4 ms·
>Why not route traffic through my actual browser? Because you can't. Not even an Extension is able to. Browsers don't want you to bypass their content enforcem
by koolala 3mo ago
>Why not route traffic through my actual browser?
Because you can't. Not even an Extension is able to. Browsers don't want you to bypass their content enforcement. I wish we had at least one hacker friendly browser.
- rlmineing_dead 3mo agoExtensions can't, correct but I wanted to bring up a special case regarding this Isolated web apps a chrome feature for developing apps that run in chromium based on HTML (but tbh only really used in Chromebooks) do support raw TCP sockets so if this was ported to an IWA you could have Firefox on a Chromebook without an external server needed.
- koolala 3mo agoChromium CEF could also embed the Puter proxy inside it too as a standalone application. No luck on Mobile though.
- bawolff 3mo ago> Browsers don't want you to bypass their content enforcement I for one am happy that browsers dont let any random web page i visit port scan my internal network.
- koolala 3mo agoNo one said any site should. Letting a site you control do it is a perfectly valid user choice. Otherwise people are stuck going through third-party proxies which is far worse.
- maxloh 3mo agoNo, it is possible with extensions. Extensions can inject headers, such as Access-Control-Allow-Origin: *, to unblock cross-origin requests. In the Manifest V3 context, however, that might require patching window.fetch and window.XMLHttpRequest. For example, // content.js window.fetch = async (...args) => { const request = args[0] instanceof Request ? args[0].url : args[0] const config = args[1] || {} return new Promise((resolve, reject) => { chrome.runtime.sendMessage({ action: "proxyFetch", request, config }, response => { if (response.error) { const err = new Error(response.error.message) err.name = response.error.name err.stack = response.error.stack if (response.error.cause) err.cause = response.error.cause reject(err) } else { const base64Data = response.dataUrl.split(",")[1] const bytes = Uint8Array.from(atob(base64Data), c => c.charCodeAt(0)) const contentType = response.headers["content-type"] || "application/octet-stream" const blob = new Blob([bytes], { type: contentType }) const status = response.status const statusText = response.statusText const headers = new Headers(response.headers) const body = status === 204 || status === 205 || status === 304 ? null : blob resolve(new Response(body, { status, statusText, headers })) } }) }) } // Background.js chrome.runtime.onMessage.addListener((message, sender, sendResponse) => { if (message.action === "proxyFetch") { fetch(message.request, message.config) .then(async res => { const headers = Object.fromEntries(res.headers.entries()) const blob = await res.blob() const reader = new FileReader() reader.onloadend = () => sendResponse({ status: res.status, statusText: res.statusText, headers, dataUrl: reader.result }) reader.readAsDataURL(blob) }) .catch(err => { const { name, message, code, stack } = err sendResponse({ error: { name, message, code, stack } }) }) // Keeps the message channel open for the async fetch return true } })
- rlmineing_dead 3mo agoThis is a cors bypass but part of this demo is that it's full Firefox including TLS support. Using this still means intercepting all requests in an inspectable medium and does defeat part of the point
- koolala 3mo agoThis isn't enough for every website to load normally.