feat(browser): Prevent initialization in browser extensions - #10844

Merged
s1gr1d merged 4 commits into
developfrom
sig-prevent-init-in-extension
Feb 29, 2024
Merged

feat(browser): Prevent initialization in browser extensions#10844
s1gr1d merged 4 commits into
developfrom
sig-prevent-init-in-extension

Conversation

@s1gr1d

@s1gr1ds1gr1d commented Feb 28, 2024

Copy link
Copy Markdown
Member

Prevents initialization inside chrome.* and browser.* extension environments.
Also refactored init() in browser because of eslint warning about too much complexity.
Fixes#10632

@s1gr1ds1gr1d self-assigned this Feb 28, 2024
@s1gr1d
s1gr1d requested a review from mydeaFebruary 28, 2024 13:57
@s1gr1ds1gr1d changed the title Prevent SDK initialization via Sentry.init in browser extensionsfeat(browser): Prevent initialization in browser extensionsFeb 28, 2024
@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 8e2fa68 to 1b85c6bCompareFebruary 28, 2024 15:30
Comment threadpackages/browser/src/sdk.ts Outdated
consoleSandbox(() => {
// eslint-disable-next-line no-console
console.error(
'[Sentry] You cannot run Sentry this way in an extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
'[Sentry] You cannot run Sentry this way in an extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',
'[Sentry] You cannot run Sentry this way in a browser extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',

maybe a bit clearer, wording wise? 🤔

it('should log a browser extension error if executed inside a Chrome extension', () => {
const consoleErrorSpy = jest.spyOn(console, 'error').mockImplementation(() => {});

Object.defineProperty(WINDOW, 'chrome', {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would add an afterEach block that resets this back to undefined, to ensure we don't leak this into other tests!

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added this block to reset it and I also added the test for the regular browser environment at last to make sure this fails directly if browser or chrome is still part of the globals.

@github-actions

github-actionsBot commented Feb 28, 2024

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize
@sentry/browser (incl. Tracing, Replay, Feedback) - Webpack (gzipped)77.33 KB (+0.21% 🔺)
@sentry/browser (incl. Tracing, Replay) - Webpack (gzipped)68.58 KB (+0.23% 🔺)
@sentry/browser (incl. Tracing, Replay with Canvas) - Webpack (gzipped)72.49 KB (+0.22% 🔺)
@sentry/browser (incl. Tracing, Replay) - Webpack with treeshaking flags (gzipped)62.13 KB (+0.26% 🔺)
@sentry/browser (incl. Tracing) - Webpack (gzipped)32.81 KB (+0.49% 🔺)
@sentry/browser (incl. browserTracingIntegration) - Webpack (gzipped)32.81 KB (+0.49% 🔺)
@sentry/browser (incl. Feedback) - Webpack (gzipped)30.96 KB (+0.49% 🔺)
@sentry/browser (incl. sendFeedback) - Webpack (gzipped)30.96 KB (+0.49% 🔺)
@sentry/browser - Webpack (gzipped)22.23 KB (+0.62% 🔺)
@sentry/browser (incl. Tracing, Replay, Feedback) - ES6 CDN Bundle (gzipped)75.73 KB (+0.21% 🔺)
@sentry/browser (incl. Tracing, Replay) - ES6 CDN Bundle (gzipped)67.41 KB (+0.23% 🔺)
@sentry/browser (incl. Tracing) - ES6 CDN Bundle (gzipped)33.25 KB (+0.48% 🔺)
@sentry/browser - ES6 CDN Bundle (gzipped)24.73 KB (+0.6% 🔺)
@sentry/browser (incl. Tracing, Replay) - ES6 CDN Bundle (minified & uncompressed)211.03 KB (+0.14% 🔺)
@sentry/browser (incl. Tracing) - ES6 CDN Bundle (minified & uncompressed)99.75 KB (+0.29% 🔺)
@sentry/browser - ES6 CDN Bundle (minified & uncompressed)73.93 KB (+0.39% 🔺)
@sentry/browser (incl. Tracing) - ES5 CDN Bundle (gzipped)36.31 KB (+0.43% 🔺)
@sentry/react (incl. Tracing, Replay) - Webpack (gzipped)68.85 KB (+0.22% 🔺)
@sentry/react - Webpack (gzipped)22.26 KB (+0.62% 🔺)
@sentry/nextjs Client (incl. Tracing, Replay) - Webpack (gzipped)85.33 KB (+0.17% 🔺)
@sentry/nextjs Client - Webpack (gzipped)49.67 KB (+0.3% 🔺)
@sentry-internal/feedback - Webpack (gzipped)17.03 KB (0%)

@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 1b85c6b to 6516bc9CompareFebruary 28, 2024 16:37
@s1gr1d
s1gr1d requested a review from mydeaFebruary 28, 2024 16:42

@mydeamydea left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

very nice! Added two more very small nits, but this is good to go from my POV! great work :)

import * as Sentry from '@sentry/browser';

window.Sentry = Sentry;
window.browser = { runtime: { id: 'mock-extension-id' } };

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
window.browser={runtime: {id: 'mock-extension-id'}};
// We mock this here to simulate a browser extension
window.browser={runtime: {id: 'mock-extension-id'}};

maybe leave a comment here for our future selves to know why this exists xD

import * as Sentry from '@sentry/browser';

window.Sentry = Sentry;
window.chrome = { runtime: { id: 'mock-extension-id' } };

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
window.chrome={runtime: {id: 'mock-extension-id'}};
// We mock this here to simulate a browser extension
window.chrome={runtime: {id: 'mock-extension-id'}};

@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 6516bc9 to 8c5ebc0CompareFebruary 29, 2024 10:31
@s1gr1d
s1gr1d enabled auto-merge (squash) February 29, 2024 12:23
@s1gr1d
s1gr1d merged commit 784b485 into developFeb 29, 2024
@s1gr1d
s1gr1d deleted the sig-prevent-init-in-extension branch February 29, 2024 13:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Prevent SDK initialization via Sentry.init in Chrome extension

2 participants

@s1gr1d@mydea
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(browser): Prevent initialization in browser extensions - #10844

