Compare commits
6
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
0c7534d9b2 | ||
|
|
ad4fb14ed9 | ||
|
|
a976287f03 | ||
|
|
649fa4ce94 | ||
|
|
3ac69e822a | ||
|
|
d7a0ed85f9 |
@@ -225,7 +225,7 @@ When connected to your real Chrome, we inject **zero** JavaScript patches. Your
|
|||||||
|
|
||||||
`0% stealth` on CreepJS is the key number: because the connect path patches **nothing**, there is no override for a lie-detector to catch. (Dashboards that read `navigator.languages` order or IP geolocation may show a soft "navigator"/"location" flag — that tracks *your real Chrome's* language list and network, not an automation tell.)
|
`0% stealth` on CreepJS is the key number: because the connect path patches **nothing**, there is no override for a lie-detector to catch. (Dashboards that read `navigator.languages` order or IP geolocation may show a soft "navigator"/"location" flag — that tracks *your real Chrome's* language list and network, not an automation tell.)
|
||||||
|
|
||||||
When using `--launch` mode (standalone browser), a full suite of stealth patches is applied instead, and it still passes the suite above.
|
When using `--launch` mode (standalone browser), a full suite of stealth patches is applied instead, and it passes the suite above — with one caveat: CreepJS reports **~20% stealth** because the srcdoc-iframe `contentWindow` patch trips its `hasIframeProxy` probe (the proxy that hides automation is itself a tell). Everything else is clean (`0% headless`, sannysoft/browserscan green, Cloudflare passed). Set **`AGENT_BROWSER_DISABLE_IFRAME_PROXY=1`** to drop that patch for a clean **0% stealth** (trades the niche srcdoc-iframe masking). The **extension-connect path** (your real Chrome) injects zero JS and is unaffected — it's the genuine 0% path.
|
||||||
|
|
||||||
### Human-like input (behavioural stealth)
|
### Human-like input (behavioural stealth)
|
||||||
|
|
||||||
|
|||||||
Generated
+1
-1
@@ -45,7 +45,7 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "agent-browser-stealth"
|
name = "agent-browser-stealth"
|
||||||
version = "0.27.0-fork.46"
|
version = "0.27.0-fork.48"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"aes-gcm",
|
"aes-gcm",
|
||||||
"async-trait",
|
"async-trait",
|
||||||
|
|||||||
+1
-1
@@ -1,6 +1,6 @@
|
|||||||
[package]
|
[package]
|
||||||
name = "agent-browser-stealth"
|
name = "agent-browser-stealth"
|
||||||
version = "0.27.0-fork.46"
|
version = "0.27.0-fork.48"
|
||||||
edition = "2021"
|
edition = "2021"
|
||||||
description = "Fast browser automation CLI for AI agents"
|
description = "Fast browser automation CLI for AI agents"
|
||||||
license = "Apache-2.0"
|
license = "Apache-2.0"
|
||||||
|
|||||||
@@ -931,6 +931,15 @@ fn parse_command_inner(args: &[String], flags: &Flags) -> Result<Value, ParseErr
|
|||||||
Ok(json!({ "id": id, "action": "evaluate", "script": script }))
|
Ok(json!({ "id": id, "action": "evaluate", "script": script }))
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// === Stealth self-check ===
|
||||||
|
"stealth" => {
|
||||||
|
// `stealth [status]` — local stealth self-check: mode, live probes
|
||||||
|
// (navigator.webdriver, window.chrome, plugins, UA), and the list of
|
||||||
|
// active overrides. --json for a stable machine-readable shape.
|
||||||
|
// (Distinct from `doctor`, which checks install/env/Chrome health.)
