use puka for escaping scripts - #17

Closed
nlf wants to merge 2 commits into
masterfrom
nlf/puka
Closed

use puka for escaping scripts#17
nlf wants to merge 2 commits into
masterfrom
nlf/puka

Conversation

@nlf

@nlfnlf commented Nov 17, 2020

Copy link
Copy Markdown
Contributor

the current escaping of shell scripts is pretty naive and fails in spectacular fashion in windows in many scenarios, this switches out that implementation in favor of some slightly creative usage of puka to ensure that commands are handled a bit more consistently

@rhendric

Copy link
Copy Markdown

Hi! Puka's author here. I'd be interested to hear a little more about what motivated the escapeCmd logic here. Just from your tests, it looks like all those cases would be covered by ShellString.sh([cmd]).toString(isWindows && 'win32'), but it's very likely there are edge cases I'm not thinking of right now. (If there are, I'm curious if Puka ought to handle them differently somehow.)

@nlf

nlf commented Nov 17, 2020

Copy link
Copy Markdown
ContributorAuthor

it seemed like there was an unnecessary amount of double quoting going on that

>constcmd=`node -e 'require("fs").writeFileSync("cwd", process.cwd())'`>constisWindows=true// for escapeCmd's sake>// copy the puka require and escapeCmd function from lib/make-spawn-args.js>console.log(escapeCmd(cmd))node-e^"require^(\^"fs\^"^).writeFileSync^(\^"cmd\^",^ process.cwd^(^)^)^">console.log(puka.ShellString.sh([cmd]).toString('win32'))node-e^^^"require^^^(\^^^"fs\^^^"^^^).writeFileSync^^^(\^^^"cmd\^^^",^^^ process.cwd^^^(^^^)^^^)^^^">child_process.spawnSync('cmd',['/d','/s','/c',escapeCmd(cmd)],{stdio: 'inherit',windowsVerbatimArguments: true}){status: 0,signal: null,output: [null,null,null],pid: 2316,stdout: null,stderr: null}>fs.readFileSync('./cwd','utf8')'C:\\Users\\Nathan LaFreniere\\Projects\\run-script'>>fs.unlinkSync('./cwd')// delete the file>fs.readFileSync('./cwd','utf8')// just showing it's really deleted
Uncaught Error: ENOENT: nosuchfileordirectory,open'./cwd'atObject.openSync(fs.js:476:3)atObject.readFileSync(fs.js:377:35){errno: -4058,syscall: 'open',code: 'ENOENT',path: './cwd'}>child_process.spawnSync('cmd',['/d','/s','/c',puka.ShellString.sh([cmd]).toString('win32')],{stdio: 'inherit',windowsVerbatimArguments: true})// try using your suggestion[eval]:1^require^(\^fs\^^).writeFileSync^(\^cwd\^,^process.cwd^(^)^)^^SyntaxError: Unexpectedtoken'^'atnewScript(vm.js:100:7)atcreateScript(vm.js:261:10)atObject.runInThisContext(vm.js:309:10)atinternal/process/execution.js:77:19at[eval]-wrapper:6:22atevalScript(internal/process/execution.js:76:60)atinternal/main/eval_string.js:23:3{status: 1,signal: null,output: [null,null,null],pid: 8916,stdout: null,stderr: null}

this was the only way I could find that seemed to work correctly for passing commands to cmd.exe using the various settings and flags that we use

@rhendric

Copy link
Copy Markdown

Ah, yes. I think you'll find that Puka's level of quoting is correct if the command calls a batch file instead of a true executable like node. (Try installing the echo-cli npm package, and running your test with echo-cli '<"' > cwd. I'm not on a Windows machine right now to test that, but I think the result of escapeCmd, which is echo-cli ^"^<\^"^" > cwd, will not result in <" successfully being written to a file called cwd—I think you'll get some sort of error instead.)

Windows is such a pain in this respect; the only way to get it right if you don't know whether your users will be calling one or the other is to walk the path and find the file referenced. I had Puka default to assuming batch files since that's what npm makes for the executables it installs, but calling node specifically maybe deserves to be a special case?