Merged
s1gr1d merged 4 commits into
developfrom
sig-prevent-init-in-extension
Feb 29, 2024
Merged

feat(browser): Prevent initialization in browser extensions#10844
s1gr1d merged 4 commits into
developfrom
sig-prevent-init-in-extension

Conversation

@s1gr1d

@s1gr1ds1gr1d commented Feb 28, 2024

Copy link
Copy Markdown
Member

Prevents initialization inside chrome.* and browser.* extension environments.
Also refactored init() in browser because of eslint warning about too much complexity.
Fixes#10632

@s1gr1ds1gr1d self-assigned this Feb 28, 2024
@s1gr1d
s1gr1d requested a review from mydeaFebruary 28, 2024 13:57
@s1gr1ds1gr1d changed the title Prevent SDK initialization via Sentry.init in browser extensionsfeat(browser): Prevent initialization in browser extensionsFeb 28, 2024
@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 8e2fa68 to 1b85c6bCompareFebruary 28, 2024 15:30
Comment threadpackages/browser/src/sdk.ts Outdated
consoleSandbox(() => {
// eslint-disable-next-line no-console
console.error(
'[Sentry] You cannot run Sentry this way in an extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
'[Sentry] You cannot run Sentry this way in an extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',
'[Sentry] You cannot run Sentry this way in a browser extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',

maybe a bit clearer, wording wise? 🤔

it('should log a browser extension error if executed inside a Chrome extension', () => {
const consoleErrorSpy = jest.spyOn(console, 'error').mockImplementation(() => {});

Object.defineProperty(WINDOW, 'chrome', {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would add an afterEach block that resets this back to undefined, to ensure we don't leak this into other tests!

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added this block to reset it and I also added the test for the regular browser environment at last to make sure this fails directly if browser or chrome is still part of the globals.

@github-actions

github-actionsBot commented Feb 28, 2024

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize
@sentry/browser (incl. Tracing, Replay, Feedback) - Webpack (gzipped)77.33 KB (+0.21% 🔺)
@sentry/browser (incl. Tracing, Replay) - Webpack (gzipped)68.58 KB (+0.23% 🔺)
@sentry/browser (incl. Tracing, Replay with Canvas) - Webpack (gzipped)72.49 KB (+0.22% 🔺)
@sentry/browser (incl. Tracing, Replay) - Webpack with treeshaking flags (gzipped)62.13 KB (+0.26% 🔺)
@sentry/browser (incl. Tracing) - Webpack (gzipped)32.81 KB (+0.49% 🔺)
@sentry/browser (incl. browserTracingIntegration) - Webpack (gzipped)32.81 KB (+0.49% 🔺)
@sentry/browser (incl. Feedback) - Webpack (gzipped)30.96 KB (+0.49% 🔺)
@sentry/browser (incl. sendFeedback) - Webpack (gzipped)30.96 KB (+0.49% 🔺)
@sentry/browser - Webpack (gzipped)22.23 KB (+0.62% 🔺)
@sentry/browser (incl. Tracing, Replay, Feedback) - ES6 CDN Bundle (gzipped)75.73 KB (+0.21% 🔺)
@sentry/browser (incl. Tracing, Replay) - ES6 CDN Bundle (gzipped)67.41 KB (+0.23% 🔺)
@sentry/browser (incl. Tracing) - ES6 CDN Bundle (gzipped)33.25 KB (+0.48% 🔺)
@sentry/browser - ES6 CDN Bundle (gzipped)24.73 KB (+0.6% 🔺)
@sentry/browser (incl. Tracing, Replay) - ES6 CDN Bundle (minified & uncompressed)211.03 KB (+0.14% 🔺)
@sentry/browser (incl. Tracing) - ES6 CDN Bundle (minified & uncompressed)99.75 KB (+0.29% 🔺)
@sentry/browser - ES6 CDN Bundle (minified & uncompressed)73.93 KB (+0.39% 🔺)
@sentry/browser (incl. Tracing) - ES5 CDN Bundle (gzipped)36.31 KB (+0.43% 🔺)
@sentry/react (incl. Tracing, Replay) - Webpack (gzipped)68.85 KB (+0.22% 🔺)
@sentry/react - Webpack (gzipped)22.26 KB (+0.62% 🔺)
@sentry/nextjs Client (incl. Tracing, Replay) - Webpack (gzipped)85.33 KB (+0.17% 🔺)
@sentry/nextjs Client - Webpack (gzipped)49.67 KB (+0.3% 🔺)
@sentry-internal/feedback - Webpack (gzipped)17.03 KB (0%)

@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 1b85c6b to 6516bc9CompareFebruary 28, 2024 16:37
@s1gr1d
s1gr1d requested a review from mydeaFebruary 28, 2024 16:42

@mydeamydea left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

very nice! Added two more very small nits, but this is good to go from my POV! great work :)

import * as Sentry from '@sentry/browser';

window.Sentry = Sentry;
window.browser = { runtime: { id: 'mock-extension-id' } };

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
window.browser={runtime: {id: 'mock-extension-id'}};
// We mock this here to simulate a browser extension
window.browser={runtime: {id: 'mock-extension-id'}};

maybe leave a comment here for our future selves to know why this exists xD

import * as Sentry from '@sentry/browser';

window.Sentry = Sentry;
window.chrome = { runtime: { id: 'mock-extension-id' } };

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
window.chrome={runtime: {id: 'mock-extension-id'}};
// We mock this here to simulate a browser extension
window.chrome={runtime: {id: 'mock-extension-id'}};

@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 6516bc9 to 8c5ebc0CompareFebruary 29, 2024 10:31
@s1gr1d
s1gr1d enabled auto-merge (squash) February 29, 2024 12:23
@s1gr1d
s1gr1d merged commit 784b485 into developFeb 29, 2024
@s1gr1d
s1gr1d deleted the sig-prevent-init-in-extension branch February 29, 2024 13:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Prevent SDK initialization via Sentry.init in Chrome extension

2 participants

@s1gr1d@mydea
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(browser): Prevent initialization in browser extensions - #10844