|
||||||
|
Ok(json!({ "id": id, "action": "stealth_status" }))
|
||||||
|
}
|
||||||
|
|
||||||
// === Close ===
|
// === Close ===
|
||||||
"close" | "quit" | "exit" => Ok(json!({ "id": id, "action": "close" })),
|
"close" | "quit" | "exit" => Ok(json!({ "id": id, "action": "close" })),
|
||||||
|
|
||||||
|
|||||||
@@ -1316,6 +1316,7 @@ pub async fn execute_command(cmd: &Value, state: &mut DaemonState) -> Value {
|
|||||||
"content" => handle_content(state).await,
|
"content" => handle_content(state).await,
|
||||||
"evaluate" => handle_evaluate(cmd, state).await,
|
"evaluate" => handle_evaluate(cmd, state).await,
|
||||||
"close" => handle_close(state).await,
|
"close" => handle_close(state).await,
|
||||||
|
"stealth_status" => handle_stealth_status(state).await,
|
||||||
"snapshot" => handle_snapshot(cmd, state).await,
|
"snapshot" => handle_snapshot(cmd, state).await,
|
||||||
"screenshot" => handle_screenshot(cmd, state).await,
|
"screenshot" => handle_screenshot(cmd, state).await,
|
||||||
"click" => handle_click(cmd, state).await,
|
"click" => handle_click(cmd, state).await,
|
||||||
@@ -2680,6 +2681,89 @@ async fn handle_evaluate(cmd: &Value, state: &DaemonState) -> Result<Value, Stri
|
|||||||
Ok(json!({ "result": result, "origin": url }))
|
Ok(json!({ "result": result, "origin": url }))
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Local stealth self-check: reports the active mode, live fingerprint probes,
|
||||||
|
/// and the list of applied overrides — so an agent (or human) can confirm
|
||||||
|
/// stealth is working without driving an external detector, and audit exactly
|
||||||
|
/// what's patched on this path (issue #5).
|
||||||
|
async fn handle_stealth_status(state: &DaemonState) -> Result<Value, String> {
|
||||||
|
let mgr = state.browser.as_ref().ok_or("Browser not launched")?;
|
||||||
|
let connect = mgr.is_cdp_connection();
|
||||||
|
|
||||||
|
let probe_js = r#"(() => {
|
||||||
|
const ua = navigator.userAgent || '';
|
||||||
|
return {
|
||||||
|
webdriver: navigator.webdriver === true,
|
||||||
|
hasWindowChrome: typeof window.chrome === 'object' && window.chrome !== null,
|
||||||
|
plugins: navigator.plugins ? navigator.plugins.length : 0,
|
||||||
|
languages: navigator.languages || [],
|
||||||
|
platform: navigator.platform || '',
|
||||||
|
headlessUA: /Headless/i.test(ua),
|
||||||
|
};
|
||||||
|
})()"#;
|
||||||
|
let p = mgr.evaluate(probe_js, None).await.unwrap_or(Value::Null);
|
||||||
|
let webdriver = p.get("webdriver").and_then(|v| v.as_bool()).unwrap_or(true);
|
||||||
|
let has_chrome = p
|
||||||
|
.get("hasWindowChrome")
|
||||||
|
.and_then(|v| v.as_bool())
|
||||||
|
.unwrap_or(false);
|
||||||
|
let plugins = p.get("plugins").and_then(|v| v.as_u64()).unwrap_or(0);
|
||||||
|
let headless_ua = p
|
||||||
|
.get("headlessUA")
|
||||||
|
.and_then(|v| v.as_bool())
|
||||||
|
.unwrap_or(false);
|
||||||
|
|
||||||
|
let checks = json!([
|
||||||
|
{ "name": "navigator.webdriver is false", "pass": !webdriver },
|
||||||
|
{ "name": "window.chrome present", "pass": has_chrome },
|
||||||
|
{ "name": "navigator.plugins non-empty", "pass": plugins > 0, "value": plugins },
|
||||||
|
{ "name": "userAgent has no 'Headless'", "pass": !headless_ua },
|
||||||
|
]);
|
||||||
|
let ok = !webdriver && has_chrome && plugins > 0 && !headless_ua;
|
||||||