@rhendricrhendric mentioned this pull request May 18, 2021
@lukekarrys
lukekarrys deleted the nlf/puka branch February 23, 2022 00:33
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nlf@rhendric
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

use puka for escaping scripts - #17

Closed
nlf wants to merge 2 commits into
masterfrom
nlf/puka
Closed

use puka for escaping scripts#17
nlf wants to merge 2 commits into
masterfrom
nlf/puka

Conversation

@nlf

@nlfnlf commented Nov 17, 2020

Copy link
Copy Markdown
Contributor

the current escaping of shell scripts is pretty naive and fails in spectacular fashion in windows in many scenarios, this switches out that implementation in favor of some slightly creative usage of puka to ensure that commands are handled a bit more consistently

@rhendric

Copy link
Copy Markdown

Hi! Puka's author here. I'd be interested to hear a little more about what motivated the escapeCmd logic here. Just from your tests, it looks like all those cases would be covered by ShellString.sh([cmd]).toString(isWindows && 'win32'), but it's very likely there are edge cases I'm not thinking of right now. (If there are, I'm curious if Puka ought to handle them differently somehow.)

@nlf

nlf commented Nov 17, 2020

Copy link
Copy Markdown
ContributorAuthor

it seemed like there was an unnecessary amount of double quoting going on that

>constcmd=`node -e 'require("fs").writeFileSync("cwd", process.cwd())'`>constisWindows=true// for escapeCmd's sake>// copy the puka require and escapeCmd function from lib/make-spawn-args.js>console.log(escapeCmd(cmd))node-e^"require^(\^"fs\^"^).writeFileSync^(\^"cmd\^",^ process.cwd^(^)^)^">console.log(puka.ShellString.sh([cmd]).toString('win32'))node-e^^^"require^^^(\^^^"fs\^^^"^^^).writeFileSync^^^(\^^^"cmd\^^^",^^^ process.cwd^^^(^^^)^^^)^^^">child_process.spawnSync('cmd',['/d','/s','/c',escapeCmd(cmd)],{stdio: 'inherit',windowsVerbatimArguments: true}){status: 0,signal: null,output: [null,null,null],pid: 2316,stdout: null,stderr: null}>fs.readFileSync('./cwd','utf8')'C:\\Users\\Nathan LaFreniere\\Projects\\run-script'>>fs.unlinkSync('./cwd')// delete the file>fs.readFileSync('./cwd','utf8')// just showing it's really deleted
Uncaught Error: ENOENT: nosuchfileordirectory,open'./cwd'atObject.openSync(fs.js:476:3)atObject.readFileSync(fs.js:377:35){errno: -4058,syscall: 'open',code: 'ENOENT',path: './cwd'}>child_process.spawnSync('cmd',['/d','/s','/c',puka.ShellString.sh([cmd]).toString('win32')],{stdio: 'inherit',windowsVerbatimArguments: true})// try using your suggestion[eval]:1^require^(\^fs\^^).writeFileSync^(\^cwd\^,^process.cwd^(^)^)^^SyntaxError: Unexpectedtoken'^'atnewScript(vm.js:100:7)atcreateScript(vm.js:261:10)atObject.runInThisContext(vm.js:309:10)atinternal/process/execution.js:77:19at[eval]-wrapper:6:22atevalScript(internal/process/execution.js:76:60)atinternal/main/eval_string.js:23:3{status: 1,signal: null,output: [null,null,null],pid: 8916,stdout: null,stderr: null}

this was the only way I could find that seemed to work correctly for passing commands to cmd.exe using the various settings and flags that we use

@rhendric

Copy link
Copy Markdown

Ah, yes. I think you'll find that Puka's level of quoting is correct if the command calls a batch file instead of a true executable like node. (Try installing the echo-cli npm package, and running your test with echo-cli '<"' > cwd. I'm not on a Windows machine right now to test that, but I think the result of escapeCmd, which is echo-cli ^"^<\^"^" > cwd, will not result in <" successfully being written to a file called cwd—I think you'll get some sort of error instead.)

Windows is such a pain in this respect; the only way to get it right if you don't know whether your users will be calling one or the other is to walk the path and find the file referenced. I had Puka default to assuming batch files since that's what npm makes for the executables it installs, but calling node specifically maybe deserves to be a special case?

