Compare commits
17
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
4b33dbadb4 | ||
|
|
fc73ee6c90 | ||
|
|
28d3748c06 | ||
|
|
fa47a0b8e5 | ||
|
|
36c593631c | ||
|
|
b92757412d | ||
|
|
6ecda4d706 | ||
|
|
123510db2b | ||
|
|
abb65c632b | ||
|
|
e803bffbbb | ||
|
|
96ee2f9758 | ||
|
|
0a3d2a91a6 | ||
|
|
1e5dfd35cb | ||
|
|
b6b2ca56ca | ||
|
|
6d740093dc | ||
|
|
c884fb4f57 | ||
|
|
57ef011817 |
@@ -227,6 +227,25 @@ When connected to your real Chrome, we inject **zero** JavaScript patches. Your
|
|||||||
|
|
||||||
When using `--launch` mode (standalone browser), a full suite of stealth patches is applied instead, and it still passes the suite above.
|
When using `--launch` mode (standalone browser), a full suite of stealth patches is applied instead, and it still passes the suite above.
|
||||||
|
|
||||||
|
### Human-like input (behavioural stealth)
|
||||||
|
|
||||||
|
Fingerprint stealth isn't the whole story — the strongest anti-bot vendors (Akamai, PerimeterX, DataDome) also score *behaviour*. A click that teleports the cursor to an element's exact centre with no approach path and zero press delay is a tell, **even though our CDP events are `isTrusted`**.
|
||||||
|
|
||||||
|
With humanize on, the cursor moves like a hand: clicks follow a curved, decelerating Bézier path and land on a jittered point *inside* the element (never the dead centre); typing uses variable inter-keystroke timing; scrolling eases in segments; drags follow a curve. It's **adaptive** — every navigation is probed for known anti-bot vendors (cookies / scripts / globals) and a guarded page auto-escalates to full human motion, while ordinary sites stay instant (zero overhead).
|
||||||
|
|
||||||
|
What the page's own `mousemove` stream sees (this *is* what a behavioural detector analyses):
|
||||||
|
|
||||||
|
| | trajectory |
|
||||||
|
|---|---|
|
||||||
|
| **off** (default) | straight lines · dead-centre · instant |
|
||||||
|
| **human** | curved trails · slow-in/slow-out · off-centre landings |
|
||||||
|
|
||||||
|
Control with `--humanize off\|fast\|human` or `AGENT_BROWSER_HUMANIZE`. Default `off`; the adaptive detector escalates per page.
|
||||||
|
|
||||||
|
### Silent operation
|
||||||
|
|
||||||
|
Driving your real Chrome should never interrupt your work. The agent operates **entirely in the background**: new tabs open un-focused (in their own colored per-session tab group), the agent **never force-fronts a tab**, and `Emulation.setFocusEmulationEnabled` keeps each agent tab rendering and reporting `document.hasFocus()` / `visibilityState: 'visible'`. So screenshots still work, pages aren't render-throttled, and "the tab was hidden the whole session" never becomes its own bot tell. You keep working in your active tab; the agent works alongside you, silently. (Surfacing a tab stays available as an explicit command.)
|
||||||
|
|
||||||
### Verify it yourself
|
### Verify it yourself
|
||||||
|
|
||||||
Don't take our word for it — point your connected Chrome at the toughest public detectors and compare:
|
Don't take our word for it — point your connected Chrome at the toughest public detectors and compare:
|
||||||
@@ -244,6 +263,7 @@ We deliberately **don't ship our own bot detector** — the strongest, most hone
|
|||||||
| Variable | Default | Effect |
|
| Variable | Default | Effect |
|
||||||
|---|---|---|
|
|---|---|---|
|
||||||
| `AGENT_BROWSER_CAPTURE_CONSOLE` | off | Enable `Runtime` domain so `console` / `errors` capture page output. Off keeps the stealthiest profile. |
|
| `AGENT_BROWSER_CAPTURE_CONSOLE` | off | Enable `Runtime` domain so `console` / `errors` capture page output. Off keeps the stealthiest profile. |
|
||||||
|
| `AGENT_BROWSER_HUMANIZE` | off | Human-like input motion: `off` (instant), `fast` (light eased trajectory), `human` (full curved trajectory + landing jitter + typing cadence + eased scroll/drag). Also `--humanize`. Default `off`; the adaptive detector auto-escalates pages guarded by Akamai/PerimeterX/DataDome to `human`. |
|
||||||
| `AGENT_BROWSER_TIMEZONE` | unset | `--launch` only. An IANA id (e.g. `Asia/Tokyo`) sets the timezone natively (Intl + Date follow, no JS lie) to match a proxy; `auto` derives one from the locale. |
|
| `AGENT_BROWSER_TIMEZONE` | unset | `--launch` only. An IANA id (e.g. `Asia/Tokyo`) sets the timezone natively (Intl + Date follow, no JS lie) to match a proxy; `auto` derives one from the locale. |
|
||||||
| `AGENT_BROWSER_BLOCK_WEBRTC` | auto | `--launch` only. Auto-forces WebRTC through the proxy when one is set (no real-IP leak). `1` hides the local IP without a proxy; `0` opts out. |
|
| `AGENT_BROWSER_BLOCK_WEBRTC` | auto | `--launch` only. Auto-forces WebRTC through the proxy when one is set (no real-IP leak). `1` hides the local IP without a proxy; `0` opts out. |
|
||||||
| `AGENT_BROWSER_HIDE_CANVAS` | off | `--launch` only. Adds session-stable canvas/audio fingerprint noise. Off by default (noise is itself a "lie"). |
|
| `AGENT_BROWSER_HIDE_CANVAS` | off | `--launch` only. Adds session-stable canvas/audio fingerprint noise. Off by default (noise is itself a "lie"). |
|
||||||
|
|||||||
@@ -148,6 +148,25 @@ agent-browser --launch --profile auto open https://x.com/home
|
|||||||
|
|
||||||
`--launch` 独立模式下会改用一整套隐身补丁,同样过上述检测。
|
`--launch` 独立模式下会改用一整套隐身补丁,同样过上述检测。
|
||||||
|
|
||||||
|
### 类人输入(行为隐身)
|
||||||
|
|
||||||
|
指纹隐身只是一半——最强的反爬厂商(Akamai、PerimeterX、DataDome)还会给**行为**打分。点击时光标瞬移到元素正中心、没有接近轨迹、按下即抬起,这本身就是破绽,**哪怕我们的 CDP 事件是 `isTrusted`**。
|
||||||
|
|
||||||
|
开启 humanize 后,光标像手在动:点击走带减速的贝塞尔曲线、落在元素内**偏离正中心**的抖动点;打字用变速的击键间隔;滚动分段缓动;拖拽走曲线。而且**自适应**——每次导航探测页面是否有已知反爬厂商(cookie/脚本/全局变量),命中就自动升到全套类人动作,普通站点保持瞬时(零开销)。
|
||||||
|
|
||||||
|
页面自己的 `mousemove` 流看到的(行为检测器分析的正是这个):
|
||||||
|
|
||||||
|
| | 轨迹 |
|
||||||
|
|---|---|
|
||||||
|
| **off**(默认) | 直线 · 死磕正中心 · 瞬时 |
|
||||||
|