|
|
||||||
|
let overrides = if connect {
|
||||||
|
json!([
|
||||||
|
"navigator.webdriver=false via Emulation.setAutomationOverride (native CDP — no JS lie)",
|
||||||
|
"Runtime.enable OFF unless console/error capture is opted in (no rebrowser runtime leak)",
|
||||||
|
"zero JS patches injected — the browser's real fingerprint is used as-is",
|
||||||
|
])
|
||||||
|
} else {
|
||||||
|
let iframe_proxy =
|
||||||
|
std::env::var("AGENT_BROWSER_DISABLE_IFRAME_PROXY").as_deref() != Ok("1");
|
||||||
|
json!([
|
||||||
|
"navigator.webdriver removed; navigator.languages/locale normalized",
|
||||||
|
"window.chrome / chrome.runtime shimmed; navigator.platform fixed",
|
||||||
|
"WebGL vendor/renderer, plugins, permissions normalized",
|
||||||
|
format!(
|
||||||
|
"srcdoc-iframe contentWindow proxy: {} (CreepJS hasIframeProxy)",
|
||||||
|
if iframe_proxy {
|
||||||
|
"ON — set AGENT_BROWSER_DISABLE_IFRAME_PROXY=1 for clean 0%"
|
||||||
|
} else {
|
||||||
|
"off"
|
||||||
|
}
|
||||||
|
),
|
||||||
|
format!(
|
||||||
|
"canvas/audio noise: {} (AGENT_BROWSER_HIDE_CANVAS)",
|
||||||
|
if std::env::var("AGENT_BROWSER_HIDE_CANVAS").as_deref() == Ok("1") {
|
||||||
|
"on"
|
||||||
|
} else {
|
||||||
|
"off (opt-in)"
|
||||||
|
}
|
||||||
|
),
|
||||||
|
"Chrome flags: --disable-blink-features=AutomationControlled, ANGLE GL",
|
||||||
|
])
|
||||||
|
};
|
||||||
|
|
||||||
|
Ok(json!({
|
||||||
|
"stealthStatus": {
|
||||||
|
"mode": if connect { "connect (your real Chrome — strongest)" } else { "launch (standalone)" },
|
||||||
|
"ok": ok,
|
||||||
|
"checks": checks,
|
||||||
|
"overrides": overrides,
|
||||||
|
"probe": p,
|
||||||
|
}
|
||||||
|
}))
|
||||||
|
}
|
||||||
|
|
||||||
async fn handle_close(state: &mut DaemonState) -> Result<Value, String> {
|
async fn handle_close(state: &mut DaemonState) -> Result<Value, String> {
|
||||||
if let Some(ref mgr) = state.browser {
|
if let Some(ref mgr) = state.browser {
|
||||||
if let Some(ref session_name) = state.session_name {
|
if let Some(ref session_name) = state.session_name {
|
||||||
|
|||||||
@@ -315,6 +315,13 @@ pub struct BrowserManager {
|
|||||||
/// browser after it ends. Only ever holds tabs we created — never the user's
|
/// browser after it ends. Only ever holds tabs we created — never the user's
|
||||||
/// existing tabs or other sessions' tabs — so closing them is always safe.
|
/// existing tabs or other sessions' tabs — so closing them is always safe.
|
||||||
created_targets: HashSet<String>,
|
created_targets: HashSet<String>,
|
||||||
|
/// The session's *intended* active tab, pinned by stable target_id rather
|
||||||
|
/// than the fragile `active_page_index`. Set on every explicit open / tab new
|
||||||
|
/// / tab switch. `active_session_id` resolves through this so a foreign tab
|
||||||
|
/// opening (passive discovery), a tab closing, or list reordering can't drift
|
||||||
|
/// the session's commands onto the wrong page — the wrong-origin-fetch hazard
|
||||||
|
/// in the dogfood reports. Falls back to the index if the pinned tab is gone.
|
||||||
|
active_target_id: Option<String>,
|
||||||
next_tab_id: u32,
|
next_tab_id: u32,
|
||||||
/// Whether to enable the CDP `Runtime` domain (console / error / exception capture).
|
/// Whether to enable the CDP `Runtime` domain (console / error / exception capture).
