mirror of
https://github.com/daijro/camoufox.git
synced 2026-10-08 16:00:36 +00:00
e425dddcfdd764957dee5e2f58d95ceedbcd257d
65
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
be9f38b08e |
chore: remove build tooling nothing uses
- The developer UI (scripts/developer.py, `make edits`). It depended on easygui, which no requirements file declares, and every action it offered is a Makefile target: patch, unpatch, workspace, revert, diff. Its two helpers in scripts/_mixin.py (is_bootstrap_patch, patch) had no other callers. - legacy/, the Go launcher deprecated in 2024-11. Nothing built or shipped it. Its Makefile targets and scripts/run-pw.py go with it, and so does Go from every dependency list and workflow. - jsonvv/ and settings/camoucfg.jvv. Nothing read the .jvv schema: config is validated against settings/properties.json, and the two had already drifted. The jsonvv package stays on PyPI. - Scripts with no caller: bootstrap.py, moztree, setup-wasi-linux.sh, package-helper.sh, install-local-build.sh, mozfetch.sh (copied into lw/ but never packaged), examples/. - The pre-ESM Juggler copies JugglerFrameParent.jsm and JugglerFrameChild.jsm, and hidden-scrollbars.css. Juggler loads the .sys.mjs actors and deliberately no stylesheet, but jar.mn still packaged all three. - patches/librewolf/*.opt, which list_patches() never picks up; the roverfox second pass in patch.py, whose directory no longer exists; the unread --no-settings-pane option. - The CAMOUFOX_PASSWD secret passed to `make fetch` and closedsrc_rev in upstream.sh, which nothing reads. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
||
|
|
6daae88dbc |
Stock-Firefox parity for native identities: input, fonts, locale, WebGL, WebRTC, media, timing, launcher (#779)
* feat(humanize): replay recorded human mouse movements (Cursory) humanize=True used to walk a Bezier curve through two random knots and emit a point every 10 ms. Both halves are tells: an analytic curve sampled at a fixed rate has velocity and jerk profiles that separate cleanly from a hand's, and every movement accelerated through the same easing function. Juggler now picks one of Cursory's 2357 recorded human movements whose direction, distance and wander suit the move, morphs it onto the requested endpoints and replays it with the recording's own timing. The generator is cursory-js (a bit-exact TypeScript port of Vinyzu/cursory) vendored under additions/juggler/input/cursory/; it is LGPLv3-or-later, not MPL-2.0, and ships its LICENSE and NOTICE inside juggler.jar. MouseTrajectories.hpp and ChromeUtils.camouGetMouseTrajectory are removed. sendTrajectoryAcked takes per-step pauses, drops points on the pixel the last dispatch left the cursor on (a zero-displacement move is never acked), and the humanize guards are updated for the new path shape. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * test(patches): shared helpers for binary resolution, a private Xvfb and Marionette resolve_binary() honours the runner's CAMOUFOX_EXECUTABLE_PATH before falling back to a Linux objdir (search-service-init and touchscreen-digitizer ignored it and ran the newest objdir, which after a macOS cross build is an arm64 Mach-O), hidden_display() gives a guard its own Xvfb so nothing ever opens on the user's display, and a minimal chrome-context Marionette client lets guards inspect browser UI state. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(juggler): synthesized input carries what real mouse and keyboard input carries - pointerType was "" for every Playwright mouse event: juggler dispatched with MOZ_SOURCE_UNKNOWN. It now passes MOZ_SOURCE_MOUSE (#776). - keyboard.type() never pressed Shift: a shifted character now arrives bracketed by ShiftLeft keydown/keyup (location 1) with shiftKey set. - After the pointer was parked off content, pointerover/enter re-entered with buttons=1 and pressure 0.5; the tracked position is now forgotten on park. - A Windows identity gets contextmenu after mouseup with buttons=0, as Windows does; GTK/macOS keep it on press. - Wheel events are sent as line deltas (DOMMouseScroll.detail 3 per notch instead of the pixel count). - The browser rect is measured after the APZ flush await, so a chrome height change during the wait cannot put a y==0 dispatch one row above content. - ci/run_sundial.py moves and clicks the mouse so input vectors have data. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(juggler): evaluate() no longer grants user activation Upstream Playwright runs every evaluate() as handling user input and notifies a user-gesture activation. Init scripts go through that path at load, so every page started with navigator.userActivation.hasBeenActive === true, autoplay allowed and popups permitted before any input. Activation now only comes from juggler's trusted input events, as in a stock browser. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(juggler): stop hiding scrollbars in headless The headless agent sheet set scrollbar-width: none !important, which a page reads back from getComputedStyle and from overflow:scroll gutters. Scrollbar appearance is left to the platform look-and-feel (the launcher sets ui.useOverlayScrollbars per claimed OS). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(ui): no visible automation cues in the browser window - Every Playwright context was a public container, so the URL bar showed a "JUGGLER <id>" label and a container colour. Contexts are now non-public identities (tabbrowser renders public identities only); startup cleanup still removes persisted leftovers. - showcursor defaulted to true, drawing a red dot that followed the mouse. It is now opt-in. tests/patches/visible-automation-cues.py checks both on a private Xvfb. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(fonts): web fonts, local(), per-character fallback and native bundles - FontFace / @font-face were answered from the font allowlist by the FontFace's own family name, so every url() web font failed with NS_ERROR_FAILURE and never rendered, local() of an allowed font failed, and a miss rejected with an XPCOM code instead of NetworkError (#759). Stock FontFace/FontFaceImpl are restored; local() is filtered by the RESOLVED family in gfxUserFontSet. - GlobalFontFallback forced the cmap scan, which skips families whose charmap is not loaded yet, so any character outside Gecko's script-based common-fallback table rendered as the primary family's .notdef (U+1E9E on macOS). The platform fallback chooses again, and its choice is held to the mask. - For a native macOS/Windows identity the bundled font sets are not activated: a bundled face of a family the system also has (Papyrus, Helvetica) won the lookup with different metrics. On Windows the enumerator still keeps Twemoji Mozilla, the emoji font stock Firefox ships (flag emoji drew nothing). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(fonts): CSS2 system fonts and system-ui follow the claimed OS - The host's own OS gets no system-ui override (macOS resolved system-ui to Helvetica instead of -apple-system). - CSS2 system font keywords use per-keyword faces and sizes; a Linux identity reports the Ubuntu desktop font; Windows form controls (-moz-button/field/list) answer "MS Shell Dlg 2" as Windows does, not Segoe UI. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * feat(fonts): per-OS font model and fontconfig parity fonts.json is now generated from the bundle by scripts/gen-fonts-json.py (fc-scan + aliases + scan-time families, intersected with the per-OS manifest in scripts/data/font-manifests.json) so every reportable family is renderable; scripts/verify-fonts.py checks that invariant, the generics and the reject globs. font-groups.json lets the draw keep co-shipped families together. Linux fontconfig: stock metric aliases (Arial -> Liberation Sans, ...), 49-sansserif, urw-base35 and the non-Latin rule files in stock conf.d order, generics resolving like a stock Ubuntu (Noto Sans / Noto Serif / DejaVu Sans Mono / Z003), hintslight so advances are not pinned to whole pixels, and weak <prefer> lists instead of strongly-bound generic pins so lang can promote a script face. Windows fontconfig: GDI substitution aliases, MS Shell Dlg 2, cursive/fantasy generics, duplicate-face rejects and Sitka / Segoe UI Variable optical-size families. NOTE: generated against a ~3.9 GB target font bundle that is not part of this change (one file is over GitHub's 100 MB limit); see docs/FONTS.md. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(locale): localize browser strings with the spoofed locale; stop rewriting explicit locales - With locale="fr-FR", Intl/number/date went French but input.validationMessage and XML parse errors stayed English, a mix no real Firefox produces. Official language packs are now baked in as packaged locales (scripts/fetch-langpacks.py, scripts/inject-locales.py, called by package.py, fetched on demand) and the launcher selects the UI locale through intl.locale.requested. A langpack add-on cannot do this: the parent pre-creates those string bundles first. - locale-spoofing.patch overrode Language/Script/Region on every intl::Locale, so new Intl.DisplayNames(['en'],{type:'region'}).of('DE') returned the spoofed region's name and Intl.Locale('ja-Jpan-JP').minimize() returned the spoofed tag. Only the OS/default locale is spoofed now. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(media): enumerate, capture and label the identity's media devices coherently The fake media engine now enumerates the identity's microphones, cameras and speakers (labels and group ids from new mediaDevices:*Labels/*Groups config keys), MediaManager uses it whenever mediaDevices:enabled, and stock exposure rules apply: before a grant one device per input kind, no outputs, no labels; after a grant OS-style labels, distinct deviceIds, shared groupIds. So enumerateDevices(), getUserMedia() tracks and getSettings() ids agree, and a claimed camera captures instead of throwing NotFoundError. Fixes the content-process crash on an identity with a camera and no microphone (InsertElementAt on an empty array). docs/MEDIA-DEVICES.md; guard tests/patches/media-devices-coherence.py. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(navigator): globalPrivacyControl agrees between window and workers (#760) The main-thread Navigator getter ignored the config key that WorkerNavigator::GlobalPrivacyControl honours, so a page read false in the window and true in a worker. Both read the key the same way now; the launcher also mirrors it into privacy.globalprivacycontrol.enabled so the Sec-GPC header agrees. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(timezone): apply the launch-level timezone from the first read (#773) The timezone config key was only applied lazily from a navigator getter, so Intl and Date reported the host zone until a page happened to touch navigator. It is now applied eagerly in every process (nsJSContext::EnsureStatics) and per realm when a new inner window is created, entering that window's realm rather than whichever one triggered the navigation. window.setTimezone() still takes precedence per context. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(screen): the CSS color media feature follows the spoofed colorDepth screen.colorDepth was spoofed at the WebIDL level only, so on a 10-bit panel a 24-bit identity reported 24 with (color: 10), a pair Gecko cannot produce. Gecko_MediaFeatures_GetColorDepth now resolves the depth in the same order as nsScreen::PixelDepth. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(webgl): pass live state through instead of answering it from the table getParameter answered everything from the sampled table, so state a page had just set read back wrong (lineWidth(5) read 1, VIEWPORT/SCISSOR_BOX stayed 300x150 on a 64x64 canvas), extension parameters were null (anisotropy, draw buffers), COMPRESSED_TEXTURE_FORMATS was null instead of [], and getContextAttributes() ignored the attributes requested ({antialias:false} still reported 4 samples). Identity and limits still come from the table; live state and context attributes are real. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(webrtc): ICE gathering completes behind a proxy (#774) With Playwright's per-context proxy and media.peerconnection.ice.proxy_only_if_behind_proxy, ICE failed before gathering started and iceGatheringState stayed "new" forever, where stock Firefox completes with host candidates. When that happens around the fabricated candidates the new -> gathering -> complete state walk is replayed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * chore(patches): refresh window-setter-seal.patch offsets Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(windows): embed Firefox's application manifest in camoufox.exe config/rules.mk embeds <program>.manifest and browser/app only ships firefox.exe.manifest, so --with-app-name=camoufox produced an exe with no manifest. Without the Windows 10 supportedOS GUID the process and its children run as a pre-Windows-10 application and Gecko's Windows-10-gated paths switch off (MediaCapabilities.decodingInfo powerEfficient false for H.264/VP9 where stock is true). The new patch adds a byte-for-byte copy as camoufox.exe.manifest; the old rename hunk in windows-theming-bug-modified.patch is dropped. Guard: tests/patches/windows-exe-manifest.py. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(settings): stock values for page-observable prefs; launcher prefs at startup Page-observable defaults that no stock Firefox has, restored: - the forced built-in dark theme (it also removed the 1 px nav-bar separator, and was applied ~1 s after startup, resizing the viewport) and ui.systemUsesDarkTheme (prefers-color-scheme disagreed with the desktop); - focus rings off, autoplay allowed, popup blocker off; - gfx.color_management.mode=0 (Playwright's test pref: ICC-tagged images were drawn unconverted, readable from a canvas pixel); - ui.use_standins_for_native_colors (non-native system colours); - GMP updates off (Widevine/OpenH264 never available); - storage.estimate() quota derived from the raw disk instead of the stock cap. The HardwareAcceleration:false enterprise policy is removed: it locked software WebRender with no hardware video decoding on every OS (guard tests/patches/hardware-acceleration-policy.py). The minimal-theme chrome.css is emptied: its ~55 px chrome made outerHeight - innerHeight impossible. Playwright's non-persistent launch writes no user.js, so launcher prefs only arrived through juggler after startup and anything Gecko reads while starting raced (on Windows the UI locale lost 3 of 4 launches). camoufox.cfg now applies the launcher's CAMOU_PREFS_1..N env chunks as default prefs at startup (guard tests/patches/startup-prefs.py). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(branding): chrome://branding assets match stock Firefox chrome://branding/content/ is content-accessible. The wordmark SVGs had different intrinsic sizes (336x48 / 172x48 vs 300x67) and document.ico, document_pdf.svg and the private-browsing about logos were missing, all measurable from a page with an <img>. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(pythonlib): identity draws that match real machines and stay stable Launcher-side fixes found by comparing camoufox against stock Firefox 152.0.4 on Linux, Windows 11 and macOS hosts: - DNT / GPC: BrowserForge draws doNotTrack "1" on most Firefox samples, but a stock Firefox 152 reports "unspecified" and globalPrivacyControl false; the stock defaults are used unless the caller sets them, and both are applied as prefs so the API, the worker and the DNT / Sec-GPC headers agree (#760). - Timezone and geolocation: the timezone is passed to the browser, and a configured position sets permissions.default.geo so permissions.query agrees with the auto-grant (#769, #773). - hardwareConcurrency: the reported count is the fingerprint's and the browser is pinned to that many cores (cpu_affinity.py, Linux/Windows), so worker timing agrees with it; otherwise the host count snapped into the core counts real machines ship with (never 2, Firefox's resistFingerprinting value). - Fonts: the OS base is always present in full, OS-version variants are drawn all-or-nothing, co-shipped groups stay together, Cascadia is never claimed off Windows, a native macOS/Windows identity claims only the real OS base, and gfx.font_rendering.fallback.async is off on Linux so per-character fallback does not depend on cmap-load timing. - Speech voices: a per-OS installed-voice model (voice-manifests.json) with the voiceURI formats each backend really produces (voice-uris.json); no default voice where stock has none. - WebGL: extensions a release Firefox never exposes are filtered, but OVR_multiview2 stays for Windows D3D11 renderers, which expose it. - Media devices: a seeded draw of common per-OS devices with OS-style labels. - Windows scrollbars follow the drawn Windows version (overlay on 11). - Glyph-advance perturbation (fonts:spacing_seed) defaults to off: it moved every measureText width off the value the same font gives on a real machine. - Launcher prefs are also exported as CAMOU_PREFS_1..N so camoufox.cfg applies them at startup, and the browser UI locale follows the spoofed locale. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(pythonlib): per-identity salt for seeded draws; core pinning under concurrency Found in review of the previous commits: - identity_seed() hashed only the UA, platform, screen size and core count. Those take a handful of values per OS, so over 500 launches the seed took 12-30 distinct values and every install drew its fonts, voices, GPU, media devices and canvas/audio noise seeds from that same short list. The seed now mixes in identity_salt(): derived from what the caller pinned the identity with (a Fingerprint, a preset dict, a config naming the UA) so relaunching that identity reproduces every draw, and random otherwise. A pinned preset now reproduces its noise seeds too; seeds the caller sets are kept. - Concurrent AsyncNewBrowser launches on one driver interleaved pin/restore: one browser inherited the other's mask and the driver could stay pinned. pin -> launch -> restore is serialized per driver. - Every pinned browser landed on cores 0..N-1; pins now take N adjacent cores from a random start. - A pinnable host with 1-3 cores reported 1, 2 or 3 (2 is the resistFingerprinting value); the table floor of 4 applies as on other hosts. - launch_options() callers that launch the browser themselves (launch_server, direct use) kept the drawn core count although nothing pins the browser; only Camoufox/AsyncCamoufox pass pin_cpu_cores=True now, everyone else reports the host's snapped count. - PLAUSIBLE_CORE_COUNTS gains 18, 22, 28 and 32, all recorded in the -v150 corpus. - The Windows voice list was drawn before the locale was resolved, so an fr-FR identity got en-US voices; it is drawn after locale/geoip now. - macOS "Alex" gets its com.apple.speech.synthesis.voice identifier. - CAMOU_PREFS env chunks are ASCII-only JSON (Windows getenv goes through the ANSI code page). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(fonts): canvas accepts CSS2 system-font keywords; local() works on macOS - GetSpoofedSystemFontForRFP's per-OS branches returned before marking the result a system font. ComputeSystemFont copies that flag into FontFamilyList::is_system_font, and without it the canvas font setter could not serialize the value: ctx.font = 'caption' (or icon, menu, message-box, small-caption, status-bar) was silently ignored and read back '10px sans-serif' where stock reads back the keyword. - CoreTextFontList::LookupLocalFont builds a CTFontEntry with no family name, and local() sources are held to the spoofed font list by the resolved family, so on macOS every local() face (Helvetica, Menlo, Arial...) failed with NetworkError, installed and allowed or not. The entry now carries the family CoreText resolved. A blocked lookup's entry is released instead of leaked. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(webgl): only device limits come from the spoofed table getParameter still answered ~100 state pnames from the table, so state the page had just changed read back wrong: UNPACK_FLIP_Y_WEBGL / PREMULTIPLY_ALPHA / COLORSPACE_CONVERSION after pixelStorei, FRAGMENT_SHADER_DERIVATIVE_HINT after hint(), DRAW_BUFFERi after drawBuffers(), RED/ALPHA/DEPTH/STENCIL_BITS and IMPLEMENTATION_COLOR_READ_* for the bound framebuffer, and COMPRESSED_TEXTURE_ FORMATS after enabling an extension. UNMASKED_VENDOR/RENDERER_WEBGL came back without the extension enabled, where stock returns null with INVALID_ENUM. The table now answers only the MAX_*/ALIASED_*/SUBPIXEL_BITS limits, WebGL 2 limits on WebGL 2 contexts only, and extension limits (anisotropy, draw buffers, OVR multiview) only once that extension is enabled; everything else is the real context's answer. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(webrtc): fabricate candidates only where a real gather would have them With webrtc:ipv4/ipv6 set (every geoip launch), new RTCPeerConnection() with no iceServers produced a srflx carrying the spoofed IP, and after end-of-candidates a second host set with a different mDNS name. getStats() exposed that srflx as id 'camou-srflx' and rewrote every candidate address, including .local host names and the remote peer's candidates. A srflx is now fabricated only when the page configured an ICE server, host candidates only when none reached the page (sharing the real UDP host's port otherwise), the synthetic stats id has the shape real candidate ids have (8 hex digits, fixed per connection), and only this side's non-mDNS addresses are rewritten. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(media): honour mediaDevices:enabled=false; page fake:true behaves as stock - MaskConfig::GetBool returns std::optional<bool>, and the checks tested its presence: "mediaDevices:enabled": false still enabled the fake devices. - media.navigator.permission.fake=true was page-readable: a page's own getUserMedia({video: true, fake: true}) prompted and never resolved, where stock resolves at once with its generic fake device. The pref is off again; the identity's devices count as real hardware in the capturing checks instead (prompt, sharing indicator, post-grant labels), and a page's fake:true request gets stock's generic devices rather than the identity's. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(storage): per-context values are session state, and misses are cached - Values lived on the user pref branch, which a persistent profile writes to prefs.js: relaunching with a different timezone (or navigator values) kept reporting the previous session's in the page, iframes and workers. They now live on the default branch, which is never saved, and reads ignore user values an older build left behind. - A read of an unset key did a synchronous IPC to the parent every time, and in a launch without per-context values every read is unset: navigator.hardwareConcurrency, screen.* and (color) media queries measured ~20x slower than stock. A miss is now cached per key until a pref change or a local put clears it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(timezone): no per-realm override for the process-wide zone; cache DateTimeInfo With a launch-level timezone every new document and worker got a per-realm override of the zone the process already reported. Setting one releases all JIT code in the runtime (hot code after adding an iframe ran ~4x slower), and the realm rebuilt its DateTimeInfo on every call (getHours() ~40x slower than stock). The override is applied only when the zone differs from the one JS::SetTimeZoneOverride applied process-wide, and a realm keeps its DateTimeInfo until its override changes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(juggler): wheel scrolls in native notches; Shift leads the key it modifies - A wheel notch now reaches the page as its own 3-line event carrying one native tick (new WHEEL_EVENT_NATIVE_NOTCHES option in patches/wheel-native-ticks.patch), so wheelDelta is -120 per notch as with a physical wheel; it was -396, and a multi-notch scroll arrived as one event. Several notches are spaced a few tens of ms apart. - Auto-Shift pressed Shift 0 ms before the character's keydown and released it 0 ms after its keyup; it now leads and trails by a drawn human-scale delay, and a failing keydown no longer leaves Shift latched. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(settings): stock cookie partitioning, preconnect, popup notification; about dialog CSS - network.cookie.cookieBehavior 4 (Playwright's) -> Firefox's default 5. With 4 a cross-site iframe (captcha and anti-bot widgets are exactly that) sees document.hasStorageAccess() true and its first-party cookies and localStorage, where stock partitions them. Playwright set 4 so storageState need not carry thirdPartyCookie^ permissions. - network.http.speculative-parallel-limit 0 turned <link rel=preconnect> into a no-op, visible in Resource Timing. - privacy.popups.showBrowserMessage false: stock shows a notification bar for a blocked popup, which shrinks the viewport and fires resize. - chrome://branding/content/aboutDialog.css is page-loadable and was empty; it is the official branding's now. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * test(patches): stock-parity probes for the leaks found in review One launch (plus two persistent relaunches) checks page-observable invariants stock Firefox 152 holds: canvas CSS2 system-font keywords, WebGL state readback and UNMASKED_RENDERER without the extension, no srflx without ICE servers and no 'camou' stats id, getUserMedia({fake: true}), cross-site storage partitioning, wheel notches, per-read cost of (color)/hardwareConcurrency and of local Date getters under a launch timezone, and a persistent profile's timezone after relaunch (page and worker). Run against the build before these fixes it fails on every one of them. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * test(humanize): judge cadence by distinct values and spread, not a share of the gap count The page clock is clamped to 1 ms and Cursory's recorded steps mostly sit between 12 and 20 ms, so the number of distinct gap values cannot grow with the number of gaps. Requiring len(gaps) // 4 made the guard fail on visibly uneven runs whenever event delivery was steady (3 of 4 runs once the per-read sync IPC jitter was gone). A fixed 10 ms cadence yields about three values within a few ms of each other, which the new rule (>= 6 values, >= 20 ms spread) still fails. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(juggler): restore the popup, wheel and history contracts The Playwright suite went red on this branch, and five of its six shards ran out their 40-minute budget before reporting, so ~470 sync tests were never run at all. Three causes, all ours: - window.open() from page.evaluate() returned null. The popup blocker being ON (Firefox's default) and evaluate() no longer granting user activation are each defensible alone; together they block every gesture-less popup. ~35 tests, each burning 30s x 4 attempts x 2 worlds, which is what exhausted the shards. The blocker goes back to Playwright's and geckodriver's value. Reading it costs a detector a popup window the user sees, so it is not a check an anti-bot script in the page runs -- unlike navigator.userActivation.hasBeenActive, which is one property read, and which is why the activation half stays. - mouse.wheel(0, 100) delivered deltaY 114 (or 132, depending on the host's font metrics) in deltaMode 1. Quantising into native wheel notches is what a physical wheel does, but it changes the number the caller asked for, so it now rides behind humanize= with the rest of the humanized input. Default is the exact requested delta in deltaMode 0. - page.go_back() did nothing after history.pushState(). canGoBack is the BACK BUTTON's answer: under browser.navigation.requireUserInteraction it reports false when every entry behind this one was pushed without the user touching the page, which is now every entry, because evaluate() grants no activation. goBack() itself does not skip those entries and neither does history.back(), so ask canGoBackIgnoringUserInteraction, as Marionette does. Two keyboard tests are skiplisted rather than fixed: auto-Shift means typing "!" emits the Shift a US keyboard requires, and upstream asserts the character's three events with shiftKey false throughout. The character's own key/code/keyCode are unchanged; what upstream asserts is the absence of a Shift no real typist could omit. Full suite against the fixed build: 2223 passed, 6 failed -- the two keyboard tests above, and four client-certificate tests that fail only on this machine (Node/OpenSSL rejects the fixture server) and pass in CI. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(pythonlib): stop overriding the corpus on core counts; pinning is opt-in Two findings from auditing the sweep's fixes against one bar: a difference is a leak only if a page's JavaScript can actually read it. hardwareConcurrency 2 was excluded from PLAUSIBLE_CORE_COUNTS because "2 is what Firefox reports under resistFingerprinting". That has not been true for years: RuntimeService::ClampedHardwareConcurrency hardcodes 4, and 8 on macOS, both of which are already in the table. The exclusion protected against nothing and cost every genuinely dual-core machine -- 20% of the macOS presets in the recorded corpus, 4.2% of Linux draws. It also made the small-host tail worse: a 3-core host reported 4, which cannot be pinned, so a page measured 3 while being told 4. At 2 the pin succeeds. pin_cpu_cores now defaults to False. What it buys is defence against a page timing N parallel workers; what it costs is a browser-wide CPU cap, a per-driver launch lock, and nothing at all on macOS. Unpinned, the host's own snapped count is reported, so reported and measurable still agree -- the identity just loses one drawn value. Callers who want the draw kept can still ask for it. The WebGL sampler keeps rejecting software rasterisers, and its docstring now says so: it described the opposite of what the code does. llvmpipe as the presented GPU is a live check on a string every fingerprint script reads, which is worth ~1.5% of corpus fidelity. 251 pythonlib tests pass. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(pythonlib): keep 2 out of the core table -- an Apple M1 is never dual-core Reverts the PLAUSIBLE_CORE_COUNTS half of |
||
|
|
0169975638 |
fix(config): declare media:spoof_codecs, and guard the whole class
PR #562 added a `media:spoof_codecs` read on the C++ side -- MaskConfig::GetBool("media:spoof_codecs") in MP4Decoder and MatroskaDecoder -- but never declared the key in settings/. Since validate_config() drops any key it does not recognise, the documented usage was inert: AsyncCamoufox(config={"media:spoof_codecs": True}) -> "Skipping unknown patch media:spoof_codecs : True" The key never reached the browser, so the feature could not be turned on through the supported path at all. Declared in both properties.json and camoucfg.jvv (bool, beside mediaDevices:enabled). The new test is the general form rather than a check for this one key: it scans patches/ and additions/ for MaskConfig::Get*/Has*("key") reads and fails when a key is not declared in settings/properties.json. A patch and its schema entry are two halves of one change, and shipping only one half is a mistake this project has now made in both directions -- canvas:seed (#721) and navigator.maxTouchPoints (#696) were declared but unconsumed; this one was consumed but undeclared. Across the tree the scan finds 63 reads against 109 declared keys, and media:spoof_codecs was the only gap. Note the runtime reads properties.json from the *installed browser bundle*, not the repo, so this fix only takes effect for a build packaged after it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GQgHHGRXNp29jr4xQjK7iv (cherry picked from commit 375b0fca4529a722220022c7993c030b83439db1) |
||
|
|
dc201ddee8 |
test(playwright): run the vendored suite in the page's own world
The suite in tests/async is upstream Playwright's conformance suite, so it asserts upstream semantics: tests read globals their own page scripts defined and pass element handles into evaluate(). Under Camoufox's isolated world about 59 of them fail on "X is not defined" for a global the page really did set. The "mw:" prefix cannot stand in -- it refuses handles by design (Runtime.js) and much of this suite needs them -- so this adds a disableWorldIsolation config key that makes the default world the page's own, and turns it on for this suite only. The flag gives up the property this fork exists for: automation JS becomes visible to the page again. It is a conformance-suite mode, not a scraping mode. Camoufox's isolation keeps its own coverage in tests/patches/isolated-evaluate.py, which must go on passing without the flag. Measured on beta.30 with Playwright 1.62: 73 failed/1023 passed -> 14 failed/1082 passed, with no test failing that was not already failing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
d5d7713684 | fix: add allow_addon_new_tab launch option | ||
|
|
2b08ae0c51 |
fix(stealth): restore a real session history; re-enable network-state partitioning