| **human** | 曲线 · 先慢后快再慢 · 落点偏移 |
|
||||||
|
|
||||||
|
用 `--humanize off\|fast\|human` 或 `AGENT_BROWSER_HUMANIZE` 控制。默认 `off`,自适应检测器按页面自动升档。
|
||||||
|
|
||||||
|
### 静默操作
|
||||||
|
|
||||||
|
操作你的真实 Chrome 不该打断你的工作。agent **全程在后台操作**:新标签后台打开(在自己的彩色会话标签组里),**从不强制把标签拽到前台**,并用 `Emulation.setFocusEmulationEnabled` 让每个 agent 标签照常渲染、`document.hasFocus()` / `visibilityState` 仍报 `visible`。于是截图正常、页面不被降频,"标签全程隐藏"也不会变成新的机器人信号。你在自己的标签里照常工作,agent 在旁边默默干活。(想置顶某个标签仍可显式调用命令。)
|
||||||
|
|
||||||
## 与上游的差异
|
## 与上游的差异
|
||||||
|
|
||||||
基于 [agent-browser v0.27.0](https://github.com/vercel-labs/agent-browser):
|
基于 [agent-browser v0.27.0](https://github.com/vercel-labs/agent-browser):
|
||||||
|
|||||||
Generated
+1
-1
@@ -45,7 +45,7 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "agent-browser-stealth"
|
name = "agent-browser-stealth"
|
||||||
version = "0.27.0-fork.38"
|
version = "0.27.0-fork.45"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"aes-gcm",
|
"aes-gcm",
|
||||||
"async-trait",
|
"async-trait",
|
||||||
|
|||||||
+1
-1
@@ -1,6 +1,6 @@
|
|||||||
[package]
|
[package]
|
||||||
name = "agent-browser-stealth"
|
name = "agent-browser-stealth"
|
||||||
version = "0.27.0-fork.38"
|
version = "0.27.0-fork.45"
|
||||||
edition = "2021"
|
edition = "2021"
|
||||||
description = "Fast browser automation CLI for AI agents"
|
description = "Fast browser automation CLI for AI agents"
|
||||||
license = "Apache-2.0"
|
license = "Apache-2.0"
|
||||||
|
|||||||
+137
-8
@@ -101,7 +101,62 @@ pub fn parse_curl_cookies(raw: &str) -> Result<Vec<Value>, String> {
|
|||||||
.get("value")
|
.get("value")
|
||||||
.and_then(|v| v.as_str())
|
.and_then(|v| v.as_str())
|
||||||
.ok_or_else(|| format!("cookies[{}] missing string value", i))?;
|
.ok_or_else(|| format!("cookies[{}] missing string value", i))?;
|
||||||
out.push(json!({ "name": name, "value": value }));
|
let mut cookie = json!({ "name": name, "value": value });
|
||||||
|
let obj = cookie.as_object_mut().unwrap();
|
||||||
|
// Preserve any CDP Network.setCookie attributes present on the
|
||||||
|
// source object so a full auth state round-trips: httpOnly session
|
||||||
|
// tokens, per-domain cookies (a single export spans .chatgpt.com,
|
||||||
|
// .openai.com, ...), and secure/sameSite/expiry. A bare
|
||||||
|
// {name,value} export is unchanged. Common aliases from DevTools /
|
||||||
|
// EditThisCookie / extension exports are accepted.
|
||||||
|
if let Some(v) = c.get("url").and_then(|v| v.as_str()) {
|
||||||
|
obj.insert("url".into(), json!(v));
|
||||||
|
}
|
||||||
|
if let Some(v) = c.get("domain").and_then(|v| v.as_str()) {
|
||||||
|
obj.insert("domain".into(), json!(v));
|
||||||
|
}
|
||||||
|
if let Some(v) = c.get("path").and_then(|v| v.as_str()) {
|
||||||
|
obj.insert("path".into(), json!(v));
|
||||||
|
}
|
||||||
|
if let Some(v) = c.get("secure").and_then(|v| v.as_bool()) {
|
||||||
|
obj.insert("secure".into(), json!(v));
|
||||||
|
}
|
||||||
|
if let Some(v) = c
|
||||||
|
.get("httpOnly")
|
||||||
|
.or_else(|| c.get("httponly"))
|
||||||
|
.or_else(|| c.get("http_only"))
|
||||||
|
.and_then(|v| v.as_bool())
|
||||||
|
{
|
||||||
|
obj.insert("httpOnly".into(), json!(v));
|
||||||
|
}
|
||||||
|
if let Some(v) = c
|
||||||
|
.get("sameSite")
|
||||||
|
.or_else(|| c.get("samesite"))
|
||||||
|
.or_else(|| c.get("same_site"))
|
||||||
|
.and_then(|v| v.as_str())
|
||||||
|
{
|
||||||
|
let norm = match v.to_lowercase().as_str() {
|
||||||
|
"strict" => "Strict",
|
||||||
|
"lax" => "Lax",
|
||||||
|
"none" | "no_restriction" => "None",
|
||||||
|
_ => "",
|
||||||
|
};
|
||||||
|
if !norm.is_empty() {
|
||||||
|
obj.insert("sameSite".into(), json!(norm));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
// CDP `expires` is seconds since the Unix epoch (f64). Accept
|
||||||
|
// `expires` or EditThisCookie's `expirationDate`.
|
||||||
|
if let Some(v) = c
|
||||||
|
.get("expires")
|
||||||
|
.or_else(|| c.get("expirationDate"))
|
||||||
|
.and_then(|v| v.as_f64())
|
||||||
|
{
|
||||||
|
if v > 0.0 {
|
||||||
|
obj.insert("expires".into(), json!(v));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
out.push(cookie);
|
||||||
}
|
}
|
||||||
return Ok(out);
|
return Ok(out);
|
||||||
}
|
}
|
||||||
@@ -348,12 +403,48 @@ fn parse_command_inner(args: &[String], flags: &Flags) -> Result<Value, ParseErr
|
|||||||
Ok(json!({ "id": id, "action": "fill", "selector": sel, "value": rest[1..].join(" ") }))
|
Ok(json!({ "id": id, "action": "fill", "selector": sel, "value": rest[1..].join(" ") }))
|
||||||
}
|
}
|
||||||
"type" => {
|
"type" => {
|
||||||
|
// `type --focused <text>` types into whatever element currently has
|
||||||
|
// focus (no selector) — for custom widgets that move focus to a hidden
|
||||||
|
// input after you open them.
|
||||||
|
if rest.first() == Some(&"--focused") {
|
||||||
|
return Ok(json!({
|
||||||
|
"id": id, "action": "type", "focused": true,
|
||||||
|
"text": rest[1..].join(" "),
|
||||||
|
}));
|
||||||
|
}
|
||||||
let sel = rest.first().ok_or_else(|| ParseError::MissingArguments {
|
let sel = rest.first().ok_or_else(|| ParseError::MissingArguments {
|
||||||
context: "type".to_string(),
|
context: "type".to_string(),
|
||||||
usage: "type <selector> <text>",
|
usage: "type <selector> <text> (or: type --focused <text>)",
|
||||||
})?;
|
})?;
|
||||||
Ok(json!({ "id": id, "action": "type", "selector": sel, "text": rest[1..].join(" ") }))
|
Ok(json!({ "id": id, "action": "type", "selector": sel, "text": rest[1..].join(" ") }))
|
||||||
}
|
}
|
||||||
|
"pick" => {
|
||||||
|
// pick <selector|@ref> --option "<text>" — atomic combobox select:
|
||||||
|
// open the control, wait for options (incl. portal menus), match by
|
||||||
|
// text, fire the right event sequence, verify. Covers native <select>,
|
||||||
|
// ARIA combobox/listbox, and react-select.