Merged
s1gr1d merged 4 commits into
developfrom
sig-prevent-init-in-extension
Feb 29, 2024
Merged

feat(browser): Prevent initialization in browser extensions#10844
s1gr1d merged 4 commits into
developfrom
sig-prevent-init-in-extension

Conversation

@s1gr1d

@s1gr1ds1gr1d commented Feb 28, 2024

Copy link
Copy Markdown
Member

Prevents initialization inside chrome.* and browser.* extension environments.
Also refactored init() in browser because of eslint warning about too much complexity.
Fixes#10632

@s1gr1ds1gr1d self-assigned this Feb 28, 2024
@s1gr1d
s1gr1d requested a review from mydeaFebruary 28, 2024 13:57
@s1gr1ds1gr1d changed the title Prevent SDK initialization via Sentry.init in browser extensionsfeat(browser): Prevent initialization in browser extensionsFeb 28, 2024
@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 8e2fa68 to 1b85c6bCompareFebruary 28, 2024 15:30
Comment threadpackages/browser/src/sdk.ts Outdated
consoleSandbox(() => {
// eslint-disable-next-line no-console
console.error(
'[Sentry] You cannot run Sentry this way in an extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
'[Sentry] You cannot run Sentry this way in an extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',
'[Sentry] You cannot run Sentry this way in a browser extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',

maybe a bit clearer, wording wise? 🤔

it('should log a browser extension error if executed inside a Chrome extension', () => {
const consoleErrorSpy = jest.spyOn(console, 'error').mockImplementation(() => {});

Object.defineProperty(WINDOW, 'chrome', {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would add an afterEach block that resets this back to undefined, to ensure we don't leak this into other tests!

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added this block to reset it and I also added the test for the regular browser environment at last to make sure this fails directly if browser or chrome is still part of the globals.

@github-actions

github-actionsBot commented Feb 28, 2024

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize
@sentry/browser (incl. Tracing, Replay, Feedback) - Webpack (gzipped)77.33 KB (+0.21% 🔺)
@sentry/browser (incl. Tracing, Replay) - Webpack (gzipped)68.58 KB (+0.23% 🔺)
@sentry/browser (incl. Tracing, Replay with Canvas) - Webpack (gzipped)72.49 KB (+0.22% 🔺)
@sentry/browser (incl. Tracing, Replay) - Webpack with treeshaking flags (gzipped)62.13 KB (+0.26% 🔺)
@sentry/browser (incl. Tracing) - Webpack (gzipped)32.81 KB (+0.49% 🔺)
@sentry/browser (incl. browserTracingIntegration) - Webpack (gzipped)32.81 KB (+0.49% 🔺)
@sentry/browser (incl. Feedback) - Webpack (gzipped)30.96 KB (+0.49% 🔺)
@sentry/browser (incl. sendFeedback) - Webpack (gzipped)30.96 KB (+0.49% 🔺)
@sentry/browser - Webpack (gzipped)22.23 KB (+0.62% 🔺)
@sentry/browser (incl. Tracing, Replay, Feedback) - ES6 CDN Bundle (gzipped)75.73 KB (+0.21% 🔺)
@sentry/browser (incl. Tracing, Replay) - ES6 CDN Bundle (gzipped)67.41 KB (+0.23% 🔺)
@sentry/browser (incl. Tracing) - ES6 CDN Bundle (gzipped)33.25 KB (+0.48% 🔺)
@sentry/browser - ES6 CDN Bundle (gzipped)24.73 KB (+0.6% 🔺)
@sentry/browser (incl. Tracing, Replay) - ES6 CDN Bundle (minified & uncompressed)211.03 KB (+0.14% 🔺)
@sentry/browser (incl. Tracing) - ES6 CDN Bundle (minified & uncompressed)99.75 KB (+0.29% 🔺)
@sentry/browser - ES6 CDN Bundle (minified & uncompressed)73.93 KB (+0.39% 🔺)
@sentry/browser (incl. Tracing) - ES5 CDN Bundle (gzipped)36.31 KB (+0.43% 🔺)
@sentry/react (incl. Tracing, Replay) - Webpack (gzipped)68.85 KB (+0.22% 🔺)
@sentry/react - Webpack (gzipped)22.26 KB (+0.62% 🔺)
@sentry/nextjs Client (incl. Tracing, Replay) - Webpack (gzipped)85.33 KB (+0.17% 🔺)
@sentry/nextjs Client - Webpack (gzipped)49.67 KB (+0.3% 🔺)
@sentry-internal/feedback - Webpack (gzipped)17.03 KB (0%)

@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 1b85c6b to 6516bc9CompareFebruary 28, 2024 16:37
@s1gr1d
s1gr1d requested a review from mydeaFebruary 28, 2024 16:42

@mydeamydea left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

very nice! Added two more very small nits, but this is good to go from my POV! great work :)

import * as Sentry from '@sentry/browser';

window.Sentry = Sentry;
window.browser = { runtime: { id: 'mock-extension-id' } };

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
window.browser={runtime: {id: 'mock-extension-id'}};
// We mock this here to simulate a browser extension
window.browser={runtime: {id: 'mock-extension-id'}};

maybe leave a comment here for our future selves to know why this exists xD

import * as Sentry from '@sentry/browser';

window.Sentry = Sentry;
window.chrome = { runtime: { id: 'mock-extension-id' } };

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
window.chrome={runtime: {id: 'mock-extension-id'}};
// We mock this here to simulate a browser extension
window.chrome={runtime: {id: 'mock-extension-id'}};

@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 6516bc9 to 8c5ebc0CompareFebruary 29, 2024 10:31
@s1gr1d
s1gr1d enabled auto-merge (squash) February 29, 2024 12:23
@s1gr1d
s1gr1d merged commit 784b485 into developFeb 29, 2024
@s1gr1d
s1gr1d deleted the sig-prevent-init-in-extension branch February 29, 2024 13:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Prevent SDK initialization via Sentry.init in Chrome extension

2 participants

@s1gr1d@mydea
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(browser): Prevent initialization in browser extensions - #10844