Two one-line pref changes in settings/camoufox.cfg. 1. browser.sessionhistory.max_entries: 0 -> 50 (F1, #326, #196) Setting this to 0 was grouped under "turn off bfcache", but it is not what disables bfcache -- fission.bfcacheInParent=false (line 487) and max_total_viewers=0 do that. What max_entries=0 does is leave the session history with no entries at all, so window.history.length reports 0. The HTML spec guarantees a browsing context always retains at least its current entry, so history.length >= 1 in every real browser. 0 is therefore a zero-false-positive automation tell that any page script can read with no timing and no heuristics. It also makes page.go_back() a silent no-op. Measured on the shipped 152.0.4-beta.28 binary, three navigations: entries=0, viewers=0 history.length=0 go_back: no-op bfcache: unused entries=50, viewers=0 history.length=3 go_back: works bfcache: unused entries=50, viewers=-1 history.length=3 go_back: works bfcache: unused So 50 (Firefox's stock default) restores correct history semantics and working back-navigation without bfcache ever serving a page. This is also why the existing `enable_cache=True` workaround for #196 works: CACHE_PREFS in utils.py already resets max_entries to 10. 2. privacy.partition.network_state: false -> true (#577) This is Firefox's stock default and the documented mitigation for the favicon-cache supercookie; disabling it also un-partitions the HTTP cache, connection pool, DNS cache and HSTS store. Being straight about the evidence: on FF152 I could NOT demonstrate an open channel. With a working same-site control (cached: 1 fetch), a shared third-party subresource loaded from two different top-level sites produced 2 fetches and 2 distinct TCP sockets with the pref BOTH false and true -- the HTTP cache and the connection pool are already partitioned either way. So this is a stock-default/consistency change and defense-in-depth for the channels the pref still governs (DNS, HSTS, TLS session resumption, favicon cache) that I have no probe for -- not a demonstrated leak fix. It measured as behaviour-neutral in both directions, so the performance risk that presumably motivated disabling it looks negligible on FF152. Worth re-checking against the build-tester score. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
0e4151f820 |
fix: page-recycle hang under spoofed window dims, and the unmerged halves of #637-#647
Fixes the new_page() hang from #666, and restores the pythonlib/ + settings/ halves of #637-#647 that were dropped when those PRs were consolidated into #666 (that PR only carried patches/ + additions/, so these never actually landed). ## new_page() hangs when window.outer* is spoofed (#666) The outer-size hijack in browser-init.patch pinned the chrome documentElement to the spoofed size. That caps .browserStack, which caps the content viewport, so the content window can never reach the size Juggler asks for in updateViewportSize() -- and awaitViewportDimensions awaits exact equality with no timeout, so it deadlocks rather than erroring. The second new_page() hung forever and took the context with it. The pin was never load-bearing: GetOuterWidth/GetOuterHeight already consult MaskConfig unconditionally (fingerprint-injection.patch), so window.outerWidth is spoofed in C++ regardless of the real chrome window size. Resizing is enough. Measured on the official v152.0.4-beta.26 build (headless): config before after none pass pass inner pass pass outer HANG pass both HANG pass (iw:360 ih:740 ow:360 oh:800 -- exact) This corrects the diagnosis in #666, which blamed the inner+outer combination and the `!(outerWidth || outerHeight)` guard. outer* ALONE is sufficient to hang, and dropping inner* does not help, so that guard is not the culprit. Also fixed driver-side: Playwright's implicit 1280x720 viewport is what asks for the impossible size, so the driver now defaults to no_viewport when the config spoofs any window dimension. That fixes the hang on already-released builds without a rebuild. An explicit viewport=/no_viewport= from the caller wins. ## WebRTC ICE prefs (#538) #666 merged the C++ half of the WebRTC fix but not the prefs, so the shipped build still has no_host=true and none of the proxy_only prefs. proxy_only_if_behind_proxy is the pref that actually stops the real-IP leak: it prevents a UDP STUN request routing around a TCP proxy. no_host=false keeps the stock two-candidate shape, which obfuscate_host_addresses makes leak-free. ## Also restored from the consolidation - fix(proxy): dom.security.https_first rewrote http:// before the launch-arg proxy filter saw it, breaking CONNECT-only proxies (#638). - fix(stealth): speech-voice spoofing + stop leaking host voices (#646). - fix(stealth): clamp inner <= outer <= avail <= screen; BrowserForge can emit impossible geometries that leak as tells (#647). Refs: https://github.com/daijro/camoufox/pull/666 Refs: https://github.com/daijro/camoufox/issues/538 |
||
|
|
fbf3196819 |
Add disableInstantAnimations opt-out flag
Instant CSS animations collapse finite animations to zero duration, which hides UI revealed only during an animation (e.g. the Microsoft "Press and Hold" CAPTCHA checkmark). Gate the behavior behind a config flag so it can be disabled. Fixes #664. |
||
|
|
8b5946e847 |
Replace disable-remote-subframes.patch with webContentIsolationStrategy=0 (#550)
The old patch gated BrowsingContext::SetRemoteSubframes() behind a config flag, preventing mUseRemoteSubframes from ever being set to true. This broke nested cross-origin iframes because CreateDetached() copies the parent's mUseRemoteSubframes directly (bypassing the patched setter), cascading false through all child browsing contexts. Strategy 0 achieves the same goal (no OOPIFs — all content same-process) via ShouldIsolateSite() returning false, without touching the setter. mUseRemoteSubframes propagates normally, so nested iframes work. Fission plumbing stays live: COOP handling, BFCache-in-parent, and cross-origin isolation for pages serving COOP+COEP headers are unaffected. Removes the enableRemoteSubframes config key (no longer needed). Refs #533 |
||
|
|
c6a6c20670 |
Camoufox 2.0: Hardware Spoofing + Python Package Updates (#519)
* feat: update timezone, geolocation, and locale spoofing patches - timezone-spoofing.patch: per-context timezone via per-realm DateTimeInfo - geolocation-spoofing.patch: CAMOU_CONFIG backwards compatibility for geolocation - locale-spoofing.patch: add camoucfg LOCAL_INCLUDES - anti-font-fingerprinting.patch: add RoverfoxStorageManager exports to moz.build * feat: per-context audio fingerprinting and screen spoofing patches - audio-fingerprint-manager.patch: per-context audio fingerprinting (all 6 API methods) - screen-spoofing.patch: per-context screen dimensions with global MaskConfig fallback - Disable webrtc-ip-spoofing.patch (will re-enable after fixing) - Remove screen-hijacker.patch (superseded by screen-spoofing.patch) * fix: add global MaskConfig hooks for navigator.platform, hardwareConcurrency, and timezone (#443) Fixes issue where global CAMOU_CONFIG settings for navigator.platform, navigator.hardwareConcurrency, and timezone were not applied in the main window Navigator (only WorkerNavigator was patched via fingerprint-injection.patch). * fix: run nsJSUtils::SetTimeZoneOverride() after SpiderMonkey has Initialized to prevent SIGSEGV * Add fingerprint improvements for PR #3 - navigator-spoofing.patch: Global config fixes for platform/hardwareConcurrency/timezone - timezone-spoofing.patch: Persistence across page navigation via SetNewDocument hook - audio-fingerprint-manager.patch: Full 6-method coverage with self-destruct pattern - screen-spoofing.patch: Per-context dimensions with