Compare commits

...
8 Commits
Author SHA1 Message Date
CloakHQ 776630e08b release: v0.3.32 — Windows extraction security fix, Widevine CDM seeding, cloakserve fixes 2026-06-20 03:17:07 +02:00
CloakHQ 402a884088 fix(download): pass extract paths to PowerShell via env vars
Windows zip extraction interpolated archive/dest paths directly into the
PowerShell -Command string. A single quote in the path (e.g. a Windows
account like C:\Users\O'Brien) closed the string literal early, breaking
extraction and creating a code-injection shape. execFileSync guards the
OS-shell boundary but not the PowerShell interpreter inside.

Pass both paths via env vars ($env:CB_ARCHIVE / $env:CB_DEST) so
PowerShell reads them as data, never as code. No escaping needed.

Python wrapper unaffected (zipfile module + argv).
2026-06-20 02:19:48 +02:00
CloakHQ 39db492b04 fix(examples): wait for reCAPTCHA score to render before screenshot (#374)
networkidle raced the async scoring and the dead button-click never ran.
Wait on the rendered result instead. Verified 4/4 in Docker.
2026-06-15 17:58:50 +02:00
CloakHQ b06499b0c1 test(humanize): deterministic timing for password CDP test
Zero typing_delay so the '!'-uses-CDP assertion no longer races the
5s default timeout under random thinking-pauses + CI load. Test only
checks which chars route through CDP, not timing.
2026-06-09 17:38:09 +02:00
KumarioandGitHub a6b1363244 fix(cloakserve): add idle cleanup for seeded profiles (#352)
* fix(cloakserve): add idle cleanup for seeded profiles

* docs(cloakserve): document idle process cleanup
2026-06-09 17:22:33 +02:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
b4a4ad21ab chore(deps): bump the actions group across 1 directory with 2 updates (#358)
Bumps the actions group with 2 updates in the / directory: [actions/checkout](https://github.com/actions/checkout) and [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action).


Updates `actions/checkout` from 6.0.2 to 6.0.3
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd...df4cb1c069e1874edd31b4311f1884172cec0e10)

Updates `docker/setup-qemu-action` from 4.0.0 to 4.1.0
- [Release notes](https://github.com/docker/setup-qemu-action/releases)
- [Commits](https://github.com/docker/setup-qemu-action/compare/ce360397dd3f832beb865e1373c09c0e9f86d70a...06116385d9baf250c9f4dcb4858b16962ea869c3)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: docker/setup-qemu-action
  dependency-version: 4.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-09 16:53:44 +02:00
CloakHQ dcf9ba55d6 feat(widevine): auto-seed CDM hint file for persistent contexts (Linux)
Sideloaded Widevine works on the first launch of a persistent context
instead of needing a manual two-launch hint-file workaround. The wrapper
writes Chromium's CDM hint file into the profile before launch when a
WidevineCdm directory is present next to the binary.

- New cloakbrowser/widevine.py and js/src/widevine.ts: resolve a sideloaded
  CDM (CLOAKBROWSER_WIDEVINE_CDM env var, else next to the binary) and seed
  the hint file. Linux only; no-op elsewhere. CLOAKBROWSER_WIDEVINE=0 disables.
- Never bundles/downloads/copies the CDM (proprietary); seeds only when the
  user-provided CDM is already present.
- Wired into launch_persistent_context[_async] and launchPersistentContext.
- README + js/README: Widevine / DRM section, env vars, FPJS tradeoff note.
- Tests: tests/test_widevine.py, js/tests/widevine.test.ts, persistent-context
  integration assertions.
2026-05-29 22:59:59 +02:00
14ec2ebf5f fix: rewrite cloakserve CDP WebSocket URLs (#234)
* fix: rewrite cloakserve CDP WebSocket URLs

* fix: guard against blank forwarded host

---------

Co-authored-by: honor2030 <19909783+honor2030@users.noreply.github.com>
2026-05-26 23:13:10 +02:00
22 changed files with 1095 additions and 33 deletions
+2 -2
View File
@@ -10,7 +10,7 @@ jobs:
python:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
with:
python-version: "3.12"
@@ -22,7 +22,7 @@ jobs:
javascript:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: 20
+6 -6
View File
@@ -24,7 +24,7 @@ jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
with:
python-version: "3.12"
@@ -42,7 +42,7 @@ jobs:
if: startsWith(github.ref, 'refs/tags/')
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
with:
python-version: "3.12"
@@ -62,7 +62,7 @@ jobs:
permissions:
id-token: write # OIDC trusted publishing — no PYPI_TOKEN needed
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
with:
python-version: "3.12"
@@ -80,7 +80,7 @@ jobs:
permissions:
id-token: write # OIDC trusted publishing + provenance — no NPM_TOKEN needed
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: 24 # npm 11.11.0 native — no upgrade needed (Node 22.22.2 has broken npm)
@@ -100,12 +100,12 @@ jobs:
attestations: write
packages: write
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- name: Extract version
run: |
VERSION=$(python -c 'import re; print(re.search(r"__version__\s*=\s*[\"'\'']([^\"'\'']+)", open("cloakbrowser/_version.py").read()).group(1))')
echo "VERSION=$VERSION" >> $GITHUB_ENV
- uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4.0.0
- uses: docker/setup-qemu-action@06116385d9baf250c9f4dcb4858b16962ea869c3 # v4.1.0
- uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4.1.0
- uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0
with:
+9
View File
@@ -8,6 +8,15 @@ Changes are tagged: **[wrapper]** for Python/JS wrapper, **[binary]** for Chromi
## [Unreleased]
## [0.3.32] — 2026-06-20
- **[wrapper]** **Security**: Windows binary extraction — pass archive/destination paths to PowerShell via env vars instead of interpolating into the `-Command` string, closing a code-injection shape on paths containing single quotes (e.g. `C:\Users\O'Brien`)
- **[wrapper]** Widevine: auto-seed CDM hint file for persistent contexts on Linux, so DRM playback works without manual pre-seeding
- **[wrapper]** `cloakserve`: rewrite CDP WebSocket URLs so clients connect through the proxy correctly (thanks [@honor2030](https://github.com/honor2030), #234)
- **[wrapper]** `cloakserve`: add idle cleanup for seeded profiles (thanks [@Kumario1](https://github.com/Kumario1), #352)
- **[meta]** Fix `recaptcha_score.py` example — wait for the reCAPTCHA score to render before screenshot (thanks [@igo](https://github.com/igo) for the report, #374)
- **[meta]** Bump GitHub Actions in the actions group (#358)
## [0.3.31] — 2026-05-26
- **[wrapper]** Route HTTP proxy credentials through `--proxy-server` flag, removing the need for Playwright's proxy auth handler on HTTP proxies
+56 -4
View File
@@ -150,7 +150,7 @@ Open [http://localhost:8080](http://localhost:8080). Create a profile. Click **L
---
## Latest: v0.3.31 (Chromium 146.0.7680.177.5)
## Latest: v0.3.32 (Chromium 146.0.7680.177.5)
- **58 fingerprint patches** — rendering consistency improvements across Linux and Windows, corrected GPU/display/graphics parameters to match stock Chrome 146 profiles
- **Windows native GPU passthrough** — real hardware values pass through directly instead of being spoofed, matching real browser behavior
@@ -383,6 +383,7 @@ Use this when you need to:
- **Bypass incognito detection** (some sites flag empty, ephemeral profiles)
- **Load Chrome extensions** (extensions only work from a real user data dir)
- **Build natural browsing history** (cached fonts, service workers, IndexedDB accumulate over time, making the profile look more realistic)
- **Play DRM-protected video** (Widevine) — with a sideloaded CDM, the wrapper enables Widevine on the first launch (see [Widevine / DRM](#widevine--drm))
```python
from cloakbrowser import launch_persistent_context
@@ -419,6 +420,26 @@ ctx = launch_persistent_context("./my-profile", args=["--fingerprint-storage-quo
| Default (auto, ~500MB) | PASS | -10 (flagged as incognito) |
| `--fingerprint-storage-quota=5000` | May trigger detection | PASS (appears non-incognito) |
### Widevine / DRM
The binary is built with Widevine support, but the Widevine CDM is a proprietary Google component we can't redistribute. Sideload it once by copying a `WidevineCdm/` directory from a real Chrome install next to the binary (full steps in [#96](https://github.com/CloakHQ/CloakBrowser/issues/96)):
```bash
cp -r /opt/google/chrome/WidevineCdm ~/.cloakbrowser/chromium-<version>/WidevineCdm
```
With the CDM in place, `launch_persistent_context()` enables Widevine **on the first launch** — the wrapper auto-writes the CDM hint file into the profile, so you don't need the manual two-launch workaround. This lets you play DRM-protected video (e.g. Netflix, Spotify Web) and makes a persistent profile present as a regular Chrome install to detection services that probe for DRM/EME support as a real-browser signal.