Merged
s1gr1d merged 4 commits into
developfrom
sig-prevent-init-in-extension
Feb 29, 2024
Merged

feat(browser): Prevent initialization in browser extensions#10844
s1gr1d merged 4 commits into
developfrom
sig-prevent-init-in-extension

Conversation

@s1gr1d

@s1gr1ds1gr1d commented Feb 28, 2024

Copy link
Copy Markdown
Member

Prevents initialization inside chrome.* and browser.* extension environments.
Also refactored init() in browser because of eslint warning about too much complexity.
Fixes#10632

@s1gr1ds1gr1d self-assigned this Feb 28, 2024
@s1gr1d
s1gr1d requested a review from mydeaFebruary 28, 2024 13:57
@s1gr1ds1gr1d changed the title Prevent SDK initialization via Sentry.init in browser extensionsfeat(browser): Prevent initialization in browser extensionsFeb 28, 2024
@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 8e2fa68 to 1b85c6bCompareFebruary 28, 2024 15:30
Comment threadpackages/browser/src/sdk.ts Outdated
consoleSandbox(() => {
// eslint-disable-next-line no-console
console.error(
'[Sentry] You cannot run Sentry this way in an extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
'[Sentry] You cannot run Sentry this way in an extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',
'[Sentry] You cannot run Sentry this way in a browser extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',

maybe a bit clearer, wording wise? 🤔

it('should log a browser extension error if executed inside a Chrome extension', () => {
const consoleErrorSpy = jest.spyOn(console, 'error').mockImplementation(() => {});

Object.defineProperty(WINDOW, 'chrome', {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would add an afterEach block that resets this back to undefined, to ensure we don't leak this into other tests!

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added this block to reset it and I also added the test for the regular browser environment at last to make sure this fails directly if browser or chrome is still part of the globals.

@github-actions

github-actionsBot commented Feb 28, 2024

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize
@sentry/browser (incl. Tracing, Replay, Feedback) - Webpack (gzipped)77.33 KB (+0.21% 🔺)
@sentry/browser (incl. Tracing, Replay) - Webpack (gzipped)68.58 KB (+0.23% 🔺)
@sentry/browser (incl. Tracing, Replay with Canvas) - Webpack (gzipped)72.49 KB (+0.22% 🔺)
@sentry/browser (incl. Tracing, Replay) - Webpack with treeshaking flags (gzipped)62.13 KB (+0.26% 🔺)
@sentry/browser (incl. Tracing) - Webpack (gzipped)32.81 KB (+0.49% 🔺)
@sentry/browser (incl. browserTracingIntegration) - Webpack (gzipped)32.81 KB (+0.49% 🔺)
@sentry/browser (incl. Feedback) - Webpack (gzipped)30.96 KB (+0.49% 🔺)
@sentry/browser (incl. sendFeedback) - Webpack (gzipped)30.96 KB (+0.49% 🔺)
@sentry/browser - Webpack (gzipped)22.23 KB (+0.62% 🔺)
@sentry/browser (incl. Tracing, Replay, Feedback) - ES6 CDN Bundle (gzipped)75.73 KB (+0.21% 🔺)
@sentry/browser (incl. Tracing, Replay) - ES6 CDN Bundle (gzipped)67.41 KB (+0.23% 🔺)
@sentry/browser (incl. Tracing) - ES6 CDN Bundle (gzipped)33.25 KB (+0.48% 🔺)
@sentry/browser - ES6 CDN Bundle (gzipped)24.73 KB (+0.6% 🔺)
@sentry/browser (incl. Tracing, Replay) - ES6 CDN Bundle (minified & uncompressed)211.03 KB (+0.14% 🔺)
@sentry/browser (incl. Tracing) - ES6 CDN Bundle (minified & uncompressed)99.75 KB (+0.29% 🔺)
@sentry/browser - ES6 CDN Bundle (minified & uncompressed)73.93 KB (+0.39% 🔺)
@sentry/browser (incl. Tracing) - ES5 CDN Bundle (gzipped)36.31 KB (+0.43% 🔺)
@sentry/react (incl. Tracing, Replay) - Webpack (gzipped)68.85 KB (+0.22% 🔺)
@sentry/react - Webpack (gzipped)22.26 KB (+0.62% 🔺)
@sentry/nextjs Client (incl. Tracing, Replay) - Webpack (gzipped)85.33 KB (+0.17% 🔺)
@sentry/nextjs Client - Webpack (gzipped)49.67 KB (+0.3% 🔺)
@sentry-internal/feedback - Webpack (gzipped)17.03 KB (0%)

@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 1b85c6b to 6516bc9CompareFebruary 28, 2024 16:37
@s1gr1d
s1gr1d requested a review from mydeaFebruary 28, 2024 16:42

@mydeamydea left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

very nice! Added two more very small nits, but this is good to go from my POV! great work :)

import * as Sentry from '@sentry/browser';

window.Sentry = Sentry;
window.browser = { runtime: { id: 'mock-extension-id' } };

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
window.browser={runtime: {id: 'mock-extension-id'}};
// We mock this here to simulate a browser extension
window.browser={runtime: {id: 'mock-extension-id'}};

maybe leave a comment here for our future selves to know why this exists xD

import * as Sentry from '@sentry/browser';

window.Sentry = Sentry;
window.chrome = { runtime: { id: 'mock-extension-id' } };

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
window.chrome={runtime: {id: 'mock-extension-id'}};
// We mock this here to simulate a browser extension
window.chrome={runtime: {id: 'mock-extension-id'}};

@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 6516bc9 to 8c5ebc0CompareFebruary 29, 2024 10:31
@s1gr1d
s1gr1d enabled auto-merge (squash) February 29, 2024 12:23
@s1gr1d
s1gr1d merged commit 784b485 into developFeb 29, 2024
@s1gr1d
s1gr1d deleted the sig-prevent-init-in-extension branch February 29, 2024 13:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Prevent SDK initialization via Sentry.init in Chrome extension

2 participants

@s1gr1d@mydea
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(browser): Prevent initialization in browser extensions - #10844

