fix(stealth): apply stealth on the --launch path (FullLaunch JS patches + UA strip)

handle_launch's fresh-launch path (the path `--launch open <url>` takes) never
called apply_stealth_to_browser — only the launch FLAGS were applied (e.g.
--disable-blink-features=AutomationControlled, which is why navigator.webdriver
was already false). As a result the 32 JS fingerprint patches and the
Emulation.setUserAgentOverride HeadlessChrome→Chrome UA strip NEVER ran on a
launched browser: navigator.userAgent kept the HeadlessChrome marker (a
longstanding bug — identical on the prior prebuilt binary).

Add the apply_stealth_to_browser call after launch (the auto_launch path
already had it; only the explicit-launch path was missing it).

Verified, FullLaunch headless:
- navigator.webdriver === false, navigator.userAgent => Chrome/<v> (no Headless)
- new tabs and the initial page both clean
- bot.sannysoft.com: 0 failed / 31 passed
This commit is contained in:
leeguooooo
2026-06-01 14:39:03 +09:00
parent a6b2f5a192
commit 21d591ee65
+5
View File
@@ -2318,6 +2318,11 @@ async fn handle_launch(cmd: &Value, state: &mut DaemonState) -> Result<Value, St
load_storage_state_or_rollback(state, &storage_state_owned).await?;
apply_launch_init_scripts(state).await;
// Apply stealth patches (the 32 JS patches + HeadlessChrome UA strip in
// FullLaunch mode). The fresh-launch path was missing this — only the launch
// FLAGS (e.g. --disable-blink-features) were applied, so the JS patches never
// ran and navigator.userAgent kept the HeadlessChrome marker.
apply_stealth_to_browser(state).await;
Ok(json!({ "launched": true }))
}