```python
from cloakbrowser import launch_persistent_context
# WidevineCdm sideloaded next to the binary -> Widevine works on first launch
ctx = launch_persistent_context("./my-profile", headless=False)
```
- **Linux only.** Chromium's hint-file mechanism is Linux/ChromeOS-specific. On Windows the CDM can't initialise (DRM host verification) and macOS uses a different layout, so seeding is a no-op there.
- **Auto by presence.** No flag needed — a sideloaded CDM is the opt-in. Point at a CDM in a non-default location with `CLOAKBROWSER_WIDEVINE_CDM=/path/to/WidevineCdm`, or disable seeding entirely with `CLOAKBROWSER_WIDEVINE=0`.
### CLI
Pre-download the binary or check installation status from the command line:
@@ -602,6 +623,8 @@ Access the original un-patched Playwright page at `page._original` if you need r
| `CLOAKBROWSER_AUTO_UPDATE` | `true` | Set to `false` to disable background update checks |
| `CLOAKBROWSER_SKIP_CHECKSUM` | `false` | Set to `true` to skip SHA-256 verification after download |
| `CLOAKBROWSER_GEOIP_TIMEOUT_SECONDS` | `5` | Max seconds for GeoIP resolution before continuing without it |
| `CLOAKBROWSER_WIDEVINE_CDM` | — | Path to a sideloaded `WidevineCdm` directory (overrides auto-detection next to the binary). See [Widevine / DRM](#widevine--drm) |
| `CLOAKBROWSER_WIDEVINE` | `1` | Set to `0` to disable automatic Widevine hint-file seeding for persistent contexts |
## Fingerprint Management
@@ -839,6 +862,26 @@ print(page.title())
browser.close()
```
If your framework needs a direct WebSocket endpoint, fetch Chrome's discovery document and use the rewritten `webSocketDebuggerUrl`. The URL points back through `cloakserve` so the CDP proxy can keep per-seed routing intact:
```bash
curl http://localhost:9222/json/version | jq -r .webSocketDebuggerUrl
# ws://localhost:9222/devtools/browser/<browser-id>
curl 'http://localhost:9222/json/version?fingerprint=11111' | jq -r .webSocketDebuggerUrl
# ws://localhost:9222/fingerprint/11111/devtools/browser/<browser-id>
```
When `cloakserve` runs behind a reverse proxy or TLS terminator, forward the public host/protocol headers so generated WebSocket URLs use the address clients can actually reach:
```nginx
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Host $host;
proxy_set_header X-Forwarded-Proto $scheme;
```
With those headers, `/json/version` returns public endpoints such as `wss://cdp.example.com/fingerprint/11111/devtools/browser/<browser-id>` instead of an internal container host.
Pass extra flags to the browser:
```bash
@@ -849,6 +892,10 @@ docker run -d --name cloak -p 127.0.0.1:9222:9222 cloakhq/cloakbrowser \
# Headed mode (renders to Xvfb inside container)
docker run -d --name cloak -p 127.0.0.1:9222:9222 cloakhq/cloakbrowser \
cloakserve --headless=false
# Reap disconnected per-seed browser processes after 5 minutes
docker run -d --name cloak -p 127.0.0.1:9222:9222 cloakhq/cloakbrowser \
cloakserve --idle-timeout=300
```
Stop the server:
@@ -900,7 +947,9 @@ b4 = pw.chromium.connect_over_cdp(
)
```
Supported query params: `fingerprint`, `timezone`, `locale`, `platform`, `platform-version`, `brand`, `brand-version`, `gpu-vendor`, `gpu-renderer`, `hardware-concurrency`, `device-memory`, `screen-width`, `screen-height`, `proxy`, `geoip`. Same seed reuses the same process (first connection's params win). No seed = shared default process (backward compatible). Check active processes at `GET /` (returns JSON with PIDs, ports, and connection counts).
Supported query params: `fingerprint`, `timezone`, `locale`, `platform`, `platform-version`, `brand`, `brand-version`, `gpu-vendor`, `gpu-renderer`, `hardware-concurrency`, `device-memory`, `screen-width`, `screen-height`, `proxy`, `geoip`. Same seed reuses the same process (first connection's params win). No seed = shared default process (backward compatible).
By default, per-seed processes stay alive until `cloakserve` exits. If clients create many unique seeds, set `--idle-timeout=SECONDS` or `CLOAKSERVE_IDLE_TIMEOUT=SECONDS` to automatically terminate a seed's Chrome process after its last CDP WebSocket disconnects. `0`, `off`, `false`, `none`, or `disabled` disable idle cleanup. When cleanup runs, the seed's temporary profile directory under `--data-dir` is removed too. Check active processes at `GET /` (returns JSON with PIDs, ports, connection counts, idle timeout, and pending cleanup status).
**Persistent profiles** — mount a volume to keep cookies and sessions across container restarts:
@@ -1049,7 +1098,9 @@ const browser = await launch({
For persistent contexts (`launch_persistent_context` / `launchPersistentContext`), also add `--fingerprint-storage-quota=500` to the args.
**Storage quota tradeoff:** The binary normalizes storage quota to ~500MB to pass FPJS, but this makes the session look like incognito to other detection services (e.g. BrowserScan's `notPrivate` check, -10 points). Setting `--fingerprint-storage-quota=5000` passes incognito checks but may trigger FPJS. You can't satisfy both simultaneously — choose based on what your target site checks. See the [storage quota tradeoff table](#launch_persistent_context) for details.
**Storage quota tradeoff:** The binary normalizes storage quota to ~500MB to pass FPJS, but this makes the session look like incognito to other detection services (e.g. BrowserScan's `notPrivate` check, -10 points). Setting `--fingerprint-storage-quota=5000` passes incognito checks but may trigger FPJS. With quota alone you can't satisfy both — choose based on what your target site checks. See the [storage quota tradeoff table](#launch_persistent_context) for details.
**Resolving the tradeoff (Linux):** Sideloading the Widevine CDM lets a persistent context pass FPJS at a higher quota, so you can satisfy both at once. See [Widevine / DRM](#widevine--drm).