Merged
s1gr1d merged 4 commits into
developfrom
sig-prevent-init-in-extension
Feb 29, 2024
Merged

feat(browser): Prevent initialization in browser extensions#10844
s1gr1d merged 4 commits into
developfrom
sig-prevent-init-in-extension

Conversation

@s1gr1d

@s1gr1ds1gr1d commented Feb 28, 2024

Copy link
Copy Markdown
Member

Prevents initialization inside chrome.* and browser.* extension environments.
Also refactored init() in browser because of eslint warning about too much complexity.
Fixes#10632

@s1gr1ds1gr1d self-assigned this Feb 28, 2024
@s1gr1d
s1gr1d requested a review from mydeaFebruary 28, 2024 13:57
@s1gr1ds1gr1d changed the title Prevent SDK initialization via Sentry.init in browser extensionsfeat(browser): Prevent initialization in browser extensionsFeb 28, 2024
@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 8e2fa68 to 1b85c6bCompareFebruary 28, 2024 15:30
Comment threadpackages/browser/src/sdk.ts Outdated
consoleSandbox(() => {
// eslint-disable-next-line no-console
console.error(
'[Sentry] You cannot run Sentry this way in an extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
'[Sentry] You cannot run Sentry this way in an extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',
'[Sentry] You cannot run Sentry this way in a browser extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',

maybe a bit clearer, wording wise? 🤔

it('should log a browser extension error if executed inside a Chrome extension', () => {
const consoleErrorSpy = jest.spyOn(console, 'error').mockImplementation(() => {});

Object.defineProperty(WINDOW, 'chrome', {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would add an afterEach block that resets this back to undefined, to ensure we don't leak this into other tests!

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added this block to reset it and I also added the test for the regular browser environment at last to make sure this fails directly if browser or chrome is still part of the globals.

@github-actions

github-actionsBot commented Feb 28, 2024

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize
@sentry/browser (incl. Tracing, Replay, Feedback) - Webpack (gzipped)77.33 KB (+0.21% 🔺)
@sentry/browser (incl. Tracing, Replay) - Webpack (gzipped)68.58 KB (+0.23% 🔺)
@sentry/browser (incl. Tracing, Replay with Canvas) - Webpack (gzipped)72.49 KB (+0.22% 🔺)
@sentry/browser (incl. Tracing, Replay) - Webpack with treeshaking flags (gzipped)62.13 KB (+0.26% 🔺)
@sentry/browser (incl. Tracing) - Webpack (gzipped)32.81 KB (+0.49% 🔺)
@sentry/browser (incl. browserTracingIntegration) - Webpack (gzipped)32.81 KB (+0.49% 🔺)
@sentry/browser (incl. Feedback) - Webpack (gzipped)30.96 KB (+0.49% 🔺)
@sentry/browser (incl. sendFeedback) - Webpack (gzipped)30.96 KB (+0.49% 🔺)
@sentry/browser - Webpack (gzipped)22.23 KB (+0.62% 🔺)
@sentry/browser (incl. Tracing, Replay, Feedback) - ES6 CDN Bundle (gzipped)75.73 KB (+0.21% 🔺)
@sentry/browser (incl. Tracing, Replay) - ES6 CDN Bundle (gzipped)67.41 KB (+0.23% 🔺)
@sentry/browser (incl. Tracing) - ES6 CDN Bundle (gzipped)33.25 KB (+0.48% 🔺)
@sentry/browser - ES6 CDN Bundle (gzipped)24.73 KB (+0.6% 🔺)
@sentry/browser (incl. Tracing, Replay) - ES6 CDN Bundle (minified & uncompressed)211.03 KB (+0.14% 🔺)
@sentry/browser (incl. Tracing) - ES6 CDN Bundle (minified & uncompressed)99.75 KB (+0.29% 🔺)
@sentry/browser - ES6 CDN Bundle (minified & uncompressed)73.93 KB (+0.39% 🔺)
@sentry/browser (incl. Tracing) - ES5 CDN Bundle (gzipped)36.31 KB (+0.43% 🔺)
@sentry/react (incl. Tracing, Replay) - Webpack (gzipped)68.85 KB (+0.22% 🔺)
@sentry/react - Webpack (gzipped)22.26 KB (+0.62% 🔺)
@sentry/nextjs Client (incl. Tracing, Replay) - Webpack (gzipped)85.33 KB (+0.17% 🔺)
@sentry/nextjs Client - Webpack (gzipped)49.67 KB (+0.3% 🔺)
@sentry-internal/feedback - Webpack (gzipped)17.03 KB (0%)

@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 1b85c6b to 6516bc9CompareFebruary 28, 2024 16:37
@s1gr1d
s1gr1d requested a review from mydeaFebruary 28, 2024 16:42

@mydeamydea left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

very nice! Added two more very small nits, but this is good to go from my POV! great work :)

import * as Sentry from '@sentry/browser';

window.Sentry = Sentry;
window.browser = { runtime: { id: 'mock-extension-id' } };

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
window.browser={runtime: {id: 'mock-extension-id'}};
// We mock this here to simulate a browser extension
window.browser={runtime: {id: 'mock-extension-id'}};

maybe leave a comment here for our future selves to know why this exists xD

import * as Sentry from '@sentry/browser';

window.Sentry = Sentry;
window.chrome = { runtime: { id: 'mock-extension-id' } };

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
window.chrome={runtime: {id: 'mock-extension-id'}};
// We mock this here to simulate a browser extension
window.chrome={runtime: {id: 'mock-extension-id'}};

@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 6516bc9 to 8c5ebc0CompareFebruary 29, 2024 10:31
@s1gr1d
s1gr1d enabled auto-merge (squash) February 29, 2024 12:23
@s1gr1d
s1gr1d merged commit 784b485 into developFeb 29, 2024
@s1gr1d
s1gr1d deleted the sig-prevent-init-in-extension branch February 29, 2024 13:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Prevent SDK initialization via Sentry.init in Chrome extension

2 participants

@s1gr1d@mydea
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(browser): Prevent initialization in browser extensions - #10844