|
||||||
/// OFF by default for stealth: a live `Runtime.enable` is a detectable CDP signal
|
/// OFF by default for stealth: a live `Runtime.enable` is a detectable CDP signal
|
||||||
@@ -440,6 +447,7 @@ impl BrowserManager {
|
|||||||
ignore_https_errors,
|
ignore_https_errors,
|
||||||
visited_origins: HashSet::new(),
|
visited_origins: HashSet::new(),
|
||||||
created_targets: HashSet::new(),
|
created_targets: HashSet::new(),
|
||||||
|
active_target_id: None,
|
||||||
next_tab_id: 1,
|
next_tab_id: 1,
|
||||||
capture_console: console_capture_enabled(),
|
capture_console: console_capture_enabled(),
|
||||||
};
|
};
|
||||||
@@ -531,6 +539,7 @@ impl BrowserManager {
|
|||||||
ignore_https_errors: false,
|
ignore_https_errors: false,
|
||||||
visited_origins: HashSet::new(),
|
visited_origins: HashSet::new(),
|
||||||
created_targets: HashSet::new(),
|
created_targets: HashSet::new(),
|
||||||
|
active_target_id: None,
|
||||||
next_tab_id: 1,
|
next_tab_id: 1,
|
||||||
capture_console: console_capture_enabled(),
|
capture_console: console_capture_enabled(),
|
||||||
};
|
};
|
||||||
@@ -547,6 +556,7 @@ impl BrowserManager {
|
|||||||
target_type: "page".to_string(),
|
target_type: "page".to_string(),
|
||||||
});
|
});
|
||||||
manager.active_page_index = 0;
|
manager.active_page_index = 0;
|
||||||
|
manager.pin_active_target();
|
||||||
manager.enable_domains_direct().await?;
|
manager.enable_domains_direct().await?;
|
||||||
} else {
|
} else {
|
||||||
manager.discover_and_attach_targets().await?;
|
manager.discover_and_attach_targets().await?;
|
||||||
@@ -621,6 +631,7 @@ impl BrowserManager {
|
|||||||
target_type: "page".to_string(),
|
target_type: "page".to_string(),
|
||||||
});
|
});
|
||||||
self.active_page_index = 0;
|
self.active_page_index = 0;
|
||||||
|
self.pin_active_target();
|
||||||
self.enable_domains(&attach_result.session_id).await?;
|
self.enable_domains(&attach_result.session_id).await?;
|
||||||
} else {
|
} else {
|
||||||
for target in &page_targets {
|
for target in &page_targets {
|
||||||
@@ -650,6 +661,7 @@ impl BrowserManager {
|
|||||||
}
|
}
|
||||||
|
|
||||||
self.active_page_index = 0;
|
self.active_page_index = 0;
|
||||||
|
self.pin_active_target();
|
||||||
let session_id = self.pages[0].session_id.clone();
|
let session_id = self.pages[0].session_id.clone();
|
||||||
self.enable_domains(&session_id).await?;
|
self.enable_domains(&session_id).await?;
|
||||||
}
|
}
|
||||||
@@ -736,9 +748,31 @@ impl BrowserManager {
|
|||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Index of the session's active page, resolved through the pinned
|
||||||
|
/// `active_target_id` (stable across reorder/removal/passive discovery) and
|
||||||
|
/// falling back to `active_page_index` when nothing is pinned or the pin is
|
||||||
|
/// gone. This is what keeps commands on the tab the agent actually opened.
|
||||||
|
fn resolved_active_index(&self) -> usize {
|
||||||
|
if let Some(tid) = &self.active_target_id {
|
||||||
|
if let Some(i) = self.pages.iter().position(|p| &p.target_id == tid) {
|
||||||
|
return i;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
self.active_page_index
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Pin the current active page by target_id so later commands stick to it.
|
||||||
|
/// Call after any explicit open / tab new / tab switch.
