10 ms·
WebKit Quirks
- deleted 6y ago[deleted]
- TonyTrapp 6y agoI really dislike this sort of quirk workarounds, not just in web browsers. It just makes everything complicated. Someone else using the exact same code will get different behaviour, just because they serve it from a different domain. I did similar workarounds before (not related to websites but to specific files), and I felt very bad about it even though it was clear that no more files in that specific format would ever be generated again.
- matsemann 6y agoshouldBypassBackForwardCache() // Google Docs used to bypass the back/forward cache by serving "Cache-Control: no-store" over HTTPS. // We started caching such content in r250437 but the Google Docs index page unfortunately is not currently compatible // because it puts an overlay (with class "docs-homescreen-freeze-el-full") over the page when navigating away and fails // to remove it when coming back from the back/forward cache Millions of pages have this bug, because of Safari's broken navigation. Nice that the big players get the browser to fix it for them. For instance, a common issue is you click a button that becomes disabled and shows a spinner while working, before forwarding to a new page. If you click back from the new page, Safari will render the previous page exactly as it was when leaving, so in a broken loading state (instead of starting it from scratch).
- m_eiman 6y agoWhy shouldn't it show it in the same state? Seems like a reasonable thing to do.
- matsemann 6y agoIf it was a static page, then sure. But for dynamic pages or SPAs it more often than not leads to going back to a page in a broken state. Other browsers have better heuristics for when this cache is used. So Safari's behavior is unexpected, even so that the big guys are taken by surprise it seems. I don't really mind either way, the main thing is that it's inconsistent. It's not a huge deal, but it's just one of many small things making Safari annoying when developing. Especially since it cannot be tested without owning an Apple device.
- timw4mail 6y agoSounds more like an issue with the web apps to me.
- unilynx 6y agoThere is no spec to conform to to work around these cache issues. (IE was even worse in the past, shutting down the back forward cache if devtools were opened. Have fun debugging that) But imagine Windows opening an app, drawing the last known interface state and then skipping half of the app startup code. Should apps deal with that too, or would it be considered a Windows bug?
- my123 6y agoModern applications for Windows (UWP) and iOS do use tombstones. The app's memory itself is completely suspended/saved to disk, and then the state is restored. The app startup code is _not_ called again.
- tinus_hn 6y agoIt has been a while since I wrote iOS app code but I’m pretty sure iOS does not, although the libraries provide a mechanism you have to save and restore state yourself. And iOS doesn’t swap, it just kills apps when it needs memory. Anyway, how would you handle connections to remote servers?
- machello13 6y agoWhat makes it broken, out of curiosity? Is there a spec anywhere that suggests that behavior is incorrect? Or is it just because it's not what Chrome does?
- pcr910303 6y agoYeah, I'm interested too. I might be wrong, but AFAIK there aren't any specs on how a browser should implement forward/back buttons, right? I'm personally getting a ton of mileage on the Safari's much more stable forward/back cache, the fact that you can go back reliably gives me more comfort than other browsers where going back usually refreshes the page (although I can't really explain how this is much better). I personally feel that this bug is more of a web app bug rather than the browser.
- capableweb 6y agoThe closest you get for how browsers should act regarding history is part of the HTML spec here: https://html.spec.whatwg.org/multipage/history.html https://html.spec.whatwg.org/multipage/history.html Of course, the exact implementation is not specified, browsers are free to either implement cached behavior, which I think Firefox does as well, or just a naive refresh.
- tinus_hn 6y agoI think the closest is the pagehide event https://html.spec.whatwg.org/multipage/browsing-the-web.html#event-pagehide https://html.spec.whatwg.org/multipage/browsing-the-web.html... Which appears to be supported in Safari, just like all the other browsers.
- gsnedders 6y agoThere's a metabug on HTML at https://github.com/whatwg/html/issues/5880 https://github.com/whatwg/html/issues/5880 about defining how various platform-exposed features behave in the face of a bfcache (backwards/forwards cache).
- GranPC 6y agoI'm actually having a similar issue with my web app currently and I'm not sure what the best way to solve it would be. I was thinking of setting a checkbox in an invisible form when the page loads initially, and force a real reload if the checkbox was previously set, but that seems like a terrible hack. Any ideas?