self-destruct pattern - webrtc-ip-spoofing.patch: Re-enabled with getStats() sanitization + comprehensive IPv6 regex * fix: simplify userContextId to BrowsingContext + add per-context docs * feat(navigator): Add per-context spoofing (platform, oscpu, hardwareConcurrency) with global fallback + docs update. * fix(navigator): use 2-arg GetUint(key, value) for RoverfoxStorageManager * fix(navigator): header line count build error * fix(navigator): move NavigatorManager.cpp into SOURCES for leakage error * fix(navigator): more line count build errors * fix(navigator): include nsTHashMap and nsHashKeys.h before RoverfoxStorageManager * feat(webgl): per-context spoofing patch * fix(webgl): changed GetCanvasElement() to mCanvasElement() for firefox version * fix(webgl): remove coupled self-destruct * feat(canvas): per-context spoofing * feat(font-list): per-context spoofing * fix(font-list): use GetOwnerWindow() instead of GetOwner() * feat(speech): per-context spoofing * fix(speech): add /dom/base inside local_includes * fix(speech): changed context to avoid conflicts * feat(navigator): add WorkerNavigator hooks for per-context platform and hardwareConcurrency in workers * feat(timezone): add per-context timezone override to workers * fix(canvas): add OffscreenCanvas userContextId support and skip zero pixels in canvas noise * fix(screen): hook nsMediaFeatures GetDeviceSize for per-context matchMedia device-width/height * fix(webgl): add OffscreenCanvas userContextId fallback in WebGL GetUserContextId * fix(canvas): make canvas noise use proper format for BGRA toDataURL path * fix(canvas): line count fixes * docs: updated hardware per-context documentation * Final Per-Context Hardware Fingerprint Spoofing (#9) * feat(navigator): Add per-context spoofing (platform, oscpu, hardwareConcurrency) with global fallback + docs update. * fix(navigator): use 2-arg GetUint(key, value) for RoverfoxStorageManager * fix(navigator): header line count build error * fix(navigator): move NavigatorManager.cpp into SOURCES for leakage error * fix(navigator): more line count build errors * fix(navigator): include nsTHashMap and nsHashKeys.h before RoverfoxStorageManager * feat(webgl): per-context spoofing patch * fix(webgl): changed GetCanvasElement() to mCanvasElement() for firefox version * fix(webgl): remove coupled self-destruct * feat(canvas): per-context spoofing * feat(font-list): per-context spoofing * fix(font-list): use GetOwnerWindow() instead of GetOwner() * feat(speech): per-context spoofing * fix(speech): add /dom/base inside local_includes * fix(speech): changed context to avoid conflicts * feat(navigator): add WorkerNavigator hooks for per-context platform and hardwareConcurrency in workers * feat(timezone): add per-context timezone override to workers * fix(canvas): add OffscreenCanvas userContextId support and skip zero pixels in canvas noise * fix(screen): hook nsMediaFeatures GetDeviceSize for per-context matchMedia device-width/height * fix(webgl): add OffscreenCanvas userContextId fallback in WebGL GetUserContextId * fix(canvas): make canvas noise use proper format for BGRA toDataURL path * fix(canvas): line count fixes * docs: updated hardware per-context documentation * feat(screen): screen avail per context * fix(font): align userContextId resolution to BrowsingContext * fix(audio): align userContextId resolution to BrowsingContext * Avoid macos caching (#11) * the property to undefined before deleting * undo webrtc undefined * feat: userContextId added to WordCacheKey * fix: hunk line counts for macos cache changes * fix: add WorkerPrivate fallback in OffscreenCanvas * fix(audio): transformation added to mSharedChannels path to ensure consistency * fix(webgl): added WorkerPrivate to ucid * fix(timezone): add ucid=0 fallback for worker timezone resolution * fix(audio): move seed lookup outside window guard for all 6 hooks * fix(canvas): add ucid=0 fallback and WorkerPrivate resolution for workers * fix(navigator): add setNavigatorUserAgent and ucid=0 fallback and WorkerNavigator for UA spoofing fix * fix(webgl): add ucid=0 fallback and WorkerPrivate resolution * fix(webgl): decouple vendor/renderer self-destruct * fix(navigator): add main-thread navigator.userAgent getter hook * fix(navigator): add MaskConfig hook for navigator.appVersion in main window * feat: Add Chakra Petch font for macOS to solidify detection on CreepJS * fix(fontconfig): rename to match Go launcher, add TTC aliases and update .gitignore * fix(navigator): oscpu missing MaskConfig global fallback * feat: add real fingerprint presets (65 firefox profiles) - mainly to test with, more will come when tested. * feat: use real fingerprint presets as default with BrowserForge as fallback * feat: add audio:seed and canvas:seed to property schema and validation * feat: add MaskConfig fallback to seed managers for cross-process worker consistency - don't need to disable fission * fix(font): moved mUserContextId declaration before mRounding in WordCacheKey so init order matches * fix(audio): line count correction * fix(canvas): line count fix * feat: add per-context fingerprinting API (NewContext/AsyncNewContext) + merge upstream - fix seed range - add oscpu derivation from platform, and timezone mapping in from_preset() - new real fingerprints preset support * feat: new presets + en-US only, stripped fonts/language, clamp DPR * feat: random 30-78% font subset generation for NewBrowser and NewContext * fix: add fission.autostart=true to camoufox.cfg - will be changing this soon with new update so processCount is not 1, so it will be undetectable * fix: update macos fonts.conf rendering settings * feat: cross-process fingerprint storage via Firefox Preferences API Replace RoverfoxStorageManager's per-process static HashMap with Firefox's built-in Preferences system. Values stored as CString prefs under "roverfox.s." namespace, auto-synced to all content processes by Firefox. Content processes can't set prefs directly (ENSURE_PARENT_PROCESS), so a single IPDL message (RoverfoxStoragePut) routes writes through the parent. Same public API — all 10 dependent patches require zero changes. Removes dom.ipc.processCount=1 from camoufox.cfg. Firefox now uses Playwright's default multi-process model (fresh process per page) with fission enabled, while fingerprint values remain accessible everywhere. * fix(cross-process): hunk headers and build fixes * fix(storage): add local write-through cache to RoverfoxStorageManager * fix(storage): add sync IPC read fallback for cross-process fingerprint propagation * fix(storage): add NS_IsMainThread guard to sync IPC fallback - prevent crashes * fix(storage): sync IPC + pref whitelist for cross-process fingerprint sync * feat: full documentation update, speech voices generated per context and BrowserForge primary fingerprint generation method for global and per context. * fix: Direct3D NVIDIA GTX 980 renderers incorrectly appearing on mac because of duplicates * Update .gitignore --------- Co-authored-by: PopcornDev1 <e.coiley@icloud.com> Co-authored-by: Build <build@local> Co-authored-by: Elliot Coiley <153072396+PopcornDev1@users.noreply.github.com> |