---
@@ -1278,6 +1329,7 @@ Issues and PRs welcome. If something isn't working, [open an issue](https://gith
- [@aaronjmars](https://github.com/aaronjmars) — security fixes (shell injection, dep bumps)
- [@Seryiza](https://github.com/Seryiza) — Nix/NixOS flake
- [@245678000000](https://github.com/245678000000) — package-lock sync
- [@honor2030](https://github.com/honor2030) — cloakserve WebSocket origin guard, composable JS launch helpers
- [@honor2030](https://github.com/honor2030) — cloakserve WebSocket origin guard, CDP WebSocket URL rewrite, composable JS launch helpers
- [@sparanoid](https://github.com/sparanoid) — Docker Xvfb lock cleanup
- [@Kumario1](https://github.com/Kumario1) — cloakserve idle cleanup for seeded profiles
- [@0xlally](https://github.com/0xlally) — security reports (cloakserve path traversal, WebSocket origin bypass)
+97 -2
View File
@@ -181,6 +181,7 @@ class ChromePool:
default_seed: str | None = None,
default_locale: str | None = None,
default_timezone: str | None = None,
idle_timeout: float = 0.0,
):
self._binary = binary
self._global_args = global_args
@@ -189,12 +190,14 @@ class ChromePool:
self._default_seed = default_seed
self._default_locale = default_locale
self._default_timezone = default_timezone
self._idle_timeout = idle_timeout
self._processes: dict[str, ChromeProcess] = {}
self._default: ChromeProcess | None = None
self._locks: dict[str, asyncio.Lock] = {}
self._next_port = BASE_CDP_PORT
# Connection refcounting for status reporting
self._connections: dict[str, int] = {}
self._idle_tasks: dict[str, asyncio.Task] = {}
def _get_lock(self, seed: str) -> asyncio.Lock:
if seed not in self._locks:
@@ -224,6 +227,7 @@ class ChromePool:
def connect(self, seed_key: str) -> None:
"""Increment connection refcount for a seed."""
self._cancel_idle_cleanup(seed_key)
self._connections[seed_key] = self._connections.get(seed_key, 0) + 1
def disconnect(self, seed_key: str) -> None:
@@ -231,9 +235,54 @@ class ChromePool:
count = self._connections.get(seed_key, 0) - 1
if count <= 0:
self._connections.pop(seed_key, None)
self._schedule_idle_cleanup(seed_key)
else:
self._connections[seed_key] = count
def _cancel_idle_cleanup(self, seed_key: str) -> None:
task = self._idle_tasks.pop(seed_key, None)
if task is None or task.done():
return
try:
current_task = asyncio.current_task()
except RuntimeError:
current_task = None
if task is not current_task:
task.cancel()
def _discard_idle_task(self, seed_key: str, task: asyncio.Task) -> None:
if self._idle_tasks.get(seed_key) is task:
self._idle_tasks.pop(seed_key, None)
def _schedule_idle_cleanup(self, seed_key: str) -> None:
if self._idle_timeout <= 0 or seed_key not in self._processes:
return
self._cancel_idle_cleanup(seed_key)
try:
loop = asyncio.get_running_loop()
except RuntimeError:
return
task = loop.create_task(
self._cleanup_after_idle(seed_key, self._idle_timeout),
name=f"cloakserve-idle-cleanup-{seed_key}",
)
self._idle_tasks[seed_key] = task
task.add_done_callback(lambda done_task: self._discard_idle_task(seed_key, done_task))
async def _cleanup_after_idle(self, seed_key: str, timeout: float) -> None:
try:
await asyncio.sleep(timeout)
if self._connections.get(seed_key, 0) > 0 or seed_key not in self._processes:
return
logger.info("Cleaning up idle Chrome process (seed=%s)", seed_key)
await self._cleanup_process(seed_key)
except asyncio.CancelledError:
raise
except Exception:
logger.exception("Idle cleanup failed for seed=%s", seed_key)
async def get_or_launch(
self,
seed: str | None,
@@ -271,6 +320,8 @@ class ChromePool:
if seed_key in self._processes:
proc = self._processes[seed_key]
if proc.process.poll() is None:
if seed_key in self._idle_tasks:
self._schedule_idle_cleanup(seed_key)
if any([extra_args, timezone, locale, proxy, geoip]):
logger.warning(
"Seed %s already running (port %d, tz=%s, locale=%s, proxy=%s) — "
@@ -360,6 +411,7 @@ class ChromePool:
async def _cleanup_process(self, key: str) -> None:
"""Terminate a Chrome process and clean up."""
self._cancel_idle_cleanup(key)
proc = self._processes.pop(key, None)
if not proc:
return
@@ -377,6 +429,13 @@ class ChromePool:
async def shutdown(self) -> None:
"""Terminate all Chrome processes."""
idle_tasks = list(self._idle_tasks.values())
self._idle_tasks.clear()
for task in idle_tasks:
if not task.done():
task.cancel()
if idle_tasks:
await asyncio.gather(*idle_tasks, return_exceptions=True)
for key in list(self._processes.keys()):
await self._cleanup_process(key)
logger.info("All Chrome processes terminated")
@@ -453,9 +512,21 @@ def parse_connection_params(query_string: str) -> dict:
def _ws_scheme(request: web.Request) -> str:
"""Return 'wss' if client connected via HTTPS (e.g. TLS-terminating proxy), else 'ws'."""
proto = request.headers.get("X-Forwarded-Proto", request.scheme)
proto = proto.split(",", 1)[0].strip().lower()
return "wss" if proto == "https" else "ws"
def _external_host(request: web.Request) -> str:
"""Return the public host to use in rewritten CDP WebSocket URLs."""
fallback_host = request.headers.get("Host") or f"localhost:{request.app['port']}"
forwarded_host = request.headers.get("X-Forwarded-Host")
if forwarded_host:
public_host = forwarded_host.split(",", 1)[0].strip()
if public_host:
return public_host
return fallback_host
async def handle_root(request: web.Request) -> web.Response:
"""Health check / process status."""
pool: ChromePool = request.app["pool"]
@@ -467,6 +538,7 @@ async def handle_root(request: web.Request) -> web.Response:
"port": proc.cdp_port,
"seed": proc.seed,
"connections": pool._connections.get(key, 0),
"idle_cleanup_pending": key in pool._idle_tasks,
"timezone": proc.timezone,
"locale": proc.locale,
"proxy": proc.proxy,
@@ -474,6 +546,7 @@ async def handle_root(request: web.Request) -> web.Response:
return web.json_response({
"status": "ok",
"active": len(processes),
"idle_timeout": pool._idle_timeout,
"processes": processes,
})
@@ -504,7 +577,7 @@ async def handle_json_version(request: web.Request) -> web.Response:
return web.json_response({"error": "CDP endpoint unreachable"}, status=502)
# Rewrite webSocketDebuggerUrl to route through our multiplexer
host = request.headers.get("Host", f"localhost:{request.app['port']}")
host = _external_host(request)
seed_key = params["seed"]
if seed_key:
ws_path = f"fingerprint/{seed_key}/devtools/browser"
@@ -545,7 +618,7 @@ async def handle_json_list(request: web.Request) -> web.Response:
logger.error("Failed to reach Chrome CDP (port %d): %s", cp.cdp_port, exc)
return web.json_response({"error": "CDP endpoint unreachable"}, status=502)
host = request.headers.get("Host", f"localhost:{request.app['port']}")
host = _external_host(request)
scheme = _ws_scheme(request)
seed_key = params["seed"]
@@ -675,6 +748,23 @@ def _default_data_dir() -> str:
return str(Path.home() / ".cloakbrowser" / "cloakserve")
def _parse_idle_timeout(value: str) -> float:
value = value.strip()
if value.lower() in {"0", "false", "off", "none", "disabled"}:
return 0.0
timeout = float(value)
if timeout < 0:
raise ValueError("--idle-timeout must be greater than or equal to 0")
return timeout
def _default_idle_timeout() -> float:
value = os.environ.get("CLOAKSERVE_IDLE_TIMEOUT")
if value is None:
return 0.0
return _parse_idle_timeout(value)
def parse_cli_args(argv: list[str]) -> tuple[dict, list[str]]:
"""Parse cloakserve-specific args, return (config, passthrough_args).