@rhendricrhendric mentioned this pull request May 18, 2021
@lukekarrys
lukekarrys deleted the nlf/puka branch February 23, 2022 00:33
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nlf@rhendric
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

use puka for escaping scripts - #17

Closed
nlf wants to merge 2 commits into
masterfrom
nlf/puka
Closed

use puka for escaping scripts#17
nlf wants to merge 2 commits into
masterfrom
nlf/puka

Conversation

@nlf

@nlfnlf commented Nov 17, 2020

Copy link
Copy Markdown
Contributor

the current escaping of shell scripts is pretty naive and fails in spectacular fashion in windows in many scenarios, this switches out that implementation in favor of some slightly creative usage of puka to ensure that commands are handled a bit more consistently

@rhendric

Copy link
Copy Markdown

Hi! Puka's author here. I'd be interested to hear a little more about what motivated the escapeCmd logic here. Just from your tests, it looks like all those cases would be covered by ShellString.sh([cmd]).toString(isWindows && 'win32'), but it's very likely there are edge cases I'm not thinking of right now. (If there are, I'm curious if Puka ought to handle them differently somehow.)

@nlf

nlf commented Nov 17, 2020

Copy link
Copy Markdown
ContributorAuthor

it seemed like there was an unnecessary amount of double quoting going on that

>constcmd=`node -e 'require("fs").writeFileSync("cwd", process.cwd())'`>constisWindows=true// for escapeCmd's sake>// copy the puka require and escapeCmd function from lib/make-spawn-args.js>console.log(escapeCmd(cmd))node-e^"require^(\^"fs\^"^).writeFileSync^(\^"cmd\^",^ process.cwd^(^)^)^">console.log(puka.ShellString.sh([cmd]).toString('win32'))node-e^^^"require^^^(\^^^"fs\^^^"^^^).writeFileSync^^^(\^^^"cmd\^^^",^^^ process.cwd^^^(^^^)^^^)^^^">child_process.spawnSync('cmd',['/d','/s','/c',escapeCmd(cmd)],{stdio: 'inherit',windowsVerbatimArguments: true}){status: 0,signal: null,output: [null,null,null],pid: 2316,stdout: null,stderr: null}>fs.readFileSync('./cwd','utf8')'C:\\Users\\Nathan LaFreniere\\Projects\\run-script'>>fs.unlinkSync('./cwd')// delete the file>fs.readFileSync('./cwd','utf8')// just showing it's really deleted
Uncaught Error: ENOENT: nosuchfileordirectory,open'./cwd'atObject.openSync(fs.js:476:3)atObject.readFileSync(fs.js:377:35){errno: -4058,syscall: 'open',code: 'ENOENT',path: './cwd'}>child_process.spawnSync('cmd',['/d','/s','/c',puka.ShellString.sh([cmd]).toString('win32')],{stdio: 'inherit',windowsVerbatimArguments: true})// try using your suggestion[eval]:1^require^(\^fs\^^).writeFileSync^(\^cwd\^,^process.cwd^(^)^)^^SyntaxError: Unexpectedtoken'^'atnewScript(vm.js:100:7)atcreateScript(vm.js:261:10)atObject.runInThisContext(vm.js:309:10)atinternal/process/execution.js:77:19at[eval]-wrapper:6:22atevalScript(internal/process/execution.js:76:60)atinternal/main/eval_string.js:23:3{status: 1,signal: null,output: [null,null,null],pid: 8916,stdout: null,stderr: null}

this was the only way I could find that seemed to work correctly for passing commands to cmd.exe using the various settings and flags that we use

@rhendric

Copy link
Copy Markdown

Ah, yes. I think you'll find that Puka's level of quoting is correct if the command calls a batch file instead of a true executable like node. (Try installing the echo-cli npm package, and running your test with echo-cli '<"' > cwd. I'm not on a Windows machine right now to test that, but I think the result of escapeCmd, which is echo-cli ^"^<\^"^" > cwd, will not result in <" successfully being written to a file called cwd—I think you'll get some sort of error instead.)

Windows is such a pain in this respect; the only way to get it right if you don't know whether your users will be calling one or the other is to walk the path and find the file referenced. I had Puka default to assuming batch files since that's what npm makes for the executables it installs, but calling node specifically maybe deserves to be a special case?

