mirror of
https://github.com/stablyai/orca.git
synced 2026-10-04 00:02:21 +00:00
The injected anti-detection script defined its own `navigator.webdriver` getter. Measured on a real Electron 43 <webview> guest, the engine already reports `false` — with and without a CDP debugger attached — so the override changed no value. What it did change is where the property lives: an own property on the navigator instance instead of Navigator.prototype, which is exactly what bot.sannysoft.com reads (`_.has(navigator, 'webdriver')`). Live three-arm run against that site: no script passes, this script fails, without the line passes. Two of 56 rows move across the arms; the other is HEADCHR_IFRAME, which the retained window.chrome branch fixes. The plugins and languages fallbacks go for the same reason: their premise is measurably false. The guest reports 5 real Plugin entries in a PluginArray and a non-empty languages list, so neither guard ever opened; had one opened it would have swapped a real PluginArray for plain objects and failed the plugins-type check it was meant to satisfy. The window.chrome branch stays. Electron leaves subframes without the object and the script is what supplies it, which is the HEADCHR_IFRAME row above. Also corrects the comment in cdp-debugger-channel.ts that claimed attaching the CDP debugger sets navigator.webdriver = true. It does not, on Electron 43 or on Chrome 152.