Merged
s1gr1d merged 4 commits into
developfrom
sig-prevent-init-in-extension
Feb 29, 2024
Merged

feat(browser): Prevent initialization in browser extensions#10844
s1gr1d merged 4 commits into
developfrom
sig-prevent-init-in-extension

Conversation

@s1gr1d

@s1gr1ds1gr1d commented Feb 28, 2024

Copy link
Copy Markdown
Member

Prevents initialization inside chrome.* and browser.* extension environments.
Also refactored init() in browser because of eslint warning about too much complexity.
Fixes#10632

@s1gr1ds1gr1d self-assigned this Feb 28, 2024
@s1gr1d
s1gr1d requested a review from mydeaFebruary 28, 2024 13:57
@s1gr1ds1gr1d changed the title Prevent SDK initialization via Sentry.init in browser extensionsfeat(browser): Prevent initialization in browser extensionsFeb 28, 2024
@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 8e2fa68 to 1b85c6bCompareFebruary 28, 2024 15:30
Comment threadpackages/browser/src/sdk.ts Outdated
consoleSandbox(() => {
// eslint-disable-next-line no-console
console.error(
'[Sentry] You cannot run Sentry this way in an extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
'[Sentry] You cannot run Sentry this way in an extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',
'[Sentry] You cannot run Sentry this way in a browser extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',

maybe a bit clearer, wording wise? 🤔

it('should log a browser extension error if executed inside a Chrome extension', () => {
const consoleErrorSpy = jest.spyOn(console, 'error').mockImplementation(() => {});

Object.defineProperty(WINDOW, 'chrome', {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would add an afterEach block that resets this back to undefined, to ensure we don't leak this into other tests!

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added this block to reset it and I also added the test for the regular browser environment at last to make sure this fails directly if browser or chrome is still part of the globals.

@github-actions

github-actionsBot commented Feb 28, 2024

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize
@sentry/browser (incl. Tracing, Replay, Feedback) - Webpack (gzipped)77.33 KB (+0.21% 🔺)
@sentry/browser (incl. Tracing, Replay) - Webpack (gzipped)68.58 KB (+0.23% 🔺)
@sentry/browser (incl. Tracing, Replay with Canvas) - Webpack (gzipped)72.49 KB (+0.22% 🔺)
@sentry/browser (incl. Tracing, Replay) - Webpack with treeshaking flags (gzipped)62.13 KB (+0.26% 🔺)
@sentry/browser (incl. Tracing) - Webpack (gzipped)32.81 KB (+0.49% 🔺)
@sentry/browser (incl. browserTracingIntegration) - Webpack (gzipped)32.81 KB (+0.49% 🔺)
@sentry/browser (incl. Feedback) - Webpack (gzipped)30.96 KB (+0.49% 🔺)
@sentry/browser (incl. sendFeedback) - Webpack (gzipped)30.96 KB (+0.49% 🔺)
@sentry/browser - Webpack (gzipped)22.23 KB (+0.62% 🔺)
@sentry/browser (incl. Tracing, Replay, Feedback) - ES6 CDN Bundle (gzipped)75.73 KB (+0.21% 🔺)
@sentry/browser (incl. Tracing, Replay) - ES6 CDN Bundle (gzipped)67.41 KB (+0.23% 🔺)
@sentry/browser (incl. Tracing) - ES6 CDN Bundle (gzipped)33.25 KB (+0.48% 🔺)
@sentry/browser - ES6 CDN Bundle (gzipped)24.73 KB (+0.6% 🔺)
@sentry/browser (incl. Tracing, Replay) - ES6 CDN Bundle (minified & uncompressed)211.03 KB (+0.14% 🔺)
@sentry/browser (incl. Tracing) - ES6 CDN Bundle (minified & uncompressed)99.75 KB (+0.29% 🔺)
@sentry/browser - ES6 CDN Bundle (minified & uncompressed)73.93 KB (+0.39% 🔺)
@sentry/browser (incl. Tracing) - ES5 CDN Bundle (gzipped)36.31 KB (+0.43% 🔺)
@sentry/react (incl. Tracing, Replay) - Webpack (gzipped)68.85 KB (+0.22% 🔺)
@sentry/react - Webpack (gzipped)22.26 KB (+0.62% 🔺)
@sentry/nextjs Client (incl. Tracing, Replay) - Webpack (gzipped)85.33 KB (+0.17% 🔺)
@sentry/nextjs Client - Webpack (gzipped)49.67 KB (+0.3% 🔺)
@sentry-internal/feedback - Webpack (gzipped)17.03 KB (0%)

@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 1b85c6b to 6516bc9CompareFebruary 28, 2024 16:37
@s1gr1d
s1gr1d requested a review from mydeaFebruary 28, 2024 16:42

@mydeamydea left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

very nice! Added two more very small nits, but this is good to go from my POV! great work :)

import * as Sentry from '@sentry/browser';

window.Sentry = Sentry;
window.browser = { runtime: { id: 'mock-extension-id' } };

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
window.browser={runtime: {id: 'mock-extension-id'}};
// We mock this here to simulate a browser extension
window.browser={runtime: {id: 'mock-extension-id'}};

maybe leave a comment here for our future selves to know why this exists xD

import * as Sentry from '@sentry/browser';

window.Sentry = Sentry;
window.chrome = { runtime: { id: 'mock-extension-id' } };

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
window.chrome={runtime: {id: 'mock-extension-id'}};
// We mock this here to simulate a browser extension
window.chrome={runtime: {id: 'mock-extension-id'}};

@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 6516bc9 to 8c5ebc0CompareFebruary 29, 2024 10:31
@s1gr1d
s1gr1d enabled auto-merge (squash) February 29, 2024 12:23
@s1gr1d
s1gr1d merged commit 784b485 into developFeb 29, 2024
@s1gr1d
s1gr1d deleted the sig-prevent-init-in-extension branch February 29, 2024 13:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Prevent SDK initialization via Sentry.init in Chrome extension

2 participants

@s1gr1d@mydea
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(browser): Prevent initialization in browser extensions - #10844