@rhendricrhendric mentioned this pull request May 18, 2021
@lukekarrys
lukekarrys deleted the nlf/puka branch February 23, 2022 00:33
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nlf@rhendric
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

use puka for escaping scripts - #17

Closed
nlf wants to merge 2 commits into
masterfrom
nlf/puka
Closed

use puka for escaping scripts#17
nlf wants to merge 2 commits into
masterfrom
nlf/puka

Conversation

@nlf

@nlfnlf commented Nov 17, 2020

Copy link
Copy Markdown
Contributor

the current escaping of shell scripts is pretty naive and fails in spectacular fashion in windows in many scenarios, this switches out that implementation in favor of some slightly creative usage of puka to ensure that commands are handled a bit more consistently

@rhendric

Copy link
Copy Markdown

Hi! Puka's author here. I'd be interested to hear a little more about what motivated the escapeCmd logic here. Just from your tests, it looks like all those cases would be covered by ShellString.sh([cmd]).toString(isWindows && 'win32'), but it's very likely there are edge cases I'm not thinking of right now. (If there are, I'm curious if Puka ought to handle them differently somehow.)

@nlf

nlf commented Nov 17, 2020

Copy link
Copy Markdown
ContributorAuthor

it seemed like there was an unnecessary amount of double quoting going on that

>constcmd=`node -e 'require("fs").writeFileSync("cwd", process.cwd())'`>constisWindows=true// for escapeCmd's sake>// copy the puka require and escapeCmd function from lib/make-spawn-args.js>console.log(escapeCmd(cmd))node-e^"require^(\^"fs\^"^).writeFileSync^(\^"cmd\^",^ process.cwd^(^)^)^">console.log(puka.ShellString.sh([cmd]).toString('win32'))node-e^^^"require^^^(\^^^"fs\^^^"^^^).writeFileSync^^^(\^^^"cmd\^^^",^^^ process.cwd^^^(^^^)^^^)^^^">child_process.spawnSync('cmd',['/d','/s','/c',escapeCmd(cmd)],{stdio: 'inherit',windowsVerbatimArguments: true}){status: 0,signal: null,output: [null,null,null],pid: 2316,stdout: null,stderr: null}>fs.readFileSync('./cwd','utf8')'C:\\Users\\Nathan LaFreniere\\Projects\\run-script'>>fs.unlinkSync('./cwd')// delete the file>fs.readFileSync('./cwd','utf8')// just showing it's really deleted
Uncaught Error: ENOENT: nosuchfileordirectory,open'./cwd'atObject.openSync(fs.js:476:3)atObject.readFileSync(fs.js:377:35){errno: -4058,syscall: 'open',code: 'ENOENT',path: './cwd'}>child_process.spawnSync('cmd',['/d','/s','/c',puka.ShellString.sh([cmd]).toString('win32')],{stdio: 'inherit',windowsVerbatimArguments: true})// try using your suggestion[eval]:1^require^(\^fs\^^).writeFileSync^(\^cwd\^,^process.cwd^(^)^)^^SyntaxError: Unexpectedtoken'^'atnewScript(vm.js:100:7)atcreateScript(vm.js:261:10)atObject.runInThisContext(vm.js:309:10)atinternal/process/execution.js:77:19at[eval]-wrapper:6:22atevalScript(internal/process/execution.js:76:60)atinternal/main/eval_string.js:23:3{status: 1,signal: null,output: [null,null,null],pid: 8916,stdout: null,stderr: null}

this was the only way I could find that seemed to work correctly for passing commands to cmd.exe using the various settings and flags that we use

@rhendric

Copy link
Copy Markdown

Ah, yes. I think you'll find that Puka's level of quoting is correct if the command calls a batch file instead of a true executable like node. (Try installing the echo-cli npm package, and running your test with echo-cli '<"' > cwd. I'm not on a Windows machine right now to test that, but I think the result of escapeCmd, which is echo-cli ^"^<\^"^" > cwd, will not result in <" successfully being written to a file called cwd—I think you'll get some sort of error instead.)

Windows is such a pain in this respect; the only way to get it right if you don't know whether your users will be calling one or the other is to walk the path and find the file referenced. I had Puka default to assuming batch files since that's what npm makes for the executables it installs, but calling node specifically maybe deserves to be a special case?