|
||||||
|
let sel = rest.first().ok_or_else(|| ParseError::MissingArguments {
|
||||||
|
context: "pick".to_string(),
|
||||||
|
usage: "pick <selector> --option \"<text>\"",
|
||||||
|
})?;
|
||||||
|
let opt_pos = rest.iter().position(|a| *a == "--option" || *a == "-o");
|
||||||
|
let option = match opt_pos {
|
||||||
|
Some(p) => rest[p + 1..].join(" "),
|
||||||
|
None => {
|
||||||
|
return Err(ParseError::MissingArguments {
|
||||||
|
context: "pick".to_string(),
|
||||||
|
usage: "pick <selector> --option \"<text>\"",
|
||||||
|
})
|
||||||
|
}
|
||||||
|
};
|
||||||
|
if option.is_empty() {
|
||||||
|
return Err(ParseError::MissingArguments {
|
||||||
|
context: "pick".to_string(),
|
||||||
|
usage: "pick <selector> --option \"<text>\"",
|
||||||
|
});
|
||||||
|
}
|
||||||
|
Ok(json!({ "id": id, "action": "pick", "selector": sel, "option": option }))
|
||||||
|
}
|
||||||
"hover" => {
|
"hover" => {
|
||||||
let sel = rest.first().ok_or_else(|| ParseError::MissingArguments {
|
let sel = rest.first().ok_or_else(|| ParseError::MissingArguments {
|
||||||
context: "hover".to_string(),
|
context: "hover".to_string(),
|
||||||
@@ -786,17 +877,31 @@ fn parse_command_inner(args: &[String], flags: &Flags) -> Result<Value, ParseErr
|
|||||||
|
|
||||||
// === Eval ===
|
// === Eval ===
|
||||||
"eval" => {
|
"eval" => {
|
||||||
// Check for flags: -b/--base64 or --stdin
|
// Check for flags: -b/--base64, --stdin, or --file <path>
|
||||||
let (is_base64, is_stdin, script_parts): (bool, bool, &[&str]) =
|
let (is_base64, is_stdin, is_file, script_parts): (bool, bool, bool, &[&str]) =
|
||||||
if rest.first() == Some(&"-b") || rest.first() == Some(&"--base64") {
|
if rest.first() == Some(&"-b") || rest.first() == Some(&"--base64") {
|
||||||
(true, false, &rest[1..])
|
(true, false, false, &rest[1..])
|
||||||
} else if rest.first() == Some(&"--stdin") {
|
} else if rest.first() == Some(&"--stdin") {
|
||||||
(false, true, &rest[1..])
|
(false, true, false, &rest[1..])
|
||||||
|
} else if rest.first() == Some(&"--file") {
|
||||||
|
(false, false, true, &rest[1..])
|
||||||
} else {
|
} else {
|
||||||
(false, false, rest.as_slice())
|
(false, false, false, rest.as_slice())
|
||||||
};
|
};
|
||||||
|
|
||||||
let script = if is_stdin {
|
let script = if is_file {
|
||||||
|
// Read the script from a file. Avoids shell-mangling of inline JS
|
||||||
|
// (non-ASCII identifiers/strings, quotes, large scripts) — the file
|
||||||
|
// is read as UTF-8 and sent verbatim.
|
||||||
|
let path = script_parts.first().ok_or(ParseError::InvalidValue {
|
||||||
|
message: "eval --file requires a path".to_string(),
|
||||||
|
usage: "eval --file <path>",
|
||||||
|
})?;
|
||||||
|
std::fs::read_to_string(path).map_err(|e| ParseError::InvalidValue {
|
||||||
|
message: format!("eval --file: cannot read {path}: {e}"),
|
||||||
|
usage: "eval --file <path>",
|
||||||
|
})?
|
||||||
|
} else if is_stdin {
|
||||||
// Read script from stdin
|
// Read script from stdin
|
||||||
let stdin = io::stdin();
|
let stdin = io::stdin();
|
||||||
let lines: Vec<String> = stdin
|
let lines: Vec<String> = stdin
|
||||||
@@ -2859,6 +2964,27 @@ mod tests {
|
|||||||
assert_eq!(cmd["action"], "cookies_clear");
|
assert_eq!(cmd["action"], "cookies_clear");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_parse_curl_cookies_json_preserves_attributes() {
|
||||||
|
// A full cookie export (httpOnly session token, per-domain, secure,
|
||||||
|
// sameSite, expiry) must round-trip — not get flattened to name/value.
|
||||||
|
let input = r#"[
|
||||||
|
{"name":"__Secure-next-auth.session-token","value":"eyJ.tok","domain":".chatgpt.com","path":"/","secure":true,"httpOnly":true,"sameSite":"Lax","expires":1893456000},
|
||||||
|
{"name":"cf_clearance","value":"abc","domain":".openai.com","path":"/","secure":true,"http_only":true,"same_site":"no_restriction"}
|
||||||
|
]"#;
|
||||||
|
let out = parse_curl_cookies(input).unwrap();
|
||||||
|
assert_eq!(out.len(), 2);
|
||||||
|
assert_eq!(out[0]["domain"], ".chatgpt.com");
|
||||||
|
assert_eq!(out[0]["secure"], true);
|
||||||
|
assert_eq!(out[0]["httpOnly"], true);
|
||||||
|
assert_eq!(out[0]["sameSite"], "Lax");
|
||||||
|
assert_eq!(out[0]["expires"], 1893456000.0);
|
||||||
|
// alias keys (http_only, same_site=no_restriction) normalize to CDP shape
|
||||||
|
assert_eq!(out[1]["domain"], ".openai.com");
|
||||||
|
assert_eq!(out[1]["httpOnly"], true);
|
||||||
|
assert_eq!(out[1]["sameSite"], "None");
|
||||||
|
}
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn test_parse_curl_cookies_json_array() {
|
fn test_parse_curl_cookies_json_array() {
|
||||||
let input = r#"[{"name":"a","value":"1"},{"name":"b","value":"2"}]"#;
|
let input = r#"[{"name":"a","value":"1"},{"name":"b","value":"2"}]"#;
|
||||||
@@ -2866,6 +2992,9 @@ mod tests {
|
|||||||
assert_eq!(out.len(), 2);
|
assert_eq!(out.len(), 2);
|
||||||
assert_eq!(out[0]["name"], "a");
|
assert_eq!(out[0]["name"], "a");
|
||||||
assert_eq!(out[0]["value"], "1");
|
assert_eq!(out[0]["value"], "1");
|
||||||
|
// bare {name,value} stays minimal — no spurious attribute keys
|
||||||
|
assert!(out[0].get("domain").is_none());
|
||||||
|
assert!(out[0].get("secure").is_none());
|
||||||
assert_eq!(out[1]["name"], "b");
|
assert_eq!(out[1]["name"], "b");
|
||||||
assert_eq!(out[1]["value"], "2");
|
assert_eq!(out[1]["value"], "2");
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -344,6 +344,19 @@ fn host_manifest_path_for_chrome() -> Option<PathBuf> {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// True if the ab-connect native-messaging host manifest is present — i.e. the
|
||||||
|
/// user has set up the extension path. When installed, auto-connect treats the
|
||||||
|
/// dialog-free extension relay as the *intended* transport and refuses to fall
|
||||||
|
/// back to a raw debug port (which would pop Chrome 136+'s "Allow remote
|
||||||
|
/// debugging?" consent modal). The relay-url file comes and goes with the
|
||||||
|
/// service worker; this manifest is the durable signal that the extension is
|
||||||
|
/// the chosen path.