- matsemann 6y agoWe use this to force a refresh: https://stackoverflow.com/a/13123626/923847 https://stackoverflow.com/a/13123626/923847 Or you can use that event to fix what's wrong on the page without a refresh if possible (remove a modal, enable the button again etc)
- GranPC 6y agoGreat! Looks like a proper way to do what I was trying to do. Thank you! My web app is a game, so fixing everything without a refresh is unfortunately pointless for the most part, and forcing a refresh also ensures players are running the latest version if they've been away for a while.
- zachrip 6y agoI've actually been dealing with this issue. Does anyone have an easy way to resolve it? It causes some pretty nasty rendering issues in our app.
- matsemann 6y agohttps://stackoverflow.com/a/13123626/923847 https://stackoverflow.com/a/13123626/923847 Can force a refresh when the page us navigated back to. Or use that event to fix whatever state your in.
- zachrip 6y agoFull refresh defeats the purpose of a spa unfortunately. I just tested that event and it actually doesn't appear to fire when navigating backwards, only when the page is initially shown...which contradicts the comments in that code.
- matsemann 6y agoMaybe you misunderstand the original issue. This is when navigating back to a "new" page, not internally in a SPA. But this issue mainly happens when navigating back to a page with dynamic behavior (typically a SPA or other interactive application).
- jaywalk 6y agoInteresting to see www.icloud.com in there...
- theXspidy 6y agohttps://thesnippets.substack.com/p/bitcoin-surges-past-51000-for-the?r=bpxxn&utm_campaign=post&utm_medium=web&utm_source=copy https://thesnippets.substack.com/p/bitcoin-surges-past-51000...
- TazeTSchnitzel 6y agoAnyone who's read a few Old New Thing posts would know that Windows must be full of similar checks.
- colejohnson66 6y agoIIRC, the “checking for a solution to the problem” dialogs were added because they (Microsoft) would submit an actual bug report to the developers, and if they offered a solution, Microsoft’s servers would respond with it. I’ve never seen it work, but IIRC, they added it back in the Windows 95 days (when there was a lot less software to deal with).
- chris_wot 6y agoThey really need to get rid of this.
- gruez 6y agoYou can disable it using group policy https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.ApplicationCompatibility::AppCompatTurnOffProgramCompatibilityAssistant_2 https://admx.help/?Category=Windows_10_2016&Policy=Microsoft...
- AshamedCaptain 6y agoThat was a Vista thing, definitely not 95. I have seen it working once, but I don't remember what the program was.
- colejohnson66 6y agoThat was Vista? Wow. I was way off...
- anaisbetts 6y agoWindows has tens of thousands of them. However, the vast majority of them unlike this quirks file are very very specifically gated to an explicit version range, file name, product name, etc etc, typically with consent of the app manufacturer.
- sdflhasjd 6y agoDomain name specific quirks? What in the world...
- robin_reala 6y agoOh, WebKit are absolutely not the only people doing this. Opera used to with their Presto engine, and I’m pretty sure I’ve seen a similar list in Gecko, though I can’t find it now. At the end of the day, this is the only way that non-Chrome browsers can meet Google’s hegemony, unless they give up and adopt Chromium itself. The opportunity cost of switching is too low for browser manufacturers no to have these workarounds; if a site is broken for a user, then they’ll change browser.
- sdflhasjd 6y agoYes, it is a real shame, but then again, a lot of these sites are made by reasonably big companies. I'm sure trello and such could fix whatever these input quirks are. Then there's autoplay specific behaviour on facebook, twitter and netflix. Is this really a google hegemony thing, or is this leniency that other sites don't get? I'm just trying to see if there's similar examples in Blink & Gecko right now.
- robin_reala 6y agoI work for a big company. There have been plenty of outstanding bugs in my company’s sites and apps, because the people that care aren’t in teams that own the systems with bugs in, or aren’t in a position to have their voices heard, and that’s before the hydra of ”legacy software” rears its many-consultanted head. (at least in my org we’re generally better at this now)
- erichurkman 6y ago> if (host == "trailers.apple.com") > return true; Even Apple themselves are not immune.
- abrowne 6y ago
- 0x0 6y agoI bet it's fun being responsible for developing and deploying on those sites. Works in CI and dev, but deploying to production makes the browser behave differently! Nice surprise!