|
||||||
|
fn pin_active_target(&mut self) {
|
||||||
|
self.active_target_id = self
|
||||||
|
.pages
|
||||||
|
.get(self.active_page_index)
|
||||||
|
.map(|p| p.target_id.clone());
|
||||||
|
}
|
||||||
|
|
||||||
pub fn active_session_id(&self) -> Result<&str, String> {
|
pub fn active_session_id(&self) -> Result<&str, String> {
|
||||||
self.pages
|
self.pages
|
||||||
.get(self.active_page_index)
|
.get(self.resolved_active_index())
|
||||||
.map(|p| p.session_id.as_str())
|
.map(|p| p.session_id.as_str())
|
||||||
.ok_or_else(|| "No active page".to_string())
|
.ok_or_else(|| "No active page".to_string())
|
||||||
}
|
}
|
||||||
@@ -991,7 +1025,7 @@ impl BrowserManager {
|
|||||||
|
|
||||||
pub fn active_target_id(&self) -> Result<&str, String> {
|
pub fn active_target_id(&self) -> Result<&str, String> {
|
||||||
self.pages
|
self.pages
|
||||||
.get(self.active_page_index)
|
.get(self.resolved_active_index())
|
||||||
.map(|p| p.target_id.as_str())
|
.map(|p| p.target_id.as_str())
|
||||||
.ok_or_else(|| "No active page".to_string())
|
.ok_or_else(|| "No active page".to_string())
|
||||||
}
|
}
|
||||||
@@ -1219,6 +1253,7 @@ impl BrowserManager {
|
|||||||
target_type: "page".to_string(),
|
target_type: "page".to_string(),
|
||||||
});
|
});
|
||||||
self.active_page_index = index;
|
self.active_page_index = index;
|
||||||
|
self.pin_active_target();
|
||||||
|
|
||||||
Ok(json!({
|
Ok(json!({
|
||||||
"tabId": format_tab_id(tab_id),
|
"tabId": format_tab_id(tab_id),
|
||||||
@@ -1238,6 +1273,7 @@ impl BrowserManager {
|
|||||||
}
|
}
|
||||||
|
|
||||||
self.active_page_index = index;
|
self.active_page_index = index;
|
||||||
|
self.pin_active_target();
|
||||||
let session_id = self.pages[index].session_id.clone();
|
let session_id = self.pages[index].session_id.clone();
|
||||||
self.enable_domains(&session_id).await?;
|
self.enable_domains(&session_id).await?;
|
||||||
|
|
||||||
@@ -1581,6 +1617,7 @@ impl BrowserManager {
|
|||||||
let index = self.pages.len();
|
let index = self.pages.len();
|
||||||
self.pages.push(page);
|
self.pages.push(page);
|
||||||
self.active_page_index = index;
|
self.active_page_index = index;
|
||||||
|
self.pin_active_target();
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Add a passively-discovered page WITHOUT changing the active tab.
|
/// Add a passively-discovered page WITHOUT changing the active tab.
|
||||||
@@ -1783,6 +1820,7 @@ async fn initialize_lightpanda_manager(
|
|||||||
ignore_https_errors: false,
|
ignore_https_errors: false,
|
||||||
visited_origins: HashSet::new(),
|
visited_origins: HashSet::new(),
|
||||||
created_targets: HashSet::new(),
|
created_targets: HashSet::new(),
|
||||||
|
active_target_id: None,
|
||||||
next_tab_id: 1,
|
next_tab_id: 1,
|
||||||
capture_console: console_capture_enabled(),
|
capture_console: console_capture_enabled(),
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -556,8 +556,12 @@ async fn verify_ref_identity(
|
|||||||
Err(format!(
|
Err(format!(
|
||||||
"Ref {} no longer matches its snapshot. Was [{} \"{}\"], now [{} \"{}\"].\n\
|
"Ref {} no longer matches its snapshot. Was [{} \"{}\"], now [{} \"{}\"].\n\
|
||||||
The DOM mutated between snapshot and interaction (typical with React/Vue \
|
The DOM mutated between snapshot and interaction (typical with React/Vue \
|
||||||
reusing nodes during re-render). Take a fresh snapshot, then re-target.\n\
|
reusing nodes during re-render). Fix: take a fresh `snapshot` and re-target \
|
||||||
To bypass this guard set AGENT_BROWSER_VERIFY_REF=0.",
|
with the new ref. For SPAs where refs churn every interaction, drive the \
|
||||||
|
element directly with `eval` (e.g. `eval \"document.querySelector(...).click()\"`), \
|
||||||
|
which doesn't depend on refs.\n\
|
||||||
|
(Last resort: AGENT_BROWSER_VERIFY_REF=0 disables this safety check — only \
|
||||||
|
if you accept clicks may land on a re-rendered/wrong node.)",
|
||||||
ref_id, expected_role, expected_name, actual_role, actual_name,
|
ref_id, expected_role, expected_name, actual_role, actual_name,
|
||||||
))
|
))
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1305,6 +1305,39 @@ fn render_tree(
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// True if a snapshot line names an interactive ARIA role. Compaction keeps
|
||||||
|
/// these even without a `ref=`/`": "` marker, so a clickable control never gets
|
||||||
|
/// dropped from `-c` output (the dogfood reports saw a button present in the full
|
||||||
|
/// snapshot vanish from compact, leaving the agent clicking an empty ref).