@rhendricrhendric mentioned this pull request May 18, 2021
@lukekarrys
lukekarrys deleted the nlf/puka branch February 23, 2022 00:33
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nlf@rhendric
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

use puka for escaping scripts - #17

Closed
nlf wants to merge 2 commits into
masterfrom
nlf/puka
Closed

use puka for escaping scripts#17
nlf wants to merge 2 commits into
masterfrom
nlf/puka

Conversation

@nlf

@nlfnlf commented Nov 17, 2020

Copy link
Copy Markdown
Contributor

the current escaping of shell scripts is pretty naive and fails in spectacular fashion in windows in many scenarios, this switches out that implementation in favor of some slightly creative usage of puka to ensure that commands are handled a bit more consistently

@rhendric

Copy link
Copy Markdown

Hi! Puka's author here. I'd be interested to hear a little more about what motivated the escapeCmd logic here. Just from your tests, it looks like all those cases would be covered by ShellString.sh([cmd]).toString(isWindows && 'win32'), but it's very likely there are edge cases I'm not thinking of right now. (If there are, I'm curious if Puka ought to handle them differently somehow.)

@nlf

nlf commented Nov 17, 2020

Copy link
Copy Markdown
ContributorAuthor

it seemed like there was an unnecessary amount of double quoting going on that

>constcmd=`node -e 'require("fs").writeFileSync("cwd", process.cwd())'`>constisWindows=true// for escapeCmd's sake>// copy the puka require and escapeCmd function from lib/make-spawn-args.js>console.log(escapeCmd(cmd))node-e^"require^(\^"fs\^"^).writeFileSync^(\^"cmd\^",^ process.cwd^(^)^)^">console.log(puka.ShellString.sh([cmd]).toString('win32'))node-e^^^"require^^^(\^^^"fs\^^^"^^^).writeFileSync^^^(\^^^"cmd\^^^",^^^ process.cwd^^^(^^^)^^^)^^^">child_process.spawnSync('cmd',['/d','/s','/c',escapeCmd(cmd)],{stdio: 'inherit',windowsVerbatimArguments: true}){status: 0,signal: null,output: [null,null,null],pid: 2316,stdout: null,stderr: null}>fs.readFileSync('./cwd','utf8')'C:\\Users\\Nathan LaFreniere\\Projects\\run-script'>>fs.unlinkSync('./cwd')// delete the file>fs.readFileSync('./cwd','utf8')// just showing it's really deleted
Uncaught Error: ENOENT: nosuchfileordirectory,open'./cwd'atObject.openSync(fs.js:476:3)atObject.readFileSync(fs.js:377:35){errno: -4058,syscall: 'open',code: 'ENOENT',path: './cwd'}>child_process.spawnSync('cmd',['/d','/s','/c',puka.ShellString.sh([cmd]).toString('win32')],{stdio: 'inherit',windowsVerbatimArguments: true})// try using your suggestion[eval]:1^require^(\^fs\^^).writeFileSync^(\^cwd\^,^process.cwd^(^)^)^^SyntaxError: Unexpectedtoken'^'atnewScript(vm.js:100:7)atcreateScript(vm.js:261:10)atObject.runInThisContext(vm.js:309:10)atinternal/process/execution.js:77:19at[eval]-wrapper:6:22atevalScript(internal/process/execution.js:76:60)atinternal/main/eval_string.js:23:3{status: 1,signal: null,output: [null,null,null],pid: 8916,stdout: null,stderr: null}

this was the only way I could find that seemed to work correctly for passing commands to cmd.exe using the various settings and flags that we use

@rhendric

Copy link
Copy Markdown

Ah, yes. I think you'll find that Puka's level of quoting is correct if the command calls a batch file instead of a true executable like node. (Try installing the echo-cli npm package, and running your test with echo-cli '<"' > cwd. I'm not on a Windows machine right now to test that, but I think the result of escapeCmd, which is echo-cli ^"^<\^"^" > cwd, will not result in <" successfully being written to a file called cwd—I think you'll get some sort of error instead.)

Windows is such a pain in this respect; the only way to get it right if you don't know whether your users will be calling one or the other is to walk the path and find the file referenced. I had Puka default to assuming batch files since that's what npm makes for the executables it installs, but calling node specifically maybe deserves to be a special case?

