6 ms·
Disclaimer: I am a Chrome developer, who formerly worked on the clipboard. For a long time, Chrome did not allow pages on the open web to use document.execComm
by zetafunction 4y ago
Disclaimer: I am a Chrome developer, who formerly worked on the clipboard.
For a long time, Chrome did not allow pages on the open web to use document.execCommand('copy') or document.execCommand('cut'), and there was a fairly steady stream of requests from web developers to enable this. Eventually, Chrome did expose this gated behind a user gesture: https://chromestatus.com/feature/5223997243392000 https://chromestatus.com/feature/5223997243392000
> So instead of changing their new tab page to require a gesture like all other sites... they decided to allow any website to copy text into the clipboard. Nice.
Ownership of the clipboard features has moved around a bit, and sometimes historical context around things like the user gesture requirement are lost. Here, the NTP doesn't actually need this to work without a user gesture. The correct fix here is to fix the NTP tests to correctly simulate a user gesture, not to allow writing to the clipboard without a user gesture.
> I think copying into the clipboard needs an overhaul—even with a gesture. Don't you hate when news sites add a "- from XYZ" to your clipboard? That shouldn't be possible. I'm not sure how you'd fix this, but it should be fixed.
This is a difficult problem to fix. There are absolutely websites that abuse this. But there are also pages that do use the legacy clipboard API events in non-abusive ways (e.g. rich text editors), and blocking this outright would break legitimate uses as well.
Maybe something like a "copy as plain text" option would make sense...
- userbinator 4y agoWhy do you call it a "user gesture" and not "consent" as it should absolutely be? Is it to reinforce the notion that users' actions are only to be taken as mere suggestions and ignored if they are contrary to your goals?
- PoignardAzur 4y ago> Is it to reinforce the notion that users' actions are only to be taken as mere suggestions and ignored if they are contrary to your goals? Wow, rude. One possible answer to your question: there is no way for a browser to detect "consent", which is a subtle and nuanced concept, but user gestures have a hard and fast definition, so that's the proxy they use.
- ndriscoll 4y agoWhen a site wants access to my camera or microphone, the browser detects my consent by asking me. I don't see why listening to clipboard events shouldn't be treated in the same way. Likewise with mouse and keyboard tracking events. The number of sites that reasonably need to know when I copy/paste or need to override what happens when I do that is approximately zero. There's no reason to allow it by default for all sites.
- samwillis 4y ago"user gesture" and "consent" are two completely different things. Currently (until this bug) it’s supposed to trace back the call stack to the event that triggered it, and only allow it if the triggering event is something like a click. That’s what’s meant by “user gesture”, the opposite of code triggering it independently of the user. “Consent” would be a positive acceptance in a browser controlled message box asking for permission to use the clipboard. Most people agree that for copying to the clipboard the first is all that’s needed (there isn’t really a security concern here), for pasting from the clipboard the later is always required.
- userbinator 4y agothere isn’t really a security concern here See the other discussion here: https://news.ycombinator.com/item?id=32614839 https://news.ycombinator.com/item?id=32614839
- samwillis 4y agoOk, so there is a related vector here, but it requires the site your are on to be compromised. I would argue the actual vector is in the terminal, it should really validate the clipboard content.
- dotancohen 4y ago> Maybe something like a "copy as plain text" option would make sense That's ask I _ever_ want. I never want to copy rich text. I even have a background script that removes formatting from the clipboard every second, to make copying less frustrating. Hide it in some hidden flag or something, but please, make plain text copying an option!
- majou 4y agomacOS has "paste as plaintext" instead.
- macintux 4y agoI’ve remapped ⌘V on my work laptop to paste as plain text which works great everywhere except Outlook, which disables that in email metadata (recipients, subject). So bloody annoying, thanks Microsoft for continuing to make my life harder than it needs to be.
- lupire 4y agoBetter than Gmail which automatically parses text on paste, and, as the cherry on top, even when it recognizes that and alerts on a failed parse (making a red chip), refuses to let you edit the text to fix it.
- hosteur 4y agoGreat idea with such a script. Do you want to share it?
- dotancohen 4y agoSure, it depends on `xclip`, which you might need to install, and `perl` which you probably already have. I only run it while I'm actually copying and pasting as I don't like leaving loops running, that said, with the 1 second sleep it's really not so bad. #!/bin/bash while true ; do xclip -sel primary -o | perl -pe 'chomp if eof' | xclip -sel primary ; sleep 1 ; done Note that this affects only the primary selection, e.g. the copy-on-highlight and paste-on-middle-click clipboard. I hardly ever use the rodent, but when I do, this is what I use it for. You could easily adapt the script to the Ctrl-C Ctrl-V clipboard.
- lupire 4y agoAll we need is "copy without running JavaScript". Just look at what is actually rendered, and copy that. And it should be the default.