@@ -690,12 +780,14 @@ def parse_cli_args(argv: list[str]) -> tuple[dict, list[str]]:
"default_seed": None,
"default_locale": None,
"default_timezone": None,
"idle_timeout": _default_idle_timeout(),
}
passthrough = []
# Flags consumed by cloakserve (not passed to Chrome)
consumed_prefixes = (
"--port=",
"--data-dir=",
"--idle-timeout=",
"--remote-debugging-port=",
"--remote-debugging-address=",
)
@@ -705,6 +797,8 @@ def parse_cli_args(argv: list[str]) -> tuple[dict, list[str]]:
config["port"] = int(arg.split("=", 1)[1])
elif arg.startswith("--data-dir="):
config["data_dir"] = arg.split("=", 1)[1]
elif arg.startswith("--idle-timeout="):
config["idle_timeout"] = _parse_idle_timeout(arg.split("=", 1)[1])
elif arg == "--headless=false" or arg == "--headless=False":
config["headless"] = False
passthrough.append(arg)
@@ -749,6 +843,7 @@ def main() -> None:
default_seed=config["default_seed"],
default_locale=config["default_locale"],
default_timezone=config["default_timezone"],
idle_timeout=config["idle_timeout"],
)
app = web.Application()
+1 -1
View File
@@ -1 +1 @@
__version__ = "0.3.31"
__version__ = "0.3.32"
+5
View File
@@ -22,6 +22,7 @@ from urllib.parse import quote, unquote, urlparse, urlunparse
from .config import DEFAULT_VIEWPORT, IGNORE_DEFAULT_ARGS, get_default_stealth_args
from .download import ensure_binary
from .human.config import HumanConfigOverrides, HumanPreset
from .widevine import seed_widevine_hint
logger = logging.getLogger("cloakbrowser")
@@ -336,6 +337,8 @@ def launch_persistent_context(
context_kwargs["color_scheme"] = color_scheme
context_kwargs.update(kwargs)
seed_widevine_hint(user_data_dir, binary_path)
pw = sync_playwright().start()
context = pw.chromium.launch_persistent_context(
user_data_dir=os.fspath(user_data_dir),
@@ -464,6 +467,8 @@ async def launch_persistent_context_async(
context_kwargs["color_scheme"] = color_scheme
context_kwargs.update(kwargs)
seed_widevine_hint(user_data_dir, binary_path)
pw = await async_playwright().start()
context = await pw.chromium.launch_persistent_context(
user_data_dir=os.fspath(user_data_dir),
+112
View File
@@ -0,0 +1,112 @@
"""Widevine CDM hint-file seeding for persistent contexts.
CloakBrowser's binary is built with Widevine support but ships no CDM (the CDM
is a proprietary Google binary we can't redistribute). Users sideload it by
copying a ``WidevineCdm/`` directory from a real Chrome install next to the
binary (see issue #96).
Chromium discovers a sideloaded CDM in two phases: an early-startup pass that
reads a "hint file" from the user-data-dir, and a later async component-updater
pass that writes that hint file. On a fresh profile the hint file doesn't exist
on the first launch, and Playwright passes ``--disable-component-update``, so the
updater never writes it Widevine only works after a manual two-launch dance.
This module pre-seeds the hint file before launch so a sideloaded CDM works on
the very first launch. It never bundles, downloads, or copies the CDM itself
it only writes the hint when a CDM the user provided is already present.
Linux only: Chromium's hint-file mechanism is Linux/ChromeOS-specific. On Windows
the CDM can't initialise (DRM host verification), and macOS uses a different CDM
layout, so seeding is a no-op there.
"""
from __future__ import annotations
import json
import logging
import os
import platform
from pathlib import Path
logger = logging.getLogger("cloakbrowser")
# Chromium reads this file from <user-data-dir>/WidevineCdm/ at early startup.
_HINT_FILENAME = "latest-component-updated-widevine-cdm"
def _seeding_disabled() -> bool:
"""True if CLOAKBROWSER_WIDEVINE is set to a falsey value (kill switch)."""
val = os.environ.get("CLOAKBROWSER_WIDEVINE", "").strip().lower()
return val in ("0", "false", "off", "no")
def resolve_widevine_cdm_dir(binary_path: str | os.PathLike) -> Path | None:
"""Locate a sideloaded Widevine CDM directory, or None if absent.
Resolution:
- If CLOAKBROWSER_WIDEVINE_CDM is set, it is used **exclusively** (overrides
auto-detection). An invalid value (no ``manifest.json``) skips seeding.
- Otherwise, ``<dir of the chrome binary>/WidevineCdm`` where a user
naturally drops it, and where it ends up for both downloaded and
CLOAKBROWSER_BINARY_PATH (local build / Docker mount) binaries.
A directory counts only if it contains ``manifest.json`` (so we don't seed a
hint pointing at a bogus path). The returned path is absolute and
symlink-resolved (``Path.resolve()``).
"""
custom = os.environ.get("CLOAKBROWSER_WIDEVINE_CDM")
# `is not None` (not truthiness): a present-but-empty env var is "set" and
# used exclusively — it resolves to an invalid path and skips seeding.
cdm_dir = Path(custom) if custom is not None else Path(os.fspath(binary_path)).parent / "WidevineCdm"
return cdm_dir.resolve() if (cdm_dir / "manifest.json").is_file() else None
def seed_widevine_hint(user_data_dir: str | os.PathLike, binary_path: str | os.PathLike) -> None:
"""Write the Widevine CDM hint file into a persistent profile before launch.
``binary_path`` is the resolved chrome executable; the CDM is looked for next
to it. No-op on non-Linux platforms, when seeding is disabled via
CLOAKBROWSER_WIDEVINE, or when no sideloaded CDM is present. Never raises
a failure here must not break the browser launch.
"""
if platform.system() != "Linux":
return
if _seeding_disabled():
logger.debug("Widevine hint seeding disabled via CLOAKBROWSER_WIDEVINE")
return
if not user_data_dir:
# Empty user_data_dir = Playwright's ephemeral profile (its own temp dir);
# a persistent hint can't be placed there, and "" would pollute the CWD.
return
# Everything below is best-effort and must never break the browser launch,
# so the whole body (resolution + write) is guarded.
try:
cdm_dir = resolve_widevine_cdm_dir(binary_path)
if cdm_dir is None:
if os.environ.get("CLOAKBROWSER_WIDEVINE_CDM") is not None:
logger.warning(
"CLOAKBROWSER_WIDEVINE_CDM is set but has no manifest.json; "
"skipping Widevine hint seeding"
)
else:
logger.debug("No sideloaded Widevine CDM found; skipping hint seeding")
return
hint_dir = Path(os.fspath(user_data_dir)) / "WidevineCdm"
hint_dir.mkdir(parents=True, exist_ok=True)
hint_file = hint_dir / _HINT_FILENAME
# cdm_dir is already absolute/resolved. Compact separators + ensure_ascii=False
# byte-match the JS wrapper's JSON.stringify (UTF-8) output.
content = json.dumps({"Path": str(cdm_dir)}, separators=(",", ":"), ensure_ascii=False)
try:
if hint_file.is_file() and hint_file.read_text(encoding="utf-8") == content:
return # already seeded correctly
except Exception:
logger.warning("Existing Widevine hint unreadable; rewriting")
hint_file.write_text(content, encoding="utf-8")
logger.info("Seeded Widevine CDM hint -> %s", cdm_dir)
except Exception as e:
logger.warning("Failed to seed Widevine CDM hint file: %s", e)
+12 -11
View File
@@ -5,7 +5,7 @@ Expected: 0.9 (human-level) with cloakbrowser.
Default Playwright typically scores 0.1-0.3.
"""
import time
import re
from cloakbrowser import launch
@@ -13,19 +13,20 @@ print("Launching stealth browser...", flush=True)
browser = launch(headless=True)
page = browser.new_page()
# Google's official reCAPTCHA v3 demo
# Google's official reCAPTCHA v3 demo — scores automatically on page load.
page.goto("https://recaptcha-demo.appspot.com/recaptcha-v3-request-scores.php")
page.wait_for_load_state("networkidle")
# Click to trigger reCAPTCHA scoring
button = page.query_selector("button")
if button:
button.click()
time.sleep(3)
# The score renders only after an async token + backend-verify round-trip,
# which can finish *after* "networkidle". Wait for the actual result text
# instead of a proxy signal, or the screenshot races the scoring.
page.wait_for_function(
"() => document.body.innerText.includes('Received response from our backend')",
timeout=20000,
)
# Extract score from page
content = page.content()
print("Page loaded. Check the score in the response.")