- londons_explore 6y agoA lot of the domain filters use things like: topPrivatelyControlledDomain(url.host().toString()).startsWith("google.") The definition of `topPrivatelyControlledDomain` means that `google.github.io` would qualify, or `google.works.aero`... Pretty much anybody can abuse that to get any of the quirks modes available in this file. See the full list here: https://publicsuffix.org/list/public_suffix_list.dat https://publicsuffix.org/list/public_suffix_list.dat
- tholman 6y agoIf I'm understanding L958+ [1] There's a hyper specific css class browser quirk because the login button for gizmodo/kotaku/etc's CMS's svg icon click event wasn't firing... and here I am fixing my day-to-day browser bugs like a chump [1] https://github.com/WebKit/WebKit/blob/main/Source/WebCore/page/Quirks.cpp#L958 https://github.com/WebKit/WebKit/blob/main/Source/WebCore/pa...
- duckerude 6y ago> domain.endsWith("hulu.com") Huh, does that mean it would also apply on "thisisnothulu.com"? Most other endsWith calls seem to do e.g. `domain.endsWith(".hulu.com")` to only match subdomains.
- Sayrus 6y agoDamn, it seems you're right and it applies to any domain ending with this instead of hulu.com subdomains. From the name of the quirk, I'm not sure this is an issue though.
- Sephr 6y agoThis is to enable Safari's legacy EME implementation. I wonder if there are any vulnerabilities waiting in those unmaintained legacy codepaths https://github.com/WebKit/webkit/blob/master/Source/WebCore/page/Quirks.cpp#L141 https://github.com/WebKit/webkit/blob/master/Source/WebCore/... I first noticed this bug a year ago last February and it's been unchanged ever since.
- richdougherty 6y agoDefinitely a vulnerability there exploitable in concert with the error in the domain name check.
- deleted 6y ago[deleted]
- dillondoyle 6y agogood catch. just on a quick glance a few lines above might possibly be a good vector to test for ads to get around autoplay sound restrictions. make a domain ending with somethingnetflix.com, iframe it, and maybe figure out if the second link below has a class that allows override to allow autoplay sound without user interaction to something like kWKWebsiteAutoplayPolicyAllow with sound on. https://github.com/WebKit/WebKit/blob/f43587ec2416b86eecef5091fe028a08e168f976/Source/WebCore/page/Quirks.cpp#L136 https://github.com/WebKit/WebKit/blob/f43587ec2416b86eecef50... https://github.com/WebKit/WebKit/blob/88278b55563e5ccdc0b3419c6c391c3becc19e40/Source/WebKit/UIProcess/API/C/WKWebsitePolicies.cpp#L82 https://github.com/WebKit/WebKit/blob/88278b55563e5ccdc0b341...
- IMTDb 6y agoThat's new "you have made it when"...they need to change the browser engine for your website.
- mappu 6y agoI was surprised to see they're almost exclusively anglosphere websites, i would have guessed a broader variation
- capableweb 6y agoThe web is surprisingly segregated. Seems there is at least three versions of everything (from my perspective), from websites like the typical social network to utilities people use day to day, english/spanish/chinese.
- jakub_g 6y agoThere was a viral tongue-in-cheek tweet this month "how to prevent scrolling in Safari when..."? 1. Buy Zillow. Destroy the company. 2. Redirect your website to zillow.com (it was more fun that what I wrote) https://github.com/WebKit/WebKit/blob/f43587ec2416b86eecef5091fe028a08e168f976/Source/WebCore/page/Quirks.cpp#L703-L709 https://github.com/WebKit/WebKit/blob/f43587ec2416b86eecef50...
- kgin 6y agoIt's like that saying about debt. When a browser renders your 500 mau site badly it's your problem. When a browser renders your 50,000,000 mau site badly it's the browser's problem.
- lxe 6y agoWow, this is terrible. Either fix the bugs, introduce non-standard behavior for all sites, or expect these big players to fix their own problems.
- eyelidlessness 6y agoThey likely can’t. What happens when whatever quirk they used to isolate goes global and breaks workarounds on thousands of other sites they didn’t test? I mean, it’s awful that anything like this exists but it’s pretty likely well past any kind of turning back. Given WebKit’s lineage I have to wonder if some portion of this was inherited from KHTML.
- firloop 6y agoWow, there's not only _domain_ specificity, but also HTML _element_ specificity in this quirks list. // When panning on an Amazon product image, we're either touching on the #magnifierLens element // or its previous sibling. auto& element = downcast<Element>(*target); if (element.getIdAttribute() == "magnifierLens") return true; if (auto* sibling = element.nextElementSibling()) return sibling->getIdAttribute() == "magnifierLens"; https://github.com/WebKit/WebKit/blob/3def0062f77b82a46fc40c7154098b5fc0f12db9/Source/WebCore/page/Quirks.cpp#L416-L422 https://github.com/WebKit/WebKit/blob/3def0062f77b82a46fc40c...