|
||||||
|
pub fn host_installed() -> bool {
|
||||||
|
native_messaging_dirs()
|
||||||
|
.into_iter()
|
||||||
|
.any(|d| d.join(format!("{HOST_NAME}.json")).exists())
|
||||||
|
}
|
||||||
|
|
||||||
fn report(json: bool, ok: bool, msg: &str) {
|
fn report(json: bool, ok: bool, msg: &str) {
|
||||||
if json {
|
if json {
|
||||||
println!(
|
println!(
|
||||||
|
|||||||
+27
-1
@@ -821,7 +821,33 @@ fn connect(session: &str) -> Result<Connection, String> {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
pub fn send_command(cmd: Value, session: &str) -> Result<Response, String> {
|
pub fn send_command(mut cmd: Value, session: &str) -> Result<Response, String> {
|
||||||
|
// Forward per-invocation env to the daemon. The daemon's environment is
|
||||||
|
// frozen at spawn, so settings like AGENT_BROWSER_CLICK_MODE /
|
||||||
|
// AGENT_BROWSER_HUMANIZE (incl. the --humanize flag, which sets the latter)
|
||||||
|
// are otherwise silently ignored on an already-running daemon. Carry them in
|
||||||
|
// the envelope so they apply to THIS command.
|
||||||
|
if let Some(obj) = cmd.as_object_mut() {
|
||||||
|
if let Ok(m) = std::env::var("AGENT_BROWSER_CLICK_MODE") {
|
||||||
|
obj.insert("_clickMode".to_string(), Value::String(m));
|
||||||
|
}
|
||||||
|
if let Ok(h) = std::env::var("AGENT_BROWSER_HUMANIZE") {
|
||||||
|
// Only forward a recognized level; warn once (like the --humanize flag
|
||||||
|
// does) when the env var is set to garbage, instead of silently
|
||||||
|
// ignoring it.
|
||||||
|
if crate::native::humanize::HumanizeLevel::parse(&h).is_some() {
|
||||||
|
obj.insert("_humanize".to_string(), Value::String(h));
|
||||||
|
} else {
|
||||||
|
static WARNED: std::sync::Once = std::sync::Once::new();
|
||||||
|
WARNED.call_once(|| {
|
||||||
|
eprintln!(
|
||||||
|
"warning: AGENT_BROWSER_HUMANIZE must be off|fast|human, got {h:?} (ignored)"
|
||||||
|
);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// Retry logic for transient errors (EAGAIN/EWOULDBLOCK/connection issues)
|
// Retry logic for transient errors (EAGAIN/EWOULDBLOCK/connection issues)
|
||||||
const MAX_RETRIES: u32 = 5;
|
const MAX_RETRIES: u32 = 5;
|
||||||
const RETRY_DELAY_MS: u64 = 200;
|
const RETRY_DELAY_MS: u64 = 200;
|
||||||
|
|||||||
@@ -1160,6 +1160,23 @@ impl Drop for DaemonState {
|
|||||||
|
|
||||||
pub async fn execute_command(cmd: &Value, state: &mut DaemonState) -> Value {
|
pub async fn execute_command(cmd: &Value, state: &mut DaemonState) -> Value {
|
||||||
let action = cmd.get("action").and_then(|v| v.as_str()).unwrap_or("");
|
let action = cmd.get("action").and_then(|v| v.as_str()).unwrap_or("");
|
||||||
|
|
||||||
|
// Apply per-invocation overrides the client forwarded (the daemon's own env
|
||||||
|
// is frozen at spawn). CLICK_MODE is read fresh from the process env by
|
||||||
|
// interaction::click, so mirror it here — set when this command provided it,
|
||||||
|
// clear otherwise, so a value from an earlier command never leaks forward.
|
||||||
|
match cmd.get("_clickMode").and_then(|v| v.as_str()) {
|
||||||
|
Some(m) if !m.is_empty() => std::env::set_var("AGENT_BROWSER_CLICK_MODE", m),
|
||||||
|
_ => std::env::remove_var("AGENT_BROWSER_CLICK_MODE"),
|
||||||
|
}
|
||||||
|
// Humanize: set the session level from the client's --humanize / env. Only
|
||||||
|
// set when provided (don't clear — the adaptive per-navigation detector also
|
||||||
|
// owns this level between explicit overrides).
|
||||||
|
if let Some(h) = cmd.get("_humanize").and_then(|v| v.as_str()) {
|
||||||
|
if let Some(level) = super::humanize::HumanizeLevel::parse(h) {
|
||||||
|
super::humanize::set_detected_level(level);
|
||||||
|
}
|
||||||
|
}
|
||||||
let id = cmd
|
let id = cmd
|
||||||
.get("id")
|
.get("id")
|
||||||
.and_then(|v| v.as_str())
|
.and_then(|v| v.as_str())
|
||||||
@@ -1306,6 +1323,7 @@ pub async fn execute_command(cmd: &Value, state: &mut DaemonState) -> Value {
|
|||||||
"fill" => handle_fill(cmd, state).await,
|
"fill" => handle_fill(cmd, state).await,
|
||||||
"type" => handle_type(cmd, state).await,
|
"type" => handle_type(cmd, state).await,
|
||||||
"press" => handle_press(cmd, state).await,
|
"press" => handle_press(cmd, state).await,
|
||||||
|
"pick" => handle_pick(cmd, state).await,
|
||||||
"hover" => handle_hover(cmd, state).await,
|
"hover" => handle_hover(cmd, state).await,
|
||||||
"scroll" => handle_scroll(cmd, state).await,
|
"scroll" => handle_scroll(cmd, state).await,
|
||||||
"select" => handle_select(cmd, state).await,
|
"select" => handle_select(cmd, state).await,
|
||||||
@@ -3014,6 +3032,22 @@ async fn handle_fill(cmd: &Value, state: &mut DaemonState) -> Result<Value, Stri
|
|||||||
async fn handle_type(cmd: &Value, state: &mut DaemonState) -> Result<Value, String> {
|
async fn handle_type(cmd: &Value, state: &mut DaemonState) -> Result<Value, String> {
|
||||||
let mgr = state.browser.as_ref().ok_or("Browser not launched")?;
|
let mgr = state.browser.as_ref().ok_or("Browser not launched")?;
|
||||||
let session_id = mgr.active_session_id()?.to_string();
|
let session_id = mgr.active_session_id()?.to_string();
|
||||||
|
|
||||||
|
// `type --focused <text>`: type into the currently-focused element without a
|
||||||
|
// selector (custom widgets that move focus to a hidden input on open).
|
||||||
|
if cmd
|
||||||
|
.get("focused")
|
||||||
|
.and_then(|v| v.as_bool())
|
||||||
|
.unwrap_or(false)
|
||||||
|
{
|
||||||
|
let text = cmd
|
||||||
|
.get("text")
|
||||||
|
.and_then(|v| v.as_str())
|
||||||
|
.ok_or("Missing 'text' parameter")?;
|
||||||
|
interaction::type_text_into_active_context(&mgr.client, &session_id, text, None).await?;
|
||||||
|
return Ok(json!({ "typed": text, "focused": true }));
|
||||||
|
}
|
||||||
|
|
||||||
let selector = cmd
|
let selector = cmd
|
||||||
.get("selector")
|
.get("selector")
|
||||||
.and_then(|v| v.as_str())
|
.and_then(|v| v.as_str())
|
||||||
@@ -3039,6 +3073,103 @@ async fn handle_type(cmd: &Value, state: &mut DaemonState) -> Result<Value, Stri
|
|||||||
Ok(json!({ "typed": text }))
|
Ok(json!({ "typed": text }))
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Atomic combobox select: `pick <selector> --option "<text>"`. Opens the control
|
||||||
|
/// (so a portal-rendered menu mounts), polls for the option by visible text, then
|
||||||
|
/// fires the full pointer/mouse event sequence on it — covering native `<select>`,
|
||||||
|
/// ARIA combobox/listbox, and react-select, which a bare `click`+`press Enter`
|
||||||
|
/// can't do reliably. Runs as one in-page async routine so the open→render→pick
|
||||||
|
/// dance happens without round-trips that let the menu collapse between commands.