# Extract score from the rendered response
match = re.search(r'"score":\s*([0-9.]+)', page.inner_text("body"))
print(f"reCAPTCHA v3 score: {match.group(1) if match else 'not found'}")
print(f"URL: {page.url}")
# Take screenshot as proof
+12
View File
@@ -202,6 +202,18 @@ if (newVersion) console.log(`Updated to ${newVersion}`);
| `CLOAKBROWSER_DOWNLOAD_URL` | `cloakbrowser.dev` | Custom download URL |
| `CLOAKBROWSER_AUTO_UPDATE` | `true` | Set to `false` to disable background update checks |
| `CLOAKBROWSER_SKIP_CHECKSUM` | `false` | Set to `true` to skip SHA-256 verification after download |
| `CLOAKBROWSER_WIDEVINE_CDM` | — | Path to a sideloaded `WidevineCdm` directory (overrides auto-detection next to the binary) |
| `CLOAKBROWSER_WIDEVINE` | `1` | Set to `0` to disable automatic Widevine hint-file seeding for persistent contexts |
### Widevine / DRM
The binary supports Widevine, but the CDM is proprietary and can't be redistributed. Sideload it once by copying a `WidevineCdm/` directory from a real Chrome install next to the binary (full steps in [#96](https://github.com/CloakHQ/CloakBrowser/issues/96)):
```bash
cp -r /opt/google/chrome/WidevineCdm ~/.cloakbrowser/chromium-<version>/WidevineCdm
```
With the CDM in place, `launchPersistentContext()` enables Widevine on the **first** launch — the wrapper auto-seeds the CDM hint file into the profile. This plays DRM-protected video (Netflix, Spotify Web) and makes a persistent profile present as a regular Chrome install to detection services that probe for DRM/EME support. **Linux only.** A sideloaded CDM is the opt-in (no flag); set `CLOAKBROWSER_WIDEVINE_CDM` for a custom path or `CLOAKBROWSER_WIDEVINE=0` to disable. See the [main README](https://github.com/CloakHQ/CloakBrowser#widevine--drm) for details.
## Migrate From Playwright
+2 -2
View File
@@ -1,12 +1,12 @@
{
"name": "cloakbrowser",
"version": "0.3.31",
"version": "0.3.32",
"lockfileVersion": 3,
"requires": true,
"packages": {
"": {
"name": "cloakbrowser",
"version": "0.3.31",
"version": "0.3.32",
"license": "MIT",
"dependencies": {
"tar": "^7.0.0"
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "cloakbrowser",
"version": "0.3.31",
"version": "0.3.32",
"description": "Stealth Chromium that passes every bot detection test. Drop-in Playwright/Puppeteer replacement with source-level fingerprint patches.",
"type": "module",
"main": "dist/index.js",
+7 -2
View File
@@ -425,11 +425,16 @@ async function extractZip(archivePath: string, destDir: string): Promise<void> {
if (process.platform === "win32") {
// PowerShell 5.1's Expand-Archive uses .NET FileStream which can conflict
// with recently-closed Node.js file handles. Use ZipFile API directly.
// Pass paths via env vars (not interpolated into the script) so a quote or
// other special char in the path can't break out and be parsed as code.
execFileSync("powershell", [
"-NoProfile", "-Command",
`Add-Type -AssemblyName System.IO.Compression.FileSystem; ` +
`[System.IO.Compression.ZipFile]::ExtractToDirectory('${archivePath}', '${destDir}')`,
], { timeout: 120_000 });
`[System.IO.Compression.ZipFile]::ExtractToDirectory($env:CB_ARCHIVE, $env:CB_DEST)`,
], {
timeout: 120_000,
env: { ...process.env, CB_ARCHIVE: archivePath, CB_DEST: destDir },
});
} else {
execFileSync("unzip", ["-o", archivePath, "-d", destDir], { timeout: 120_000 });
}
+3
View File
@@ -10,6 +10,7 @@ import { buildArgs } from "./args.js";
import { ensureBinary } from "./download.js";
import { resolveProxyConfig } from "./proxy.js";
import { maybeResolveGeoip, resolveWebrtcArgs } from "./geoip.js";
import { seedWidevineHint } from "./widevine.js";
/** @internal Accept both timezone and timezoneId — either works, no warning. Exported for testing. */
export function resolveTimezone<T extends { timezone?: string; timezoneId?: string }>(options: T): T {
@@ -227,6 +228,8 @@ export async function launchPersistentContext(
}
const args = buildArgs({ ...options, ...resolved, args: [...(resolvedArgs ?? []), ...proxyArgs] });
seedWidevineHint(options.userDataDir, binaryPath);
// locale and timezone are set via binary flags (--lang, --fingerprint-timezone)
// — NOT via Playwright context kwargs which use detectable CDP emulation.
const context = await chromium.launchPersistentContext(options.userDataDir, {
+3
View File
@@ -11,6 +11,7 @@ import { buildArgs } from "./args.js";
import { ensureBinary } from "./download.js";
import { isSocksProxy, normalizeHttpStringUrl, parseProxyUrl, reconstructHttpUrl, resolveProxyConfig, supportsHttpProxyInlineAuth } from "./proxy.js";
import { maybeResolveGeoip, resolveWebrtcArgs } from "./geoip.js";
import { seedWidevineHint } from "./widevine.js";
/** Resolve binary path, geoip, webrtc, and build final Chrome args. */
async function resolveArgs(options: LaunchOptions): Promise<{ binaryPath: string; args: string[] }> {
@@ -155,6 +156,8 @@ export async function launchPersistentContext(
const { binaryPath, args } = await resolveArgs(options);
const proxyAuth = resolveProxy(options, args);
seedWidevineHint(options.userDataDir, binaryPath);
const browser = await puppeteer.default.launch({
...options.launchOptions,
executablePath: binaryPath,
+111
View File
@@ -0,0 +1,111 @@
/**
* Widevine CDM hint-file seeding for persistent contexts.
* Mirrors Python cloakbrowser/widevine.py.
*
* CloakBrowser's binary supports Widevine but ships no CDM (proprietary, can't
* redistribute). Users sideload it by copying a `WidevineCdm/` directory from a
* real Chrome install next to the binary (see issue #96). Chromium reads a
* "hint file" from the user-data-dir at early startup to register the CDM, but
* on a fresh profile it doesn't exist yet, and Playwright disables the component
* updater that would write it. This seeds the hint file before launch so a
* sideloaded CDM works on the first run. It never bundles, downloads, or copies
* the CDM only writes the hint when a user-provided CDM is already present.
*
* Linux only: Chromium's hint-file mechanism is Linux/ChromeOS-specific.
*/
import fs from "node:fs";
import path from "node:path";
const HINT_FILENAME = "latest-component-updated-widevine-cdm";
/** True if `file` exists and is a regular file (mirrors Python's Path.is_file()). */
function isFile(file: string): boolean {
try {
return fs.statSync(file).isFile();
} catch {
return false;
}
}
/** Absolute, symlink-resolved path (mirrors Python's Path.resolve()). */
function realPath(p: string): string {
try {
return fs.realpathSync(p);
} catch {
return path.resolve(p);
}
}
function seedingDisabled(): boolean {
const val = (process.env.CLOAKBROWSER_WIDEVINE ?? "").trim().toLowerCase();
return val === "0" || val === "false" || val === "off" || val === "no";
}
/**
* Locate a sideloaded Widevine CDM directory, or null if absent.
*
* Resolution:
* - If CLOAKBROWSER_WIDEVINE_CDM is set, it is used exclusively (overrides
* auto-detection). An invalid value (no `manifest.json`) skips seeding.
* - Otherwise, `<dir of the chrome binary>/WidevineCdm` where a user naturally
* drops it, and where it lives for both downloaded and CLOAKBROWSER_BINARY_PATH binaries.
*
* A directory counts only if it contains `manifest.json`. The returned path is
* absolute and symlink-resolved (mirrors Python's Path.resolve()).
* @internal Exported for testing.
*/
export function resolveWidevineCdmDir(binaryPath: string): string | null {
const custom = process.env.CLOAKBROWSER_WIDEVINE_CDM;
// `!== undefined` (not truthiness): a present-but-empty env var is "set" and
// used exclusively — it resolves to an invalid path and skips seeding.
const cdmDir = custom !== undefined ? custom : path.join(path.dirname(binaryPath), "WidevineCdm");
return isFile(path.join(cdmDir, "manifest.json")) ? realPath(cdmDir) : null;
}
/**
* Write the Widevine CDM hint file into a persistent profile before launch.