@rhendricrhendric mentioned this pull request May 18, 2021
@lukekarrys
lukekarrys deleted the nlf/puka branch February 23, 2022 00:33
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nlf@rhendric
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

use puka for escaping scripts - #17

Closed
nlf wants to merge 2 commits into
masterfrom
nlf/puka
Closed

use puka for escaping scripts#17
nlf wants to merge 2 commits into
masterfrom
nlf/puka

Conversation

@nlf

@nlfnlf commented Nov 17, 2020

Copy link
Copy Markdown
Contributor

the current escaping of shell scripts is pretty naive and fails in spectacular fashion in windows in many scenarios, this switches out that implementation in favor of some slightly creative usage of puka to ensure that commands are handled a bit more consistently

@rhendric

Copy link
Copy Markdown

Hi! Puka's author here. I'd be interested to hear a little more about what motivated the escapeCmd logic here. Just from your tests, it looks like all those cases would be covered by ShellString.sh([cmd]).toString(isWindows && 'win32'), but it's very likely there are edge cases I'm not thinking of right now. (If there are, I'm curious if Puka ought to handle them differently somehow.)

@nlf

nlf commented Nov 17, 2020

Copy link
Copy Markdown
ContributorAuthor

it seemed like there was an unnecessary amount of double quoting going on that

>constcmd=`node -e 'require("fs").writeFileSync("cwd", process.cwd())'`>constisWindows=true// for escapeCmd's sake>// copy the puka require and escapeCmd function from lib/make-spawn-args.js>console.log(escapeCmd(cmd))node-e^"require^(\^"fs\^"^).writeFileSync^(\^"cmd\^",^ process.cwd^(^)^)^">console.log(puka.ShellString.sh([cmd]).toString('win32'))node-e^^^"require^^^(\^^^"fs\^^^"^^^).writeFileSync^^^(\^^^"cmd\^^^",^^^ process.cwd^^^(^^^)^^^)^^^">child_process.spawnSync('cmd',['/d','/s','/c',escapeCmd(cmd)],{stdio: 'inherit',windowsVerbatimArguments: true}){status: 0,signal: null,output: [null,null,null],pid: 2316,stdout: null,stderr: null}>fs.readFileSync('./cwd','utf8')'C:\\Users\\Nathan LaFreniere\\Projects\\run-script'>>fs.unlinkSync('./cwd')// delete the file>fs.readFileSync('./cwd','utf8')// just showing it's really deleted
Uncaught Error: ENOENT: nosuchfileordirectory,open'./cwd'atObject.openSync(fs.js:476:3)atObject.readFileSync(fs.js:377:35){errno: -4058,syscall: 'open',code: 'ENOENT',path: './cwd'}>child_process.spawnSync('cmd',['/d','/s','/c',puka.ShellString.sh([cmd]).toString('win32')],{stdio: 'inherit',windowsVerbatimArguments: true})// try using your suggestion[eval]:1^require^(\^fs\^^).writeFileSync^(\^cwd\^,^process.cwd^(^)^)^^SyntaxError: Unexpectedtoken'^'atnewScript(vm.js:100:7)atcreateScript(vm.js:261:10)atObject.runInThisContext(vm.js:309:10)atinternal/process/execution.js:77:19at[eval]-wrapper:6:22atevalScript(internal/process/execution.js:76:60)atinternal/main/eval_string.js:23:3{status: 1,signal: null,output: [null,null,null],pid: 8916,stdout: null,stderr: null}

this was the only way I could find that seemed to work correctly for passing commands to cmd.exe using the various settings and flags that we use

@rhendric

Copy link
Copy Markdown

Ah, yes. I think you'll find that Puka's level of quoting is correct if the command calls a batch file instead of a true executable like node. (Try installing the echo-cli npm package, and running your test with echo-cli '<"' > cwd. I'm not on a Windows machine right now to test that, but I think the result of escapeCmd, which is echo-cli ^"^<\^"^" > cwd, will not result in <" successfully being written to a file called cwd—I think you'll get some sort of error instead.)

Windows is such a pain in this respect; the only way to get it right if you don't know whether your users will be calling one or the other is to walk the path and find the file referenced. I had Puka default to assuming batch files since that's what npm makes for the executables it installs, but calling node specifically maybe deserves to be a special case?