Merged
s1gr1d merged 4 commits into
developfrom
sig-prevent-init-in-extension
Feb 29, 2024
Merged

feat(browser): Prevent initialization in browser extensions#10844
s1gr1d merged 4 commits into
developfrom
sig-prevent-init-in-extension

Conversation

@s1gr1d

@s1gr1ds1gr1d commented Feb 28, 2024

Copy link
Copy Markdown
Member

Prevents initialization inside chrome.* and browser.* extension environments.
Also refactored init() in browser because of eslint warning about too much complexity.
Fixes#10632

@s1gr1ds1gr1d self-assigned this Feb 28, 2024
@s1gr1d
s1gr1d requested a review from mydeaFebruary 28, 2024 13:57
@s1gr1ds1gr1d changed the title Prevent SDK initialization via Sentry.init in browser extensionsfeat(browser): Prevent initialization in browser extensionsFeb 28, 2024
@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 8e2fa68 to 1b85c6bCompareFebruary 28, 2024 15:30
Comment threadpackages/browser/src/sdk.ts Outdated
consoleSandbox(() => {
// eslint-disable-next-line no-console
console.error(
'[Sentry] You cannot run Sentry this way in an extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
'[Sentry] You cannot run Sentry this way in an extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',
'[Sentry] You cannot run Sentry this way in a browser extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',

maybe a bit clearer, wording wise? 🤔

it('should log a browser extension error if executed inside a Chrome extension', () => {
const consoleErrorSpy = jest.spyOn(console, 'error').mockImplementation(() => {});

Object.defineProperty(WINDOW, 'chrome', {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would add an afterEach block that resets this back to undefined, to ensure we don't leak this into other tests!

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added this block to reset it and I also added the test for the regular browser environment at last to make sure this fails directly if browser or chrome is still part of the globals.

@github-actions

github-actionsBot commented Feb 28, 2024

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize
@sentry/browser (incl. Tracing, Replay, Feedback) - Webpack (gzipped)77.33 KB (+0.21% 🔺)
@sentry/browser (incl. Tracing, Replay) - Webpack (gzipped)68.58 KB (+0.23% 🔺)
@sentry/browser (incl. Tracing, Replay with Canvas) - Webpack (gzipped)72.49 KB (+0.22% 🔺)
@sentry/browser (incl. Tracing, Replay) - Webpack with treeshaking flags (gzipped)62.13 KB (+0.26% 🔺)
@sentry/browser (incl. Tracing) - Webpack (gzipped)32.81 KB (+0.49% 🔺)
@sentry/browser (incl. browserTracingIntegration) - Webpack (gzipped)32.81 KB (+0.49% 🔺)
@sentry/browser (incl. Feedback) - Webpack (gzipped)30.96 KB (+0.49% 🔺)
@sentry/browser (incl. sendFeedback) - Webpack (gzipped)30.96 KB (+0.49% 🔺)
@sentry/browser - Webpack (gzipped)22.23 KB (+0.62% 🔺)
@sentry/browser (incl. Tracing, Replay, Feedback) - ES6 CDN Bundle (gzipped)75.73 KB (+0.21% 🔺)
@sentry/browser (incl. Tracing, Replay) - ES6 CDN Bundle (gzipped)67.41 KB (+0.23% 🔺)
@sentry/browser (incl. Tracing) - ES6 CDN Bundle (gzipped)33.25 KB (+0.48% 🔺)
@sentry/browser - ES6 CDN Bundle (gzipped)24.73 KB (+0.6% 🔺)
@sentry/browser (incl. Tracing, Replay) - ES6 CDN Bundle (minified & uncompressed)211.03 KB (+0.14% 🔺)
@sentry/browser (incl. Tracing) - ES6 CDN Bundle (minified & uncompressed)99.75 KB (+0.29% 🔺)
@sentry/browser - ES6 CDN Bundle (minified & uncompressed)73.93 KB (+0.39% 🔺)
@sentry/browser (incl. Tracing) - ES5 CDN Bundle (gzipped)36.31 KB (+0.43% 🔺)
@sentry/react (incl. Tracing, Replay) - Webpack (gzipped)68.85 KB (+0.22% 🔺)
@sentry/react - Webpack (gzipped)22.26 KB (+0.62% 🔺)
@sentry/nextjs Client (incl. Tracing, Replay) - Webpack (gzipped)85.33 KB (+0.17% 🔺)
@sentry/nextjs Client - Webpack (gzipped)49.67 KB (+0.3% 🔺)
@sentry-internal/feedback - Webpack (gzipped)17.03 KB (0%)

@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 1b85c6b to 6516bc9CompareFebruary 28, 2024 16:37
@s1gr1d
s1gr1d requested a review from mydeaFebruary 28, 2024 16:42

@mydeamydea left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

very nice! Added two more very small nits, but this is good to go from my POV! great work :)

import * as Sentry from '@sentry/browser';

window.Sentry = Sentry;
window.browser = { runtime: { id: 'mock-extension-id' } };

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
window.browser={runtime: {id: 'mock-extension-id'}};
// We mock this here to simulate a browser extension
window.browser={runtime: {id: 'mock-extension-id'}};

maybe leave a comment here for our future selves to know why this exists xD

import * as Sentry from '@sentry/browser';

window.Sentry = Sentry;
window.chrome = { runtime: { id: 'mock-extension-id' } };

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
window.chrome={runtime: {id: 'mock-extension-id'}};
// We mock this here to simulate a browser extension
window.chrome={runtime: {id: 'mock-extension-id'}};

@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 6516bc9 to 8c5ebc0CompareFebruary 29, 2024 10:31
@s1gr1d
s1gr1d enabled auto-merge (squash) February 29, 2024 12:23
@s1gr1d
s1gr1d merged commit 784b485 into developFeb 29, 2024
@s1gr1d
s1gr1d deleted the sig-prevent-init-in-extension branch February 29, 2024 13:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Prevent SDK initialization via Sentry.init in Chrome extension

2 participants

@s1gr1d@mydea
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(browser): Prevent initialization in browser extensions - #10844

Merged
s1gr1d merged 4 commits into
developfrom
sig-prevent-init-in-extension
Feb 29, 2024
Merged

feat(browser): Prevent initialization in browser extensions#10844
s1gr1d merged 4 commits into
developfrom
sig-prevent-init-in-extension