|
||||||
|
async fn handle_pick(cmd: &Value, state: &mut DaemonState) -> Result<Value, String> {
|
||||||
|
let mgr = state.browser.as_ref().ok_or("Browser not launched")?;
|
||||||
|
let session_id = mgr.active_session_id()?.to_string();
|
||||||
|
let selector = cmd
|
||||||
|
.get("selector")
|
||||||
|
.and_then(|v| v.as_str())
|
||||||
|
.ok_or("Missing 'selector' parameter")?;
|
||||||
|
let option = cmd
|
||||||
|
.get("option")
|
||||||
|
.and_then(|v| v.as_str())
|
||||||
|
.ok_or("Missing 'option' parameter")?;
|
||||||
|
|
||||||
|
let (object_id, effective_session_id) = super::element::resolve_element_object_id(
|
||||||
|
&mgr.client,
|
||||||
|
&session_id,
|
||||||
|
&state.ref_map,
|
||||||
|
selector,
|
||||||
|
&state.iframe_sessions,
|
||||||
|
)
|
||||||
|
.await?;
|
||||||
|
|
||||||
|
let func = format!(
|
||||||
|
r#"async function() {{
|
||||||
|
const want = {opt};
|
||||||
|
const norm = s => (s || '').replace(/\s+/g, ' ').trim();
|
||||||
|
const matches = el => norm(el.textContent).toLowerCase().includes(want.toLowerCase());
|
||||||
|
const el = this;
|
||||||
|
const fire = (n, t) => n.dispatchEvent(new MouseEvent(t, {{ bubbles: true, cancelable: true, view: window }}));
|
||||||
|
|
||||||
|
// Native <select>: set the matching option and dispatch input/change.
|
||||||
|
if (el.tagName === 'SELECT') {{
|
||||||
|
const opt = [...el.options].find(matches);
|
||||||
|
if (!opt) return {{ ok: false, error: 'no <option> matched ' + JSON.stringify(want) }};
|
||||||
|
el.value = opt.value;
|
||||||
|
el.dispatchEvent(new Event('input', {{ bubbles: true }}));
|
||||||
|
el.dispatchEvent(new Event('change', {{ bubbles: true }}));
|
||||||
|
return {{ ok: true, picked: norm(opt.textContent), value: el.value, kind: 'select' }};
|
||||||
|
}}
|
||||||
|
|
||||||
|
// Custom widget: open it.
|
||||||
|
(el.focus && el.focus());
|
||||||
|
['pointerdown', 'mousedown', 'mouseup', 'click'].forEach(t => fire(el, t));
|
||||||
|
|
||||||
|
// Poll for the option to render anywhere in the document (portals
|
||||||
|
// mount the menu outside the trigger), then click it.
|
||||||
|
const sel = '[role=option], [role=listbox] [role=option], li[role=option], [class*=option], [class*=item]';
|
||||||
|
const find = () => [...document.querySelectorAll(sel)].find(o => o.offsetParent !== null && matches(o));
|
||||||
|
const deadline = Date.now() + 2500;
|
||||||
|
let opt = find();
|
||||||
|
while (!opt && Date.now() < deadline) {{
|
||||||
|
await new Promise(r => setTimeout(r, 80));
|
||||||
|
opt = find();
|
||||||
|
}}
|
||||||
|
if (!opt) return {{ ok: false, error: 'option ' + JSON.stringify(want) + ' did not appear after opening the control' }};
|
||||||
|
(opt.scrollIntoView && opt.scrollIntoView({{ block: 'center' }}));
|
||||||
|
['pointermove', 'pointerover', 'mouseover', 'pointerdown', 'mousedown', 'mouseup', 'click'].forEach(t => fire(opt, t));
|
||||||
|
return {{ ok: true, picked: norm(opt.textContent), kind: 'custom' }};
|
||||||
|
}}"#,
|
||||||
|
opt = serde_json::to_string(option).unwrap_or_default(),
|
||||||
|
);
|
||||||
|
|
||||||
|
let result: super::cdp::types::EvaluateResult = mgr
|
||||||
|
.client
|
||||||
|
.send_command_typed(
|
||||||
|
"Runtime.callFunctionOn",
|
||||||
|
&super::cdp::types::CallFunctionOnParams {
|
||||||
|
function_declaration: func,
|
||||||
|
object_id: Some(object_id),
|
||||||
|
arguments: None,
|
||||||
|
return_by_value: Some(true),
|
||||||
|
await_promise: Some(true),
|
||||||
|
},
|
||||||
|
Some(&effective_session_id),
|
||||||
|
)
|
||||||
|
.await?;
|
||||||
|
|
||||||
|
if let Some(ref ex) = result.exception_details {
|
||||||
|
return Err(format!("pick failed: {}", ex.text));
|
||||||
|
}
|
||||||
|
let val = result.result.value.unwrap_or(Value::Null);
|
||||||
|
if val.get("ok").and_then(|v| v.as_bool()).unwrap_or(false) {
|
||||||
|
Ok(json!({ "picked": val.get("picked"), "selector": selector }))
|
||||||
|
} else {
|
||||||
|
Err(val
|
||||||
|
.get("error")
|
||||||
|
.and_then(|v| v.as_str())
|
||||||
|
.unwrap_or("pick failed")
|
||||||
|
.to_string())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
async fn handle_press(cmd: &Value, state: &mut DaemonState) -> Result<Value, String> {
|
async fn handle_press(cmd: &Value, state: &mut DaemonState) -> Result<Value, String> {
|
||||||
let mgr = state.browser.as_ref().ok_or("Browser not launched")?;
|
let mgr = state.browser.as_ref().ok_or("Browser not launched")?;
|
||||||
let session_id = mgr.active_session_id()?.to_string();
|
let session_id = mgr.active_session_id()?.to_string();
|
||||||
|
|||||||
@@ -309,6 +309,12 @@ pub struct BrowserManager {
|
|||||||
pub ignore_https_errors: bool,
|
pub ignore_https_errors: bool,
|
||||||
/// Origins visited during this session, used by save_state to collect cross-origin localStorage.
|
/// Origins visited during this session, used by save_state to collect cross-origin localStorage.
|
||||||
visited_origins: HashSet<String>,
|
visited_origins: HashSet<String>,
|
||||||
|
/// Target IDs of tabs THIS session created via `Target.createTarget`. When
|
||||||
|
/// connected to the user's real Chrome (not a launched browser), these are
|
||||||
|
/// closed on `close()` so the session's tabs don't pile up in the user's
|
||||||
|
/// browser after it ends. Only ever holds tabs we created — never the user's
|
||||||
|
/// existing tabs or other sessions' tabs — so closing them is always safe.
|
||||||
|
created_targets: HashSet<String>,
|
||||||
next_tab_id: u32,
|
next_tab_id: u32,
|
||||||
/// Whether to enable the CDP `Runtime` domain (console / error / exception capture).
|
/// Whether to enable the CDP `Runtime` domain (console / error / exception capture).