- andrekandre 6y agoam i crazy or does this seem not scalable? at what point does it make more sense to just have a wasm "html-lib" provided by a specific site that it can depend on instead of burdening webkit/blink with all these unsafory hacks? if html-lib was versioned and slimed down to remove old hacks, it could he small enough to download quickly, and with hashing could ensure other pages that use the same version dont have to re-download again... at some point we could have other web front ends than html that can represent "apps" on the web better too... is that a crazy idea?
- throwaway744678 6y agoWow, there's a nice 77 characters function name [1]! Yes, with a typo. Hard to keep the lines under 80 characters... [1] https://github.com/WebKit/WebKit/blob/main/Source/WebCore/page/Quirks.cpp#L265 https://github.com/WebKit/WebKit/blob/main/Source/WebCore/pa...
- RandallBrown 6y agoI wonder if the typo was done on purpose given the point of the function is to suppress autocorrection.
- tabtab 6y agoWeb UI "standards" are a friggen mess. We really need to rethink it all. For one, if we had a standard state-ful GUI markup language, we wouldn't need to reinvent so many common GUI widgets and idioms using bloated libraries based on JS + DOM. Second, if web standards allowed true absolute positioning of vectors (as an option), then the layout engines could reside on servers, allowing us to choose a layout engine that best fits domain and need. Note that while existing web standards do have some coordinate based features, they are too inconsistent to reply upon. If they were any good, we wouldn't need PDF viewers.
- eyelidlessness 6y agoMy goodness a coordinates based layout system would be an enormous step backwards. We’d be back to `m.` subdomains and horizontal scrolling as the norm. The CSS layout standards are certainly not all ideal for my preferences. But the adaptability they afford in fluid layout is far better for real end users than any kind of absolute layout predetermined on a server. We’ve reached a point I can use most of the web on my phone without compromise and I’d hate to lose that for some development convenience.
- tabtab 6y agoI don't think you understand. The layout engine could be on the server, not "non existent". (Although one could program directly with coordinates if they wanted.) Coordinate based vectors allows the layout engine to be on the server, so that we are not stuck with a one-size-fits all layout engine. And what's wrong with the "m." standard as an option? For some jobs it's the right tool. And what's good for public site phone use may not be the right tool for internal CRUD applications. I don't recommend Google make an email client with the additions I suggest, for example. The existing standards are fine for light-input consumer sites, but lousy for productivity-oriented CRUD. I'm not saying get rid of existing standards.
- eyelidlessness 6y ago> I don't think you understand. The layout engine could be on the server, not "non existent". Oh, I do understand which is why the thing in your quotes isn't something I said. Layout on the server means you're laying out without the context of my device or viewport, and certainly without any change of context like if I switch to dark mode or prefers-reduced-motion, or if my data access changes. > And what's wrong with the "m." standard as an option? For some jobs it's the right tool. Instead of getting overly principled about it... one of the reasons it went away was because the heuristics that determined what even is mobile were becoming increasingly wrong. And like I said this resulted in a bunch of ridiculous horizontal scrolling for lots of users.
- saagarjha 6y agoIt's fun (and a little depressing) to look at this list, but it exists is basically every popular project. Unfortunately, the incentives are set up for this to essentially be necessary: if something popular doesn't work in your software, users are going to think your code is the one who is broken, not the thing they are trying to use. So you have a sort of a "tragedy of the commons" where if you keep a principled position a user is going to switch to your competitor that supports quirks to get the thing to work.
- shadowgovt 6y agoThe thing about network effects is this: When you're making a new technology to interact with existing technology, and following the specification results in your new technology failing to work with what's already there, nobody will care if you blame the standard or everyone's mis-implementation of the standard. They'll consider your malfunctioning tool as damage and route around it... Until you become big enough that you can be the existing implementation other people have to adapt to. Every commonly-used browser either has something like this buried in its implementation or has a date-stamp of first release older than everything else out there.
- spectramax 6y agoWe need something new here. This is not scalable. If a group of engineers can't write a new browser in sabbatical, then we need to change what a browser (and the spec) should be. Access to internet should be simple, not complicated so many can participate and leave control out of big corp.