP/blockers attached via
webRequest hooks remain active — only the script-injection layer for
anti-anti-adblock scriptlets is lost, which is a niche feature that
breaks more sites than it fixes.
The 1.0.7 Blink TrustedDOMTypes disable stays (defense in depth, no
cost). The 1.0.6 CSP-header strip stays removed (adblocker overwrites
the webRequest listener anyway).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
22
main.js
22
main.js
@@ -111,7 +111,27 @@ function getBlocker() {
|
||||
|
||||
function enableBlockingInSession(sess) {
|
||||
getBlocker()
|
||||
.then(b => { b.enableBlockingInSession(sess); console.log('[adblock] enabled for session'); })
|
||||
.then(b => {
|
||||
b.enableBlockingInSession(sess);
|
||||
// Remove the cliqz preload script that the blocker just registered on this
|
||||
// session. The preload injects inline <script> elements (via createTextNode +
|
||||
// appendChild) to neutralize anti-adblock scripts, but:
|
||||
// • Strict-CSP sites (kinogo via Cloudflare, etc.) reject inline scripts
|
||||
// without a matching nonce → "Refused to execute inline script".
|
||||
// • Trusted-Types sites (YouTube, Gmail) reject `script.appendChild(text)`
|
||||
// → "HTMLScriptElement was directly modified" (52 errors).
|
||||
// We keep the adblocker's network blocking and CSP filtering (via the still-
|
||||
// attached webRequest hooks), losing only the niche scriptlet/cosmetic-DOM
|
||||
// injection layer that breaks more sites than it helps.
|
||||
const before = sess.getPreloads();
|
||||
const after = before.filter(p => !/adblocker-electron-preload/i.test(p));
|
||||
if (after.length !== before.length) {
|
||||
sess.setPreloads(after);
|
||||
console.log('[adblock] enabled for session (preload script disabled)');
|
||||
} else {
|
||||
console.log('[adblock] enabled for session');
|
||||
}
|
||||
})
|
||||
.catch(e => console.warn('[adblock] failed to enable:', e.message));
|
||||
}
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "ESH-Media",
|
||||
"version": "1.0.7",
|
||||
"version": "1.0.8",
|
||||
"private": true,
|
||||
"main": "main.js",
|
||||
"scripts": {
|
||||
|
||||
Reference in New Issue
Block a user