* `binaryPath` is the resolved chrome executable; the CDM is looked for next to
* it. No-op on non-Linux, when disabled via CLOAKBROWSER_WIDEVINE, or when no
* sideloaded CDM is present. Never throws a failure must not break launch.
*/
export function seedWidevineHint(userDataDir: string, binaryPath: string): void {
if (process.platform !== "linux") return;
if (seedingDisabled()) return;
// Empty userDataDir = Playwright's ephemeral profile (its own temp dir);
// a persistent hint can't be placed there, and "" would pollute the CWD.
if (!userDataDir) return;
// Everything below is best-effort and must never break the browser launch,
// so the whole body (resolution + write) is guarded.
try {
const cdmDir = resolveWidevineCdmDir(binaryPath);
if (cdmDir === null) {
if (process.env.CLOAKBROWSER_WIDEVINE_CDM !== undefined) {
console.warn(
"[cloakbrowser] CLOAKBROWSER_WIDEVINE_CDM is set but has no manifest.json; " +
"skipping Widevine hint seeding",
);
}
return;
}
const hintDir = path.join(userDataDir, "WidevineCdm");
fs.mkdirSync(hintDir, { recursive: true });
const hintFile = path.join(hintDir, HINT_FILENAME);
// cdmDir is already absolute/resolved.
const content = JSON.stringify({ Path: cdmDir });
try {
if (isFile(hintFile) && fs.readFileSync(hintFile, "utf-8") === content) {
return; // already seeded correctly
}
} catch {
console.warn("[cloakbrowser] Existing Widevine hint unreadable; rewriting");
}
fs.writeFileSync(hintFile, content);
} catch (e) {
// Best-effort: never break the launch, but surface the failure.
console.warn("[cloakbrowser] Failed to seed Widevine CDM hint file:", e);
}
}
+1 -1
View File
@@ -418,7 +418,7 @@ describe("humanType mixed text with CDP", () => {
});
it("password-like text 'SecurePass!123' uses CDP for '!'", async () => {
const cfg = resolveConfig("default", { mistype_chance: 0 });
const cfg = resolveConfig("default", { mistype_chance: 0, typing_delay: 0 });
const { raw } = buildRawKeyboard();
const page = buildMockPage();
const cdpCalls: Array<[string, any]> = [];
+57
View File
@@ -0,0 +1,57 @@
import { describe, it, expect, vi, afterEach, beforeEach } from "vitest";
// Assert the persistent-context launchers actually invoke seedWidevineHint,
// so accidental removal of the wiring fails CI (parity with the Python
// test_persistent_context_seeds_widevine tests).
vi.mock("../src/widevine.js", () => ({
seedWidevineHint: vi.fn(),
resolveWidevineCdmDir: vi.fn(),
}));
vi.mock("../src/download.js", () => ({
ensureBinary: vi.fn().mockResolvedValue("/fake/chrome"),
}));
vi.mock("../src/geoip.js", () => ({
resolveProxyGeo: vi.fn().mockResolvedValue({ timezone: null, locale: null }),
maybeResolveGeoip: vi.fn().mockResolvedValue({}),
resolveWebrtcArgs: vi.fn().mockImplementation((opts: any) => Promise.resolve(opts.args)),
}));
vi.mock("playwright-core", () => ({ chromium: { launchPersistentContext: vi.fn() } }));
vi.mock("puppeteer-core", () => ({ default: { launch: vi.fn() } }));
describe("persistent context seeds Widevine (integration)", () => {
beforeEach(() => {
delete process.env.CLOAKBROWSER_BINARY_PATH;
});
afterEach(() => {
vi.clearAllMocks();
});
it("Playwright launchPersistentContext seeds with (userDataDir, binaryPath)", async () => {
const pw = await import("playwright-core");
vi.mocked(pw.chromium.launchPersistentContext).mockResolvedValue({
close: vi.fn(),
pages: () => [],
} as any);
const { seedWidevineHint } = await import("../src/widevine.js");
const { launchPersistentContext } = await import("../src/playwright.js");
await launchPersistentContext({ userDataDir: "/tmp/profile" });
expect(seedWidevineHint).toHaveBeenCalledWith("/tmp/profile", "/fake/chrome");
});
it("Puppeteer launchPersistentContext seeds with (userDataDir, binaryPath)", async () => {
const pptr = await import("puppeteer-core");
vi.mocked(pptr.default.launch).mockResolvedValue({
newPage: vi.fn().mockResolvedValue({ authenticate: vi.fn() }),
close: vi.fn(),
} as any);
const { seedWidevineHint } = await import("../src/widevine.js");
const { launchPersistentContext } = await import("../src/puppeteer.js");
await launchPersistentContext({ userDataDir: "/tmp/profile" });
expect(seedWidevineHint).toHaveBeenCalledWith("/tmp/profile", "/fake/chrome");
});
});
+160
View File
@@ -0,0 +1,160 @@
import { describe, it, expect, afterEach, beforeEach, vi } from "vitest";
import fs from "node:fs";
import os from "node:os";
import path from "node:path";
import { resolveWidevineCdmDir, seedWidevineHint } from "../src/widevine.js";
const HINT = "WidevineCdm/latest-component-updated-widevine-cdm";
const tempDirs: string[] = [];
const origPlatform = process.platform;
function tmpDir(prefix: string): string {
const d = fs.mkdtempSync(path.join(os.tmpdir(), prefix));
tempDirs.push(d);
return d;
}
function makeCdm(dir: string): string {
fs.mkdirSync(dir, { recursive: true });
fs.writeFileSync(path.join(dir, "manifest.json"), '{"version":"4.10.3050.0"}');
return dir;
}
/** A fake chrome binary path inside its own dir. */
function fakeBinary(): string {
const bdir = path.join(tmpDir("cloak-bin-"), "bin");
fs.mkdirSync(bdir, { recursive: true });
return path.join(bdir, "chrome");
}
function setPlatform(value: string) {
Object.defineProperty(process, "platform", { value, configurable: true });
}
beforeEach(() => {
setPlatform("linux"); // seeding is Linux-only; default to Linux in tests
delete process.env.CLOAKBROWSER_WIDEVINE;
delete process.env.CLOAKBROWSER_WIDEVINE_CDM;
});
afterEach(() => {
vi.restoreAllMocks();
Object.defineProperty(process, "platform", { value: origPlatform, configurable: true });
delete process.env.CLOAKBROWSER_WIDEVINE;
delete process.env.CLOAKBROWSER_WIDEVINE_CDM;
for (const dir of tempDirs.splice(0)) fs.rmSync(dir, { recursive: true, force: true });
});
describe("resolveWidevineCdmDir", () => {
it("returns env-var dir when it has manifest.json", () => {
const cdm = makeCdm(path.join(tmpDir("cloak-wv-"), "WidevineCdm"));
process.env.CLOAKBROWSER_WIDEVINE_CDM = cdm;
expect(resolveWidevineCdmDir(fakeBinary())).toBe(fs.realpathSync(cdm));
});
it("returns null when dir lacks manifest.json", () => {
const bogus = path.join(tmpDir("cloak-wv-"), "WidevineCdm");
fs.mkdirSync(bogus, { recursive: true });
process.env.CLOAKBROWSER_WIDEVINE_CDM = bogus;
expect(resolveWidevineCdmDir(fakeBinary())).toBeNull();
});
it("falls back to <binary dir>/WidevineCdm", () => {
const binary = fakeBinary();
expect(resolveWidevineCdmDir(binary)).toBeNull(); // no CDM yet
const cdm = makeCdm(path.join(path.dirname(binary), "WidevineCdm"));
expect(resolveWidevineCdmDir(binary)).toBe(fs.realpathSync(cdm));
});
it("env var is exclusive — invalid env skips, no fallback to binary dir", () => {
const binary = fakeBinary();
makeCdm(path.join(path.dirname(binary), "WidevineCdm")); // valid CDM next to binary
const bogus = path.join(tmpDir("cloak-wv-"), "bogus");
fs.mkdirSync(bogus, { recursive: true }); // set but no manifest.json
process.env.CLOAKBROWSER_WIDEVINE_CDM = bogus;
expect(resolveWidevineCdmDir(binary)).toBeNull();
});