||
|
|
3bf91de311 | feat: Support for passing certificates & cert files | ||
|
|
cf28f78658 | Merge latest Playwright patches #230 | ||
|
|
c75baab79b | Workaround to restore custom match media without disabling HiDPI | ||
|
|
c2b5eb14ba | Fix devPixelsPerPx cfg value | ||
|
|
3484b7c4be | Fix WebRTC IP leaks in SDP log #184 | ||
|
|
3c2621d5c0 | Disable hidpi by default | ||
|
|
2a250720a6 | Add the disableTheming property to config map #179 | ||
|
|
8a1abfb9a5 | Disable OOPIFs without disabling COOP #150 | ||
|
|
cf269d6b60 |
feat: Force system principal scope access (forceScopeAccess)
A workaround to restore some original Playwright functionality. Forces Playwright to run in "God mode", allowing it to bypass CORS restrictions, access shadow roots (with element.shadowRootUnl), access undocumented JS browser methods, modify DOM without `allowMainWorld`, & restore some unsupported Playwright functionality. Note: `forceScopeAccess` is not detectable/visible to the page unless the dom is directly modified (elements are added or removed). |
||
|
|
33085c90f3 |
Merge with Playwright a121f85
Merges patches with the latest commit: https://github.com/microsoft/playwright/commit/a121f85ce91b67aeb1191e2fcca0939ad5b38671 |
||
|
|
b3e7636378 |
Cleanup pref file
Reverted certain config related to offline caching restrictions, better organization, removed non essential prefs, etc. |
||
|
|
e01c2d6476 |
Increase process count for perfomance boost while keeping it a realistic number
Using 16 is to balance process isolation and resource use as using 60000 as PlayWright is impractical and may cause instability. |
||
|
|
499fcd5442 |
Enable clipboard Events
Websites can check if clipboard events are turned off, this hurts stealth |
||
|
|
e1fc678719 | Do not underline links | ||
|
|
9b8eed1d24 | Use Skia azure backend by default | ||
|
|
a8e0855639 |
[Closed] feat: Canvas anti-fingerprinting beta.19
Added undetectable Canvas shape & line fingerprint rotation by modifying the Skia rendering pipeline. This bypasses all known Canvas pixel integrity tests. Note: Due to this repository being monitored, the source for this patch is closed. All GitHub releases will still have this patch included in it. However, this patch will not be included in local builds of Camoufox. |
||
|
|
31963aa83b | pythonlib: Update WebGL sample database | ||
|
|
4305385f0b |
feat: Main world JS evaluation
Experimental support to execute in the main world. Usage: `page.evaluate("mw:<script>")`
Has only been implemented to pass JSON serializable objects to/from the main world (Isolated worlds are still the default, and should be used unless necessary).
|
||
|
|
3e524aa2ea | Include jvv validator file in packaging | ||
|
|
ad807b2ffe | Bump to FF133 beta.18 | ||
|
|
045877746d | jsonvv: Less restrictive property groups for BrowserForge | ||
|
|
31b5c0fceb |
jsonvv: Add Camoufox config validator #90
Added a Camoufox jsonvv property file to allow users to check if their passed config is incomplete/may cause leaks. This will also validate WebGl types and fix the crashing issue presented in #90. |
||
|
|
c5cad3040c | Bump to beta.17 | ||
|
|
85eb40aee4 | Leak fixes #90 | ||
|
|
ed87adf6fe | Update properties & release beta.16 | ||
|
|
1e8e667641 | Memory optimization fixes #87 | ||
|
|
e126cf379c | Update uBlock Origin assets & updater | ||
|
|
cc01ab2088 | Remove privacy.clearOnShutdown config #69 | ||
|
|
74d016e9a9 |
feat: Voice spoofing
- Added `voices` parameter, which takes a list maps for each voice to add. Example:
`[ {"isLocalService": true, "isDefault": true, "voiceUri": "Ting-Ting", "name": "Ting-Ting", "lang": "zh-CN" } ... ]`
- Added `voices:blockIfNotDefined` has been added to block system voices
- Added `voices:fakeCompletion: bool` and `voices:fakeCompletion:charsPerSecond: double` to set a fake playback speed.
|
||
|
|
d279ed0cf0 |
Add font spacing seed #38
Adds fonts:spacing_seed to control the spacing of rendered text. |
||
|
|
dc3c0bde16 |
Misc fixes beta.13
- Fixed some memory enhancement prefs not setting correctly. - Bfcache is now completely disabled. This should improve memory, but kills Playwright's page.go_back() and page.go_forward(). To re-enable this, set `browser.sessionhistory.max_entries` to the amount of pages you want to remember. - Moved SanitizeOnShutdown policy to preferences instead. This unlocks clearOnShutdown preferences. #47 - Added experimental memorysaver property that clears all of the memory after each page.goto navigation. Helpful for datacenters running Camoufox, but could potentially break things. - Cursor now starts in a random position on the screen - Fixed screenshots not capturing the full window when a viewport is set by window.innerWidth and window.innerHeight. |
||
|
|
711b5b4550 |
Backwards compatibility with <0.3.0
Change ALL webgl keys to webGl. This keeps backwards compatibility with <0.3.0 versions of the Python library. |
||
|
|
0ff90fc750 |
Version range control, multi locale usage, etc
- Python library now constrains the supported Camoufox version, and will force an update if you are out of date. - Added support patch for multiple accepted languages #37 - Added pysocks #43 - Added README deprecation notices - Added public launch_options command - Bumped python library to 0.3.0 - Full support for beta.12 |
||
|
|
5bfc3ee026 |
Further improved WebGL spoofing beta.12
- Added ability to spoof webgl2 supported extensions - Added ability to block parameters that aren't defined in config - Passing null in config will block the value - Added more parameters to the demo site |
||
|
|
1532d7bb31 |
Consistent naming of webgl properties
Always use "webgl:" instead of "webGl:" |
||
|
|
02bc15161a |
feat: WebGL fingerprint spoofing
Experimental WebGL fingerprint injection. - Allows the ability to set all WebGL parameters, supported extension list, shader precision formats, & context attributes. - Added a demo website under scripts/examples/webgl.html that can be used to generate Camoufox config data |
||
|
|
595828a446 | Update Makefile & add navigation debugging | ||
|
|
80b084a9b3 |
feat: Add human-like cursor movement & cursor highlighter #19 beta.10
All info in README. |
||
|
|
5263cb6305 |
Add locale spoofing #16 beta.8
Spoof the Intl API, headers, and system locale values. Added the following properties: - locale:language - locale:region - locale:script |
||
|
|
8385561b19 |
Add timezone spoofing #5
Adds "timezone" property to set a custom tz identifier (ex: "America/Chicago"). Also changes Date() properties to return the local time. |