|
||||||
|
fn is_interactive_line(line: &str) -> bool {
|
||||||
|
const ROLES: &[&str] = &[
|
||||||
|
"button",
|
||||||
|
"link",
|
||||||
|
"textbox",
|
||||||
|
"checkbox",
|
||||||
|
"radio",
|
||||||
|
"combobox",
|
||||||
|
"listbox",
|
||||||
|
"menuitem",
|
||||||
|
"menuitemcheckbox",
|
||||||
|
"menuitemradio",
|
||||||
|
"option",
|
||||||
|
"switch",
|
||||||
|
"slider",
|
||||||
|
"spinbutton",
|
||||||
|
"searchbox",
|
||||||
|
"tab ",
|
||||||
|
"clickable",
|
||||||
|
"focusable",
|
||||||
|
"editable",
|
||||||
|
];
|
||||||
|
let t = line.trim_start();
|
||||||
|
// Lines look like `- button "Label" [ref=e1]`; match the role token after the
|
||||||
|
// leading "- " marker.
|
||||||
|
let t = t.strip_prefix("- ").unwrap_or(t);
|
||||||
|
ROLES.iter().any(|r| t.starts_with(r))
|
||||||
|
}
|
||||||
|
|
||||||
fn compact_tree(tree: &str, interactive: bool) -> String {
|
fn compact_tree(tree: &str, interactive: bool) -> String {
|
||||||
let lines: Vec<&str> = tree.lines().collect();
|
let lines: Vec<&str> = tree.lines().collect();
|
||||||
if lines.is_empty() {
|
if lines.is_empty() {
|
||||||
@@ -1314,7 +1347,7 @@ fn compact_tree(tree: &str, interactive: bool) -> String {
|
|||||||
let mut keep = vec![false; lines.len()];
|
let mut keep = vec![false; lines.len()];
|
||||||
|
|
||||||
for (i, line) in lines.iter().enumerate() {
|
for (i, line) in lines.iter().enumerate() {
|
||||||
if line.contains("ref=") || line.contains(": ") {
|
if line.contains("ref=") || line.contains(": ") || is_interactive_line(line) {
|
||||||
keep[i] = true;
|
keep[i] = true;
|
||||||
// Mark ancestors
|
// Mark ancestors
|
||||||
let my_indent = count_indent(line);
|
let my_indent = count_indent(line);
|
||||||
|
|||||||
@@ -51,18 +51,19 @@ pub fn build_stealth_script(mode: StealthMode, locale: Option<&str>) -> String {
|
|||||||
vec![locale, base_lang]
|
vec![locale, base_lang]
|
||||||
};
|
};
|
||||||
let config_line = format!(
|
let config_line = format!(
|
||||||
r#"const __abStealth = {{ locale: "{}", languages: {}, allowWebGLContextFallback: false, hideCanvas: {}, canvasSeed: {} }};"#,
|
r#"const __abStealth = {{ locale: "{}", languages: {}, allowWebGLContextFallback: false, hideCanvas: {}, canvasSeed: {}, disableIframeProxy: {} }};"#,
|
||||||
locale,
|
locale,
|
||||||
serde_json::to_string(&languages).unwrap_or_else(|_| r#"["en-US","en"]"#.to_string()),
|
serde_json::to_string(&languages).unwrap_or_else(|_| r#"["en-US","en"]"#.to_string()),
|
||||||
hide_canvas_enabled(),
|
hide_canvas_enabled(),
|
||||||
canvas_noise_seed(),
|
canvas_noise_seed(),
|
||||||
|
disable_iframe_proxy_enabled(),
|
||||||
);
|
);
|
||||||
|
|
||||||
// NB: this prefix MUST match the first line of stealth_scripts.js verbatim,
|
// NB: this prefix MUST match the first line of stealth_scripts.js verbatim,
|
||||||
// otherwise the fallback below prepends a SECOND `const __abStealth`
|
// otherwise the fallback below prepends a SECOND `const __abStealth`
|
||||||
// declaration and the whole script dies with a redeclaration SyntaxError.