it("empty env var is exclusive — no fallback to binary dir", () => {
const binary = fakeBinary();
makeCdm(path.join(path.dirname(binary), "WidevineCdm")); // valid CDM next to binary
process.env.CLOAKBROWSER_WIDEVINE_CDM = ""; // set but empty
expect(resolveWidevineCdmDir(binary)).toBeNull();
});
});
describe("seedWidevineHint", () => {
it("writes the hint file with the absolute CDM path", () => {
const cdm = makeCdm(path.join(tmpDir("cloak-wv-"), "WidevineCdm"));
process.env.CLOAKBROWSER_WIDEVINE_CDM = cdm;
const profile = tmpDir("cloak-prof-");
seedWidevineHint(profile, fakeBinary());
const hint = path.join(profile, HINT);
expect(fs.existsSync(hint)).toBe(true);
expect(JSON.parse(fs.readFileSync(hint, "utf-8")).Path).toBe(fs.realpathSync(cdm));
});
it("no-ops when no CDM present", () => {
const profile = tmpDir("cloak-prof-");
seedWidevineHint(profile, fakeBinary());
expect(fs.existsSync(path.join(profile, HINT))).toBe(false);
});
it("kill switch CLOAKBROWSER_WIDEVINE=0 disables seeding", () => {
const cdm = makeCdm(path.join(tmpDir("cloak-wv-"), "WidevineCdm"));
process.env.CLOAKBROWSER_WIDEVINE_CDM = cdm;
process.env.CLOAKBROWSER_WIDEVINE = "0";
const profile = tmpDir("cloak-prof-");
seedWidevineHint(profile, fakeBinary());
expect(fs.existsSync(path.join(profile, HINT))).toBe(false);
});
it("is idempotent", () => {
const cdm = makeCdm(path.join(tmpDir("cloak-wv-"), "WidevineCdm"));
process.env.CLOAKBROWSER_WIDEVINE_CDM = cdm;
const profile = tmpDir("cloak-prof-");
seedWidevineHint(profile, fakeBinary());
seedWidevineHint(profile, fakeBinary());
expect(JSON.parse(fs.readFileSync(path.join(profile, HINT), "utf-8")).Path).toBe(
fs.realpathSync(cdm),
);
});
it("no-ops on non-Linux", () => {
setPlatform("win32");
const cdm = makeCdm(path.join(tmpDir("cloak-wv-"), "WidevineCdm"));
process.env.CLOAKBROWSER_WIDEVINE_CDM = cdm;
const profile = tmpDir("cloak-prof-");
seedWidevineHint(profile, fakeBinary());
expect(fs.existsSync(path.join(profile, HINT))).toBe(false);
});
it("skips empty userDataDir (no CWD pollution)", () => {
const cdm = makeCdm(path.join(tmpDir("cloak-wv-"), "WidevineCdm"));
process.env.CLOAKBROWSER_WIDEVINE_CDM = cdm;
seedWidevineHint("", fakeBinary());
expect(fs.existsSync(path.join(process.cwd(), "WidevineCdm"))).toBe(false);
});
it("never throws on write failure", () => {
const cdm = makeCdm(path.join(tmpDir("cloak-wv-"), "WidevineCdm"));
process.env.CLOAKBROWSER_WIDEVINE_CDM = cdm;
const profile = tmpDir("cloak-prof-");
// Block mkdir of <profile>/WidevineCdm by occupying that path with a file.
fs.writeFileSync(path.join(profile, "WidevineCdm"), "not a dir");
expect(() => seedWidevineHint(profile, fakeBinary())).not.toThrow();
});
it("rewrites a mismatched existing hint", () => {
const cdm = makeCdm(path.join(tmpDir("cloak-wv-"), "WidevineCdm"));
process.env.CLOAKBROWSER_WIDEVINE_CDM = cdm;
const profile = tmpDir("cloak-prof-");
const hint = path.join(profile, HINT);
fs.mkdirSync(path.dirname(hint), { recursive: true });
fs.writeFileSync(hint, '{"Path":"/stale/path"}');
seedWidevineHint(profile, fakeBinary());
expect(JSON.parse(fs.readFileSync(hint, "utf-8")).Path).toBe(fs.realpathSync(cdm));
});
});
+251 -1
View File
@@ -3,6 +3,7 @@
import asyncio
import importlib.machinery
import importlib.util
import json
import sys
from pathlib import Path
from types import SimpleNamespace
@@ -24,6 +25,8 @@ parse_connection_params = _mod.parse_connection_params
parse_cli_args = _mod.parse_cli_args
ChromePool = _mod.ChromePool
_default_data_dir = _mod._default_data_dir
_external_host = _mod._external_host
_ws_scheme = _mod._ws_scheme
SAFE_SEED_RE = _mod.SAFE_SEED_RE
RESERVED_SEEDS = _mod.RESERVED_SEEDS
@@ -90,6 +93,7 @@ class TestParseCliArgs:
assert config["port"] == 9222
assert config["headless"] is True
assert config["data_dir"] is not None
assert config["idle_timeout"] == 0.0
assert passthrough == []
def test_custom_port(self):
@@ -128,6 +132,31 @@ class TestParseCliArgs:
_, passthrough = parse_cli_args(["--data-dir=/tmp/test"])
assert not any(a.startswith("--data-dir=") for a in passthrough)
def test_idle_timeout_not_in_passthrough(self):
config, passthrough = parse_cli_args(["--idle-timeout=30", "--no-sandbox"])
assert config["idle_timeout"] == 30.0
assert "--idle-timeout=30" not in passthrough
assert "--no-sandbox" in passthrough
@pytest.mark.parametrize("value", ["0", "off", "false", "none", "disabled"])
def test_idle_timeout_disabled_values(self, value):
config, _ = parse_cli_args([f"--idle-timeout={value}"])
assert config["idle_timeout"] == 0.0
def test_idle_timeout_env_default(self, monkeypatch):
monkeypatch.setenv("CLOAKSERVE_IDLE_TIMEOUT", "2.5")
config, _ = parse_cli_args([])
assert config["idle_timeout"] == 2.5
def test_idle_timeout_cli_overrides_env(self, monkeypatch):
monkeypatch.setenv("CLOAKSERVE_IDLE_TIMEOUT", "2.5")
config, _ = parse_cli_args(["--idle-timeout=9"])
assert config["idle_timeout"] == 9.0
def test_idle_timeout_rejects_negative_values(self):
with pytest.raises(ValueError):
parse_cli_args(["--idle-timeout=-1"])
@patch("os.path.exists", return_value=True)
def test_default_data_dir_docker(self, _mock):
assert _default_data_dir() == "/tmp/cloakserve"
@@ -138,6 +167,141 @@ class TestParseCliArgs:
assert result.endswith(".cloakbrowser/cloakserve")
# ---------------------------------------------------------------------------
# External host detection
# ---------------------------------------------------------------------------
class TestExternalHost:
"""Test public host selection for rewritten CDP WebSocket URLs."""
class _Request:
def __init__(self, headers, port=9222, scheme="http", query_string=""):
self.headers = headers
self.app = {"port": port}
self.scheme = scheme
self.query_string = query_string
def test_forwarded_host_overrides_internal_host(self):
request = self._Request({
"Host": "localhost:8080",
"X-Forwarded-Host": "cdp.example.com:443",
})
assert _external_host(request) == "cdp.example.com:443"
def test_forwarded_host_uses_first_value(self):
request = self._Request({
"Host": "internal:9222",
"X-Forwarded-Host": "public.example.com, internal:9222",
})
assert _external_host(request) == "public.example.com"
def test_blank_forwarded_host_falls_back_to_host_header(self):
request = self._Request({
"Host": "internal:9222",
"X-Forwarded-Host": " ",
})
assert _external_host(request) == "internal:9222"
def test_falls_back_to_host_header(self):
request = self._Request({"Host": "localhost:9222"})
assert _external_host(request) == "localhost:9222"
def test_falls_back_to_app_port_without_host_header(self):
request = self._Request({}, port=9333)
assert _external_host(request) == "localhost:9333"
def test_forwarded_proto_selects_wss(self):
request = self._Request({"X-Forwarded-Proto": "https"}, scheme="http")
assert _ws_scheme(request) == "wss"
def test_forwarded_proto_uses_first_value(self):
request = self._Request({"X-Forwarded-Proto": "https, http"}, scheme="http")
assert _ws_scheme(request) == "wss"
class TestHandlerURLRewriting:
"""Verify handlers rewrite CDP WebSocket URLs to the public cloakserve endpoint."""