|
||||||
/// OFF by default for stealth: a live `Runtime.enable` is a detectable CDP signal
|
/// OFF by default for stealth: a live `Runtime.enable` is a detectable CDP signal
|
||||||
@@ -433,6 +439,7 @@ impl BrowserManager {
|
|||||||
download_path: download_path.clone(),
|
download_path: download_path.clone(),
|
||||||
ignore_https_errors,
|
ignore_https_errors,
|
||||||
visited_origins: HashSet::new(),
|
visited_origins: HashSet::new(),
|
||||||
|
created_targets: HashSet::new(),
|
||||||
next_tab_id: 1,
|
next_tab_id: 1,
|
||||||
capture_console: console_capture_enabled(),
|
capture_console: console_capture_enabled(),
|
||||||
};
|
};
|
||||||
@@ -523,6 +530,7 @@ impl BrowserManager {
|
|||||||
download_path: None,
|
download_path: None,
|
||||||
ignore_https_errors: false,
|
ignore_https_errors: false,
|
||||||
visited_origins: HashSet::new(),
|
visited_origins: HashSet::new(),
|
||||||
|
created_targets: HashSet::new(),
|
||||||
next_tab_id: 1,
|
next_tab_id: 1,
|
||||||
capture_console: console_capture_enabled(),
|
capture_console: console_capture_enabled(),
|
||||||
};
|
};
|
||||||
@@ -586,6 +594,8 @@ impl BrowserManager {
|
|||||||
None,
|
None,
|
||||||
)
|
)
|
||||||
.await?;
|
.await?;
|
||||||
|
// We created this tab — own it so close() can clean it up.
|
||||||
|
self.created_targets.insert(result.target_id.clone());
|
||||||
|
|
||||||
let attach_result: AttachToTargetResult = self
|
let attach_result: AttachToTargetResult = self
|
||||||
.client
|
.client
|
||||||
@@ -892,6 +902,24 @@ impl BrowserManager {
|
|||||||
.client
|
.client
|
||||||
.send_command_no_params("Browser.close", None)
|
.send_command_no_params("Browser.close", None)
|
||||||
.await;
|
.await;
|
||||||
|
} else {
|
||||||
|
// Connected to the user's real Chrome: we must NOT close their
|
||||||
|
// browser, but we DO own the tabs this session created. Close them so
|
||||||
|
// they don't pile up in the user's window (in their per-session tab
|
||||||
|
// group) every time a session ends, idles out, or the daemon shuts
|
||||||
|
// down. `created_targets` only holds tabs we made via
|
||||||
|
// Target.createTarget — never the user's existing tabs or other
|
||||||
|
// sessions' — so this is always safe. Best-effort per tab.
|
||||||
|
for target_id in self.created_targets.drain() {
|
||||||
|
let _ = self
|
||||||
|
.client
|
||||||
|
.send_command_typed::<_, Value>(
|
||||||
|
"Target.closeTarget",
|
||||||
|
&CloseTargetParams { target_id },
|
||||||
|
None,
|
||||||
|
)
|
||||||
|
.await;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if let Some(mut process) = self.browser_process.take() {
|
if let Some(mut process) = self.browser_process.take() {
|
||||||
@@ -993,6 +1021,8 @@ impl BrowserManager {
|
|||||||
None,
|
None,
|
||||||
)
|
)
|
||||||
.await?;
|
.await?;
|
||||||
|
// We created this tab — own it so close() can clean it up.
|
||||||
|
self.created_targets.insert(result.target_id.clone());
|
||||||
|
|
||||||
let attach_result: AttachToTargetResult = self
|
let attach_result: AttachToTargetResult = self
|
||||||
.client
|
.client
|
||||||
@@ -1158,6 +1188,8 @@ impl BrowserManager {
|
|||||||
None,
|
None,
|
||||||
)
|
)
|
||||||
.await?;
|
.await?;
|
||||||
|
// We created this tab — own it so close() can clean it up.
|
||||||
|
self.created_targets.insert(result.target_id.clone());
|
||||||
|
|
||||||
let attach: AttachToTargetResult = self
|
let attach: AttachToTargetResult = self
|
||||||
.client
|
.client
|
||||||
@@ -1750,6 +1782,7 @@ async fn initialize_lightpanda_manager(
|
|||||||
download_path: None,
|
download_path: None,
|
||||||
ignore_https_errors: false,
|
ignore_https_errors: false,
|
||||||
visited_origins: HashSet::new(),
|
visited_origins: HashSet::new(),
|
||||||
|
created_targets: HashSet::new(),
|
||||||
next_tab_id: 1,
|
next_tab_id: 1,
|
||||||
capture_console: console_capture_enabled(),
|
capture_console: console_capture_enabled(),
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -783,14 +783,46 @@ pub async fn auto_connect_cdp() -> Result<String, String> {
|
|||||||
// / :9222 probes below: if the user's Chrome happens to also be listening on a
|
// / :9222 probes below: if the user's Chrome happens to also be listening on a
|
||||||
// debug port, attaching there would pop the consent dialog and defeat the
|
// debug port, attaching there would pop the consent dialog and defeat the
|
||||||
// whole zero-interaction extension path.
|
// whole zero-interaction extension path.
|
||||||
if let Some(relay) = crate::connect::relay_url() {
|
// If the extension is installed, it is the *intended* transport. The relay
|
||||||
// The relay is a local CDP-over-WS endpoint we connect to like Chrome.
|
// URL file comes and goes with the MV3 service worker (a Chrome restart or an
|
||||||
// A bare TCP liveness check (no WS upgrade) confirms it is actually
|
// idle SW briefly drops it), so a single failed probe doesn't mean "no
|
||||||
// accepting before we commit, mirroring the consent-free probe used for
|
// extension" — retry for a few seconds while it reconnects. Crucially, when
|
||||||
// DevToolsActivePort.
|
// the extension is set up we must NEVER fall through to the raw :9222 path
|
||||||
if relay_is_live(&relay).await {
|
// below: that pops Chrome 136+'s "Allow remote debugging?" dialog, the exact
|
||||||
return Ok(relay);
|
// thing the extension exists to avoid.
|
||||||
|
// ~15s of retries (500ms apart) when the extension is installed: long enough
|
||||||
|
// for the MV3 service worker to wake and reconnect on its own (onStartup
|
||||||
|
// after a Chrome restart, or the keepalive alarm) so the relay self-heals
|
||||||
|
// with NO user action. The loop re-checks the relay file every iteration, so
|
||||||
|
// a recovery mid-wait is picked up immediately — the full window is only ever
|
||||||
|
// spent when the extension is genuinely down.
|
||||||
|
let host_installed = crate::connect::host_installed();
|
||||||
|
let relay_attempts = if host_installed { 30 } else { 1 };
|
||||||
|
for attempt in 0..relay_attempts {
|
||||||
|
if let Some(relay) = crate::connect::relay_url() {
|
||||||
|
// The relay is a local CDP-over-WS endpoint we connect to like Chrome.
|
||||||
|
// A bare TCP liveness check (no WS upgrade) confirms it is actually
|
||||||
|
// accepting before we commit, mirroring the consent-free probe used
|
||||||
|
// for DevToolsActivePort.
|
||||||
|
if relay_is_live(&relay).await {
|
||||||
|
return Ok(relay);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
if host_installed && attempt + 1 < relay_attempts {
|
||||||
|
tokio::time::sleep(std::time::Duration::from_millis(500)).await;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if host_installed {
|
||||||
|
return Err(
|
||||||
|
"The agent-browser-stealth extension is installed, but its relay \
|
||||||
|
isn't connected right now. Wake it up — click the extension's \
|
||||||
|
toolbar icon, or reload it at chrome://extensions — then retry. \
|
||||||
|
(agent-browser will not attach to a raw --remote-debugging-port \
|
||||||
|
while the extension is set up, because that pops Chrome's \"Allow \
|
||||||
|
remote debugging?\" dialog. Use --cdp <port> to force the raw path.)"