@rhendricrhendric mentioned this pull request May 18, 2021
@lukekarrys
lukekarrys deleted the nlf/puka branch February 23, 2022 00:33
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nlf@rhendric
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

use puka for escaping scripts - #17

Closed
nlf wants to merge 2 commits into
masterfrom
nlf/puka
Closed

use puka for escaping scripts#17
nlf wants to merge 2 commits into
masterfrom
nlf/puka

Conversation

@nlf

@nlfnlf commented Nov 17, 2020

Copy link
Copy Markdown
Contributor

the current escaping of shell scripts is pretty naive and fails in spectacular fashion in windows in many scenarios, this switches out that implementation in favor of some slightly creative usage of puka to ensure that commands are handled a bit more consistently

@rhendric

Copy link
Copy Markdown

Hi! Puka's author here. I'd be interested to hear a little more about what motivated the escapeCmd logic here. Just from your tests, it looks like all those cases would be covered by ShellString.sh([cmd]).toString(isWindows && 'win32'), but it's very likely there are edge cases I'm not thinking of right now. (If there are, I'm curious if Puka ought to handle them differently somehow.)

@nlf

nlf commented Nov 17, 2020

Copy link
Copy Markdown
ContributorAuthor

it seemed like there was an unnecessary amount of double quoting going on that

>constcmd=`node -e 'require("fs").writeFileSync("cwd", process.cwd())'`>constisWindows=true// for escapeCmd's sake>// copy the puka require and escapeCmd function from lib/make-spawn-args.js>console.log(escapeCmd(cmd))node-e^"require^(\^"fs\^"^).writeFileSync^(\^"cmd\^",^ process.cwd^(^)^)^">console.log(puka.ShellString.sh([cmd]).toString('win32'))node-e^^^"require^^^(\^^^"fs\^^^"^^^).writeFileSync^^^(\^^^"cmd\^^^",^^^ process.cwd^^^(^^^)^^^)^^^">child_process.spawnSync('cmd',['/d','/s','/c',escapeCmd(cmd)],{stdio: 'inherit',windowsVerbatimArguments: true}){status: 0,signal: null,output: [null,null,null],pid: 2316,stdout: null,stderr: null}>fs.readFileSync('./cwd','utf8')'C:\\Users\\Nathan LaFreniere\\Projects\\run-script'>>fs.unlinkSync('./cwd')// delete the file>fs.readFileSync('./cwd','utf8')// just showing it's really deleted
Uncaught Error: ENOENT: nosuchfileordirectory,open'./cwd'atObject.openSync(fs.js:476:3)atObject.readFileSync(fs.js:377:35){errno: -4058,syscall: 'open',code: 'ENOENT',path: './cwd'}>child_process.spawnSync('cmd',['/d','/s','/c',puka.ShellString.sh([cmd]).toString('win32')],{stdio: 'inherit',windowsVerbatimArguments: true})// try using your suggestion[eval]:1^require^(\^fs\^^).writeFileSync^(\^cwd\^,^process.cwd^(^)^)^^SyntaxError: Unexpectedtoken'^'atnewScript(vm.js:100:7)atcreateScript(vm.js:261:10)atObject.runInThisContext(vm.js:309:10)atinternal/process/execution.js:77:19at[eval]-wrapper:6:22atevalScript(internal/process/execution.js:76:60)atinternal/main/eval_string.js:23:3{status: 1,signal: null,output: [null,null,null],pid: 8916,stdout: null,stderr: null}

this was the only way I could find that seemed to work correctly for passing commands to cmd.exe using the various settings and flags that we use

@rhendric

Copy link
Copy Markdown

Ah, yes. I think you'll find that Puka's level of quoting is correct if the command calls a batch file instead of a true executable like node. (Try installing the echo-cli npm package, and running your test with echo-cli '<"' > cwd. I'm not on a Windows machine right now to test that, but I think the result of escapeCmd, which is echo-cli ^"^<\^"^" > cwd, will not result in <" successfully being written to a file called cwd—I think you'll get some sort of error instead.)

Windows is such a pain in this respect; the only way to get it right if you don't know whether your users will be calling one or the other is to walk the path and find the file referenced. I had Puka default to assuming batch files since that's what npm makes for the executables it installs, but calling node specifically maybe deserves to be a special case?