|
// declaration and the whole script dies with a redeclaration SyntaxError.
|
||||||
if let Some(rest) = STEALTH_SCRIPTS_RAW.strip_prefix(
|
if let Some(rest) = STEALTH_SCRIPTS_RAW.strip_prefix(
|
||||||
r#"const __abStealth = { locale: "en-US", languages: ["en-US", "en"], allowWebGLContextFallback: false, hideCanvas: false, canvasSeed: 0 };"#,
|
r#"const __abStealth = { locale: "en-US", languages: ["en-US", "en"], allowWebGLContextFallback: false, hideCanvas: false, canvasSeed: 0, disableIframeProxy: false };"#,
|
||||||
) {
|
) {
|
||||||
format!("{}{}", config_line, rest)
|
format!("{}{}", config_line, rest)
|
||||||
} else {
|
} else {
|
||||||
@@ -81,6 +82,18 @@ fn hide_canvas_enabled() -> bool {
|
|||||||
.unwrap_or(false)
|
.unwrap_or(false)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Whether to DROP the srcdoc-iframe `contentWindow` Proxy patch (FullLaunch).
|
||||||
|
/// That patch masks automation in srcdoc iframes, but the JS `Proxy` is itself a
|
||||||
|
/// fingerprintable tell (CreepJS `hasIframeProxy` → ~20% stealth). Off by default
|
||||||
|
/// (keep the patch); `AGENT_BROWSER_DISABLE_IFRAME_PROXY=1` drops it for a clean
|
||||||
|
/// 0% CreepJS at the cost of that niche srcdoc-iframe masking.
|
||||||
|
fn disable_iframe_proxy_enabled() -> bool {
|
||||||
|
std::env::var("AGENT_BROWSER_DISABLE_IFRAME_PROXY")
|
||||||
|
.ok()
|
||||||
|
.map(|v| v == "1" || v.eq_ignore_ascii_case("true"))
|
||||||
|
.unwrap_or(false)
|
||||||
|
}
|
||||||
|
|
||||||
/// A per-process seed so canvas/audio noise is STABLE within a session (a real
|
/// A per-process seed so canvas/audio noise is STABLE within a session (a real
|
||||||
/// device returns the same hash on repeated reads) but differs from the
|
/// device returns the same hash on repeated reads) but differs from the
|
||||||
/// headless-stable default. 0 is avoided so the JS can treat it as "unset".
|
/// headless-stable default. 0 is avoided so the JS can treat it as "unset".
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
const __abStealth = { locale: "en-US", languages: ["en-US", "en"], allowWebGLContextFallback: false, hideCanvas: false, canvasSeed: 0 };
|
const __abStealth = { locale: "en-US", languages: ["en-US", "en"], allowWebGLContextFallback: false, hideCanvas: false, canvasSeed: 0, disableIframeProxy: false };
|
||||||
// Redefine a navigator property on its PROTOTYPE (Navigator / WorkerNavigator),
|
// Redefine a navigator property on its PROTOTYPE (Navigator / WorkerNavigator),
|
||||||
// the way real Chrome exposes these — as prototype getters, NOT instance own
|
// the way real Chrome exposes these — as prototype getters, NOT instance own
|
||||||
// properties. Adding an own property to the `navigator` instance is itself a
|
// properties. Adding an own property to the `navigator` instance is itself a
|
||||||
@@ -289,6 +289,10 @@ const __abRedefineNavProto = (name, getterImpl) => {
|
|||||||
})();
|
})();
|
||||||
(function(){
|
(function(){
|
||||||
if (typeof document === 'undefined' || typeof document.createElement !== 'function') return;
|
if (typeof document === 'undefined' || typeof document.createElement !== 'function') return;
|
||||||
|
// The srcdoc-iframe contentWindow Proxy below is itself a fingerprintable tell
|
||||||
|
// (CreepJS `hasIframeProxy`). Honor the opt-out so callers can trade the niche
|
||||||
|
// srcdoc masking for a clean 0% CreepJS fingerprint.