|
||||||
|
.to_string(),
|
||||||
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
let user_data_dirs = get_chrome_user_data_dirs();
|
let user_data_dirs = get_chrome_user_data_dirs();
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ use serde_json::Value;
|
|||||||
|
|
||||||
use super::cdp::client::CdpClient;
|
use super::cdp::client::CdpClient;
|
||||||
use super::cdp::types::*;
|
use super::cdp::types::*;
|
||||||
use super::element::{resolve_element_center, resolve_element_object_id, RefMap};
|
use super::element::{parse_ref, resolve_element_center, resolve_element_object_id, RefMap};
|
||||||
use super::humanize;
|
use super::humanize;
|
||||||
|
|
||||||
pub async fn click(
|
pub async fn click(
|
||||||
@@ -56,6 +56,33 @@ pub async fn click(
|
|||||||
|
|
||||||
match resolved {
|
match resolved {
|
||||||
Ok((cx, cy, w, h, effective_session_id)) => {
|
Ok((cx, cy, w, h, effective_session_id)) => {
|
||||||
|
// Occlusion guard for the CSS-selector path. `@ref` clicks are already
|
||||||
|
// occlusion-checked in resolve_element_center, but a plain selector
|
||||||
|
// resolves to coordinates without that check — so an overlay (modal
|
||||||
|
// backdrop, sticky banner, the getByText located node sitting under a
|
||||||
|
// full-screen layer) would make the coordinate click land on the
|
||||||
|
// overlay and still report success. If the click point doesn't hit the
|
||||||
|
// target, dispatch through the DOM instead (targets the element
|
||||||
|
// directly). Skipped for strict `coord` mode and non-left/multi-clicks.
|
||||||
|
if mode != "coord"
|
||||||
|
&& button == "left"
|
||||||
|
&& click_count == 1
|
||||||
|
&& parse_ref(selector_or_ref).is_none()
|
||||||
|
&& point_misses_element(client, &effective_session_id, selector_or_ref).await
|
||||||
|
{
|
||||||
|
eprintln!(
|
||||||
|
"[click] target occluded at its click point; dispatching through \
|
||||||
|
the DOM (set AGENT_BROWSER_CLICK_MODE=coord to disable)"
|
||||||
|
);
|
||||||
|
return dom_click(
|
||||||
|
client,
|
||||||
|
session_id,
|
||||||
|
ref_map,
|
||||||
|
selector_or_ref,
|
||||||
|
iframe_sessions,
|
||||||
|
)
|
||||||
|
.await;
|
||||||
|
}
|
||||||
// Land on a jittered point inside the element rather than its exact
|
// Land on a jittered point inside the element rather than its exact
|
||||||
// centre (Fast/Human). Zero size or Off → exact centre.
|
// centre (Fast/Human). Zero size or Off → exact centre.
|
||||||
let (tx, ty) = humanize::landing_point(
|
let (tx, ty) = humanize::landing_point(
|
||||||
@@ -92,6 +119,42 @@ pub async fn click(
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// True if a coordinate click at the selector's centre would land on something
|
||||||
|
/// OTHER than the element (an overlay on top), i.e. the element is occluded.
|
||||||
|
/// `false` when not occluded, the element is missing, or the probe fails (so we
|
||||||
|
/// never block a click on a flaky probe — the normal coordinate path runs).
|
||||||
|
async fn point_misses_element(client: &CdpClient, session_id: &str, selector: &str) -> bool {
|
||||||
|
let js = format!(
|
||||||
|
r#"(() => {{
|
||||||
|
const el = document.querySelector({sel});
|
||||||
|
if (!el) return false;
|
||||||
|
const r = el.getBoundingClientRect();
|
||||||
|
if (r.width === 0 || r.height === 0) return false;
|
||||||
|
const hit = document.elementFromPoint(r.left + r.width / 2, r.top + r.height / 2);
|
||||||
|
if (!hit) return false;
|
||||||
|
// Not occluded if the hit is the element, a descendant, or an ancestor
|
||||||
|
// wrapper (clicking those still reaches the element's handlers).
|
||||||
|
return !(hit === el || el.contains(hit) || hit.contains(el));
|
||||||
|
}})()"#,
|
||||||
|
sel = serde_json::to_string(selector).unwrap_or_default()
|
||||||
|
);
|
||||||
|
match client
|
||||||
|
.send_command_typed::<_, EvaluateResult>(
|
||||||
|
"Runtime.evaluate",
|
||||||
|
&EvaluateParams {
|
||||||
|
expression: js,
|
||||||
|
return_by_value: Some(true),
|
||||||
|
await_promise: Some(false),
|
||||||
|
},
|
||||||
|
Some(session_id),
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
{
|
||||||
|
Ok(r) => r.result.value.and_then(|v| v.as_bool()).unwrap_or(false),
|
||||||
|
Err(_) => false,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/// Best-effort scroll-into-view before a coordinate click. Uses Chrome's
|
/// Best-effort scroll-into-view before a coordinate click. Uses Chrome's
|
||||||
/// `scrollIntoViewIfNeeded` (only scrolls when not already fully visible),
|
/// `scrollIntoViewIfNeeded` (only scrolls when not already fully visible),
|
||||||
/// falling back to centered `scrollIntoView`. Resolution failures are ignored —
|
/// falling back to centered `scrollIntoView`. Resolution failures are ignored —
|
||||||
|
|||||||
@@ -130,6 +130,20 @@ fn format_stream_status_text(action: Option<&str>, data: &serde_json::Value) ->
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Shorten an over-long string by keeping its head and tail and eliding the
|
||||||
|
/// middle, with a char count. Used so multi-KB URLs (JWT/OTP login links) don't
|
||||||
|
/// flood `tab list`.
|
||||||
|
fn truncate_middle(s: &str, max: usize) -> String {
|
||||||
|
let n = s.chars().count();
|
||||||
|
if n <= max {
|
||||||
|
return s.to_string();
|
||||||
|
}
|
||||||
|
let keep = max.saturating_sub(1) / 2;
|
||||||
|
let head: String = s.chars().take(keep).collect();
|
||||||
|
let tail: String = s.chars().skip(n - keep).collect();
|
||||||
|
format!("{head}…{tail} [{n} chars]")
|
||||||
|
}
|
||||||
|
|
||||||
pub fn print_response_with_opts(resp: &Response, action: Option<&str>, opts: &OutputOptions) {
|
pub fn print_response_with_opts(resp: &Response, action: Option<&str>, opts: &OutputOptions) {
|
||||||
if opts.json {
|
if opts.json {
|
||||||
if opts.content_boundaries {
|
if opts.content_boundaries {
|
||||||
@@ -344,6 +358,16 @@ pub fn print_response_with_opts(resp: &Response, action: Option<&str>, opts: &Ou
|
|||||||
}
|
}
|
||||||
// Eval result
|
// Eval result
|
||||||
if let Some(result) = data.get("result") {
|
if let Some(result) = data.get("result") {
|
||||||
|
// Surface which page the eval actually ran on — to stderr, so it
|
||||||
|
// never corrupts the parsed value on stdout. Lets an agent catch tab
|
||||||
|
// drift (commands landing on the wrong tab) before trusting a result,
|
||||||
|
// e.g. a logged-in `fetch` that hit the wrong origin. (In
|
||||||
|
// content-boundaries mode the origin is already in the banner.)