@rhendricrhendric mentioned this pull request May 18, 2021
@lukekarrys
lukekarrys deleted the nlf/puka branch February 23, 2022 00:33
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nlf@rhendric
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

use puka for escaping scripts - #17

Closed
nlf wants to merge 2 commits into
masterfrom
nlf/puka
Closed

use puka for escaping scripts#17
nlf wants to merge 2 commits into
masterfrom
nlf/puka

Conversation

@nlf

@nlfnlf commented Nov 17, 2020

Copy link
Copy Markdown
Contributor

the current escaping of shell scripts is pretty naive and fails in spectacular fashion in windows in many scenarios, this switches out that implementation in favor of some slightly creative usage of puka to ensure that commands are handled a bit more consistently

@rhendric

Copy link
Copy Markdown

Hi! Puka's author here. I'd be interested to hear a little more about what motivated the escapeCmd logic here. Just from your tests, it looks like all those cases would be covered by ShellString.sh([cmd]).toString(isWindows && 'win32'), but it's very likely there are edge cases I'm not thinking of right now. (If there are, I'm curious if Puka ought to handle them differently somehow.)

@nlf

nlf commented Nov 17, 2020

Copy link
Copy Markdown
ContributorAuthor

it seemed like there was an unnecessary amount of double quoting going on that

>constcmd=`node -e 'require("fs").writeFileSync("cwd", process.cwd())'`>constisWindows=true// for escapeCmd's sake>// copy the puka require and escapeCmd function from lib/make-spawn-args.js>console.log(escapeCmd(cmd))node-e^"require^(\^"fs\^"^).writeFileSync^(\^"cmd\^",^ process.cwd^(^)^)^">console.log(puka.ShellString.sh([cmd]).toString('win32'))node-e^^^"require^^^(\^^^"fs\^^^"^^^).writeFileSync^^^(\^^^"cmd\^^^",^^^ process.cwd^^^(^^^)^^^)^^^">child_process.spawnSync('cmd',['/d','/s','/c',escapeCmd(cmd)],{stdio: 'inherit',windowsVerbatimArguments: true}){status: 0,signal: null,output: [null,null,null],pid: 2316,stdout: null,stderr: null}>fs.readFileSync('./cwd','utf8')'C:\\Users\\Nathan LaFreniere\\Projects\\run-script'>>fs.unlinkSync('./cwd')// delete the file>fs.readFileSync('./cwd','utf8')// just showing it's really deleted
Uncaught Error: ENOENT: nosuchfileordirectory,open'./cwd'atObject.openSync(fs.js:476:3)atObject.readFileSync(fs.js:377:35){errno: -4058,syscall: 'open',code: 'ENOENT',path: './cwd'}>child_process.spawnSync('cmd',['/d','/s','/c',puka.ShellString.sh([cmd]).toString('win32')],{stdio: 'inherit',windowsVerbatimArguments: true})// try using your suggestion[eval]:1^require^(\^fs\^^).writeFileSync^(\^cwd\^,^process.cwd^(^)^)^^SyntaxError: Unexpectedtoken'^'atnewScript(vm.js:100:7)atcreateScript(vm.js:261:10)atObject.runInThisContext(vm.js:309:10)atinternal/process/execution.js:77:19at[eval]-wrapper:6:22atevalScript(internal/process/execution.js:76:60)atinternal/main/eval_string.js:23:3{status: 1,signal: null,output: [null,null,null],pid: 8916,stdout: null,stderr: null}

this was the only way I could find that seemed to work correctly for passing commands to cmd.exe using the various settings and flags that we use

@rhendric

Copy link
Copy Markdown

Ah, yes. I think you'll find that Puka's level of quoting is correct if the command calls a batch file instead of a true executable like node. (Try installing the echo-cli npm package, and running your test with echo-cli '<"' > cwd. I'm not on a Windows machine right now to test that, but I think the result of escapeCmd, which is echo-cli ^"^<\^"^" > cwd, will not result in <" successfully being written to a file called cwd—I think you'll get some sort of error instead.)

Windows is such a pain in this respect; the only way to get it right if you don't know whether your users will be calling one or the other is to walk the path and find the file referenced. I had Puka default to assuming batch files since that's what npm makes for the executables it installs, but calling node specifically maybe deserves to be a special case?

@rhendricrhendric mentioned this pull request May 18, 2021
@lukekarrys
lukekarrys deleted the nlf/puka branch February 23, 2022 00:33
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nlf@rhendric