Conversation

@s1gr1d

@s1gr1ds1gr1d commented Feb 28, 2024

Copy link
Copy Markdown
Member

Prevents initialization inside chrome.* and browser.* extension environments.
Also refactored init() in browser because of eslint warning about too much complexity.
Fixes#10632

@s1gr1ds1gr1d self-assigned this Feb 28, 2024
@s1gr1d
s1gr1d requested a review from mydeaFebruary 28, 2024 13:57
@s1gr1ds1gr1d changed the title Prevent SDK initialization via Sentry.init in browser extensionsfeat(browser): Prevent initialization in browser extensionsFeb 28, 2024
@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 8e2fa68 to 1b85c6bCompareFebruary 28, 2024 15:30
Comment threadpackages/browser/src/sdk.ts Outdated
consoleSandbox(() => {
// eslint-disable-next-line no-console
console.error(
'[Sentry] You cannot run Sentry this way in an extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
'[Sentry] You cannot run Sentry this way in an extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',
'[Sentry] You cannot run Sentry this way in a browser extension, check: https://docs.sentry.io/platforms/javascript/troubleshooting/#setting-up-sentry-in-shared-environments-eg-browser-extensions',

maybe a bit clearer, wording wise? 🤔

it('should log a browser extension error if executed inside a Chrome extension', () => {
const consoleErrorSpy = jest.spyOn(console, 'error').mockImplementation(() => {});

Object.defineProperty(WINDOW, 'chrome', {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would add an afterEach block that resets this back to undefined, to ensure we don't leak this into other tests!

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added this block to reset it and I also added the test for the regular browser environment at last to make sure this fails directly if browser or chrome is still part of the globals.

@github-actions

github-actionsBot commented Feb 28, 2024

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize
@sentry/browser (incl. Tracing, Replay, Feedback) - Webpack (gzipped)77.33 KB (+0.21% 🔺)
@sentry/browser (incl. Tracing, Replay) - Webpack (gzipped)68.58 KB (+0.23% 🔺)
@sentry/browser (incl. Tracing, Replay with Canvas) - Webpack (gzipped)72.49 KB (+0.22% 🔺)
@sentry/browser (incl. Tracing, Replay) - Webpack with treeshaking flags (gzipped)62.13 KB (+0.26% 🔺)
@sentry/browser (incl. Tracing) - Webpack (gzipped)32.81 KB (+0.49% 🔺)
@sentry/browser (incl. browserTracingIntegration) - Webpack (gzipped)32.81 KB (+0.49% 🔺)
@sentry/browser (incl. Feedback) - Webpack (gzipped)30.96 KB (+0.49% 🔺)
@sentry/browser (incl. sendFeedback) - Webpack (gzipped)30.96 KB (+0.49% 🔺)
@sentry/browser - Webpack (gzipped)22.23 KB (+0.62% 🔺)
@sentry/browser (incl. Tracing, Replay, Feedback) - ES6 CDN Bundle (gzipped)75.73 KB (+0.21% 🔺)
@sentry/browser (incl. Tracing, Replay) - ES6 CDN Bundle (gzipped)67.41 KB (+0.23% 🔺)
@sentry/browser (incl. Tracing) - ES6 CDN Bundle (gzipped)33.25 KB (+0.48% 🔺)
@sentry/browser - ES6 CDN Bundle (gzipped)24.73 KB (+0.6% 🔺)
@sentry/browser (incl. Tracing, Replay) - ES6 CDN Bundle (minified & uncompressed)211.03 KB (+0.14% 🔺)
@sentry/browser (incl. Tracing) - ES6 CDN Bundle (minified & uncompressed)99.75 KB (+0.29% 🔺)
@sentry/browser - ES6 CDN Bundle (minified & uncompressed)73.93 KB (+0.39% 🔺)
@sentry/browser (incl. Tracing) - ES5 CDN Bundle (gzipped)36.31 KB (+0.43% 🔺)
@sentry/react (incl. Tracing, Replay) - Webpack (gzipped)68.85 KB (+0.22% 🔺)
@sentry/react - Webpack (gzipped)22.26 KB (+0.62% 🔺)
@sentry/nextjs Client (incl. Tracing, Replay) - Webpack (gzipped)85.33 KB (+0.17% 🔺)
@sentry/nextjs Client - Webpack (gzipped)49.67 KB (+0.3% 🔺)
@sentry-internal/feedback - Webpack (gzipped)17.03 KB (0%)

@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 1b85c6b to 6516bc9CompareFebruary 28, 2024 16:37
@s1gr1d
s1gr1d requested a review from mydeaFebruary 28, 2024 16:42

@mydeamydea left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

very nice! Added two more very small nits, but this is good to go from my POV! great work :)

import * as Sentry from '@sentry/browser';

window.Sentry = Sentry;
window.browser = { runtime: { id: 'mock-extension-id' } };

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
window.browser={runtime: {id: 'mock-extension-id'}};
// We mock this here to simulate a browser extension
window.browser={runtime: {id: 'mock-extension-id'}};

maybe leave a comment here for our future selves to know why this exists xD

import * as Sentry from '@sentry/browser';

window.Sentry = Sentry;
window.chrome = { runtime: { id: 'mock-extension-id' } };

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
window.chrome={runtime: {id: 'mock-extension-id'}};
// We mock this here to simulate a browser extension
window.chrome={runtime: {id: 'mock-extension-id'}};

@s1gr1d
s1gr1dforce-pushed the sig-prevent-init-in-extension branch from 6516bc9 to 8c5ebc0CompareFebruary 29, 2024 10:31
@s1gr1d
s1gr1d enabled auto-merge (squash) February 29, 2024 12:23
@s1gr1d
s1gr1d merged commit 784b485 into developFeb 29, 2024
@s1gr1d
s1gr1d deleted the sig-prevent-init-in-extension branch February 29, 2024 13:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Prevent SDK initialization via Sentry.init in Chrome extension

2 participants

@s1gr1d@mydea