|
||||||
|
if !opts.content_boundaries {
|
||||||
|
if let Some(o) = origin.filter(|o| !o.is_empty()) {
|
||||||
|
eprintln!("eval @ {o}");
|
||||||
|
}
|
||||||
|
}
|
||||||
let formatted = serde_json::to_string_pretty(result).unwrap_or_default();
|
let formatted = serde_json::to_string_pretty(result).unwrap_or_default();
|
||||||
print_with_boundaries(&formatted, origin, opts);
|
print_with_boundaries(&formatted, origin, opts);
|
||||||
return;
|
return;
|
||||||
@@ -422,6 +446,9 @@ pub fn print_response_with_opts(resp: &Response, action: Option<&str>, opts: &Ou
|
|||||||
.and_then(|v| v.as_str())
|
.and_then(|v| v.as_str())
|
||||||
.unwrap_or("Untitled");
|
.unwrap_or("Untitled");
|
||||||
let url = tab.get("url").and_then(|v| v.as_str()).unwrap_or("");
|
let url = tab.get("url").and_then(|v| v.as_str()).unwrap_or("");
|
||||||
|
// Truncate very long URLs (e.g. multi-KB JWT/OTP login links) so
|
||||||
|
// the list stays readable instead of flooding the terminal.
|
||||||
|
let url = truncate_middle(url, 120);
|
||||||
let active = tab.get("active").and_then(|v| v.as_bool()).unwrap_or(false);
|
let active = tab.get("active").and_then(|v| v.as_bool()).unwrap_or(false);
|
||||||
let marker = if active {
|
let marker = if active {
|
||||||
color::cyan("→")
|
color::cyan("→")
|
||||||
|
|||||||
+1
-1
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "agent-browser-stealth",
|
"name": "agent-browser-stealth",
|
||||||
"version": "0.27.0-fork.38",
|
"version": "0.27.0-fork.45",
|
||||||
"description": "Browser automation CLI for AI agents — stealth fork with anti-detection",
|
"description": "Browser automation CLI for AI agents — stealth fork with anti-detection",
|
||||||
"type": "module",
|
"type": "module",
|
||||||
"packageManager": "pnpm@11.1.3",
|
"packageManager": "pnpm@11.1.3",
|
||||||
|
|||||||
+42
-10
@@ -102,6 +102,20 @@ connect) > a headed launched browser > headless (forbidden).** A genuine human
|
|||||||
browser has no headless/automation tells at all, so prefer it for anything
|
browser has no headless/automation tells at all, so prefer it for anything
|
||||||
anti-bot-sensitive.
|
anti-bot-sensitive.
|
||||||
|
|
||||||
|
**Silent by default.** When driving the user's real Chrome the agent works
|
||||||
|
entirely in the background — new tabs open un-focused, the agent never force-
|
||||||
|
fronts a tab, and focus is emulated so the page still renders and reports
|
||||||
|
`visibilityState: 'visible'`. You don't need to do anything; just don't expect
|
||||||
|
the user's view to follow you (use the explicit `bringToFront` only if you
|
||||||
|
deliberately want to surface a tab).
|
||||||
|
|
||||||
|
**Human-like input for behavioural anti-bot.** Beyond fingerprint stealth,
|
||||||
|
`--humanize off|fast|human` (or `AGENT_BROWSER_HUMANIZE`) makes clicks follow a
|
||||||
|
curved, decelerating path with in-element landing jitter, typing use variable
|
||||||
|
cadence, and scroll/drag ease. Default `off`; a per-navigation detector
|
||||||
|
auto-escalates pages guarded by Akamai/PerimeterX/DataDome to `human`. Leave it
|
||||||
|
on auto; force `human` only when you already know the target scores behaviour.
|
||||||
|
|
||||||
## Two ways to drive a page — and when to drop to `eval`
|
## Two ways to drive a page — and when to drop to `eval`
|
||||||
|
|
||||||
You have a **real Chrome with the user's DOM**. Two layers, mix them freely:
|
You have a **real Chrome with the user's DOM**. Two layers, mix them freely:
|
||||||
@@ -168,14 +182,17 @@ Snapshot output looks like:
|
|||||||
Page: Example - Log in
|
Page: Example - Log in
|
||||||
URL: https://example.com/login
|
URL: https://example.com/login
|
||||||
|
|
||||||
@e1 [heading] "Log in"
|
- heading "Log in" [level=1, ref=e1]
|
||||||
@e2 [form]
|
- textbox "Email" [ref=e2]
|
||||||
@e3 [input type="email"] placeholder="Email"
|
- textbox "Password" [ref=e3]
|
||||||
@e4 [input type="password"] placeholder="Password"
|
- button "Continue" [ref=e4]
|
||||||
@e5 [button type="submit"] "Continue"
|
- link "Forgot password?" [ref=e5]
|
||||||
@e6 [link] "Forgot password?"
|
|
||||||
```
|
```
|
||||||
|
|
||||||
|
Each line is `- <role> "<accessible name>" [<attrs>, ref=eN]`, indented by nesting
|
||||||
|
depth. You pass the ref to commands as `@eN` (e.g. `click @e4`). Refs are
|
||||||
|
assigned fresh on every snapshot.
|
||||||
|
|
||||||
For unstructured reading (no refs needed):
|
For unstructured reading (no refs needed):
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
@@ -202,8 +219,16 @@ agent-browser press Enter # press a key at current focus
|
|||||||
agent-browser press Control+a # key combination
|
agent-browser press Control+a # key combination
|
||||||
agent-browser check @e3 # check checkbox
|
agent-browser check @e3 # check checkbox
|
||||||
agent-browser uncheck @e3 # uncheck
|
agent-browser uncheck @e3 # uncheck
|
||||||
agent-browser select @e4 "option-value" # select dropdown option
|
agent-browser select @e4 "option-value" # native <select> only
|
||||||
agent-browser select @e4 "a" "b" # select multiple
|
agent-browser select @e4 "a" "b" # select multiple
|
||||||
|
agent-browser pick @e4 --option "Europe" # ANY combobox (react-select / ARIA /
|
||||||
|
# native): opens it, waits for the menu
|
||||||
|
# (incl. portal-rendered), matches by
|
||||||
|
# visible text, fires the right events,
|
||||||
|
# and ERRORS if the option never shows
|
||||||
|
# (no silent no-op). Use this for custom
|
||||||
|
# dropdowns where `select` returns ✓ but
|
||||||
|
# changes nothing.
|
||||||
agent-browser upload @e5 file1.pdf # upload file(s)
|
agent-browser upload @e5 file1.pdf # upload file(s)
|
||||||
agent-browser scroll down 500 # scroll page (up/down/left/right)
|
agent-browser scroll down 500 # scroll page (up/down/left/right)
|
||||||
agent-browser scrollintoview @e1 # scroll element into view
|
agent-browser scrollintoview @e1 # scroll element into view
|
||||||
@@ -372,9 +397,16 @@ Array.from(rows).map(r => ({
|
|||||||
EOF
|
EOF
|
||||||
```
|
```
|
||||||
|
|
||||||
Prefer `eval --stdin` (heredoc) or `eval -b <base64>` for any JS with
|
Prefer `eval --stdin` (heredoc), `eval --file <path>`, or `eval -b <base64>`
|
||||||
quotes or special characters. Inline `agent-browser eval "..."` works
|
for any JS with quotes, **non-ASCII identifiers/strings (e.g. Chinese)**, or
|
||||||
only for simple expressions.
|
large scripts — inline `agent-browser eval "..."` is shell-mangled and works
|
||||||
|
only for simple ASCII expressions.
|
||||||
|
|
||||||
|
**`eval` runs in the page's MAIN world and state persists across calls**, so a
|
||||||
|
top-level `const x`/`let x`/`var x` in one call collides with the next
|
||||||
|
(`SyntaxError: Identifier 'x' has already been declared`). Either use unique
|
||||||
|
names, assign to `window.x`, or wrap the body in an IIFE
|
||||||
|
(`(() => { const x = …; return x; })()`).
|
||||||
|
|
||||||
### Screenshot
|
### Screenshot
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user