|
||||||
|
if (typeof __abStealth !== 'undefined' && __abStealth.disableIframeProxy) return;
|
||||||
const nativeCreateElement = document.createElement.bind(document);
|
const nativeCreateElement = document.createElement.bind(document);
|
||||||
const nativeSrcdocDescriptor =
|
const nativeSrcdocDescriptor =
|
||||||
typeof HTMLIFrameElement !== 'undefined'
|
typeof HTMLIFrameElement !== 'undefined'
|
||||||
|
|||||||
@@ -352,6 +352,39 @@ pub fn print_response_with_opts(resp: &Response, action: Option<&str>, opts: &Ou
|
|||||||
println!("{}", enabled);
|
println!("{}", enabled);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
// Stealth self-check (`stealth status` / `doctor`)
|
||||||
|
if let Some(s) = data.get("stealthStatus") {
|
||||||
|
let ok = s.get("ok").and_then(|v| v.as_bool()).unwrap_or(false);
|
||||||
|
let mode = s.get("mode").and_then(|v| v.as_str()).unwrap_or("?");
|
||||||
|
println!(
|
||||||
|
"{} stealth: {} · mode: {}",
|
||||||
|
if ok {
|
||||||
|
color::success_indicator().to_string()
|
||||||
|
} else {
|
||||||
|
color::cyan("•")
|
||||||
|
},
|
||||||
|
if ok {
|
||||||
|
"all checks pass"
|
||||||
|
} else {
|
||||||
|
"some checks need attention"
|
||||||
|
},
|
||||||
|
mode
|
||||||
|
);
|
||||||
|
if let Some(checks) = s.get("checks").and_then(|v| v.as_array()) {
|
||||||
|
for c in checks {
|
||||||
|
let pass = c.get("pass").and_then(|v| v.as_bool()).unwrap_or(false);
|
||||||
|
let name = c.get("name").and_then(|v| v.as_str()).unwrap_or("");
|
||||||
|
println!(" {} {}", if pass { "✓" } else { "✗" }, name);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if let Some(ovs) = s.get("overrides").and_then(|v| v.as_array()) {
|
||||||
|
println!(" applied overrides:");
|
||||||
|
for o in ovs.iter().filter_map(|v| v.as_str()) {
|
||||||
|
println!(" {}", color::dim(&format!("· {o}")));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return;
|
||||||
|
}
|
||||||
if let Some(checked) = data.get("checked").and_then(|v| v.as_bool()) {
|
if let Some(checked) = data.get("checked").and_then(|v| v.as_bool()) {
|
||||||
println!("{}", checked);
|
println!("{}", checked);
|
||||||
return;
|
return;
|
||||||
|
|||||||
+1
-1
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "agent-browser-stealth",
|
"name": "agent-browser-stealth",
|
||||||
"version": "0.27.0-fork.46",
|
"version": "0.27.0-fork.48",
|
||||||
"description": "Browser automation CLI for AI agents — stealth fork with anti-detection",
|
"description": "Browser automation CLI for AI agents — stealth fork with anti-detection",
|
||||||
"type": "module",
|
"type": "module",
|
||||||
"packageManager": "pnpm@11.1.3",
|
"packageManager": "pnpm@11.1.3",
|
||||||
|
|||||||
@@ -520,6 +520,10 @@ agent-browser doctor # full diagnosis (env, Chrome, daemons,
|
|||||||
agent-browser doctor --offline --quick # fast, local-only
|
agent-browser doctor --offline --quick # fast, local-only
|
||||||
agent-browser doctor --fix # also run destructive repairs (reinstall Chrome, purge old state, ...)
|
agent-browser doctor --fix # also run destructive repairs (reinstall Chrome, purge old state, ...)
|
||||||
agent-browser doctor --json # structured output for programmatic consumption
|
agent-browser doctor --json # structured output for programmatic consumption
|
||||||
|
agent-browser stealth status # stealth self-check: mode + live probes
|
||||||
|
agent-browser stealth status --json # (webdriver/chrome/plugins/UA) + applied
|
||||||
|
# overrides. Gate a sensitive flow on this
|
||||||
|
# instead of driving an external detector.
|
||||||
```
|
```
|
||||||
|
|
||||||
`doctor` auto-cleans stale socket/pid/version sidecar files on every run.
|
`doctor` auto-cleans stale socket/pid/version sidecar files on every run.
|
||||||
|
|||||||
Reference in New Issue
Block a user