class _Request:
def __init__(self, headers, query_string="fingerprint=seed1", port=9222, scheme="http"):
self.headers = headers
self.query_string = query_string
self.scheme = scheme
self.app = {"port": port, "pool": self._Pool()}
class _Pool:
async def get_or_launch(self, **_kwargs):
return SimpleNamespace(cdp_port=5100)
class _FakeResponse:
def __init__(self, data):
self._data = data
async def __aenter__(self):
return self
async def __aexit__(self, *_exc):
return None
async def json(self):
return self._data
class _FakeSession:
def __init__(self, data):
self._data = data
async def __aenter__(self):
return self
async def __aexit__(self, *_exc):
return None
def get(self, *_args, **_kwargs):
return TestHandlerURLRewriting._FakeResponse(self._data)
def _patch_session(self, monkeypatch, data):
monkeypatch.setattr(
_mod.aiohttp,
"ClientSession",
lambda *_args, **_kwargs: self._FakeSession(data),
)
def test_json_version_uses_forwarded_host_and_proto(self, monkeypatch):
self._patch_session(monkeypatch, {
"webSocketDebuggerUrl": "ws://127.0.0.1:5100/devtools/browser/browser-guid",
})
request = self._Request({
"Host": "internal:9222",
"X-Forwarded-Host": "cdp.example.com",
"X-Forwarded-Proto": "https",
})
response = asyncio.run(_mod.handle_json_version(request))
payload = json.loads(response.text)
assert payload["webSocketDebuggerUrl"] == (
"wss://cdp.example.com/fingerprint/seed1/devtools/browser/browser-guid"
)
def test_json_list_uses_forwarded_host_and_proto(self, monkeypatch):
self._patch_session(monkeypatch, [{
"webSocketDebuggerUrl": "ws://127.0.0.1:5100/devtools/page/page-guid",
}])
request = self._Request({
"Host": "internal:9222",
"X-Forwarded-Host": "cdp.example.com",
"X-Forwarded-Proto": "https",
})
response = asyncio.run(_mod.handle_json_list(request))
payload = json.loads(response.text)
assert payload[0]["webSocketDebuggerUrl"] == (
"wss://cdp.example.com/fingerprint/seed1/devtools/page/page-guid"
)
# ---------------------------------------------------------------------------
# URL rewriting logic (pure string manipulation, extracted from handlers)
# ---------------------------------------------------------------------------
@@ -293,12 +457,21 @@ class TestHandlerURLRewriting:
class TestConnectionTracking:
"""Test ChromePool.connect() / disconnect() without real Chrome."""
def _make_pool(self):
def _make_pool(self, idle_timeout: float = 0.0):
return ChromePool(
binary="/fake/chrome",
global_args=[],
headless=True,
data_dir="/tmp/test-cloakserve",
idle_timeout=idle_timeout,
)
def _track_process(self, pool, seed="seed1"):
pool._processes[seed] = SimpleNamespace()
def _track_live_process(self, pool, seed="seed1"):
pool._processes[seed] = SimpleNamespace(
process=SimpleNamespace(poll=lambda: None),
)
def test_connect_increments(self):
@@ -335,6 +508,83 @@ class TestConnectionTracking:
assert pool._connections["a"] == 1
assert pool._connections["b"] == 1
def test_idle_cleanup_disabled_by_default(self):
async def run():
pool = self._make_pool()
self._track_process(pool)
pool.connect("seed1")
pool.disconnect("seed1")
await asyncio.sleep(0)
assert pool._idle_tasks == {}
asyncio.run(run())
def test_disconnect_to_zero_schedules_idle_cleanup(self):
async def run():
pool = self._make_pool(idle_timeout=0.01)
self._track_process(pool)
cleaned = []
async def fake_cleanup(seed):
cleaned.append(seed)
pool._processes.pop(seed, None)
pool._cleanup_process = fake_cleanup
pool.connect("seed1")
pool.disconnect("seed1")
assert "seed1" in pool._idle_tasks
await asyncio.sleep(0.05)
assert cleaned == ["seed1"]
assert "seed1" not in pool._idle_tasks
asyncio.run(run())
def test_reconnect_cancels_pending_idle_cleanup(self):
async def run():
pool = self._make_pool(idle_timeout=0.03)
self._track_process(pool)
cleaned = []
async def fake_cleanup(seed):
cleaned.append(seed)
pool._processes.pop(seed, None)
pool._cleanup_process = fake_cleanup
pool.connect("seed1")
pool.disconnect("seed1")
assert "seed1" in pool._idle_tasks
pool.connect("seed1")
await asyncio.sleep(0.06)
assert cleaned == []
assert pool._connections["seed1"] == 1
assert "seed1" not in pool._idle_tasks
asyncio.run(run())
def test_discovery_refreshes_pending_idle_cleanup(self):
async def run():
pool = self._make_pool(idle_timeout=1.0)
self._track_live_process(pool)
pool.connect("seed1")
pool.disconnect("seed1")
first_task = pool._idle_tasks["seed1"]
await pool.get_or_launch("seed1")
second_task = pool._idle_tasks["seed1"]
assert second_task is not first_task
pool._cancel_idle_cleanup("seed1")
await asyncio.sleep(0)
assert "seed1" not in pool._idle_tasks
asyncio.run(run())
# ---------------------------------------------------------------------------
# Seed validation (CVE fix — path traversal via fingerprint param)
+29
View File
@@ -258,3 +258,32 @@ async def test_persistent_context_async_timezone_id_alias(_mock_bin):
call_kwargs = pw.chromium.launch_persistent_context.call_args[1]
assert "--fingerprint-timezone=Europe/Paris" in call_kwargs["args"]
assert "timezone_id" not in call_kwargs
@patch("cloakbrowser.browser.ensure_binary", return_value="/fake/chrome")
@patch("cloakbrowser.browser.maybe_resolve_geoip", return_value=(None, None, None))
@patch("cloakbrowser.browser.seed_widevine_hint")
def test_persistent_context_seeds_widevine(_mock_seed, _mock_geoip, _mock_bin):
"""Sync persistent launch seeds the Widevine hint with the profile path."""
pw_cm, pw, context = _make_mock_pw_and_context()
with patch("playwright.sync_api.sync_playwright", return_value=pw_cm):
from cloakbrowser.browser import launch_persistent_context
launch_persistent_context("/tmp/profile")
_mock_seed.assert_called_once_with("/tmp/profile", "/fake/chrome")
@pytest.mark.asyncio
@patch("cloakbrowser.browser.ensure_binary", return_value="/fake/chrome")
@patch("cloakbrowser.browser.maybe_resolve_geoip", return_value=(None, None, None))
@patch("cloakbrowser.browser.seed_widevine_hint")
async def test_persistent_context_async_seeds_widevine(_mock_seed, _mock_geoip, _mock_bin):
"""Async persistent launch seeds the Widevine hint with the profile path."""
pw_cm, pw, context = _make_mock_async_pw_and_context()
with patch("playwright.async_api.async_playwright", return_value=pw_cm):
from cloakbrowser.browser import launch_persistent_context_async
await launch_persistent_context_async("/tmp/profile")
_mock_seed.assert_called_once_with("/tmp/profile", "/fake/chrome")
+158
View File
@@ -0,0 +1,158 @@
"""Unit tests for Widevine CDM hint-file seeding (cloakbrowser/widevine.py)."""
import json
import pytest
from cloakbrowser import widevine
from cloakbrowser.widevine import resolve_widevine_cdm_dir, seed_widevine_hint
_HINT = "WidevineCdm/latest-component-updated-widevine-cdm"
@pytest.fixture(autouse=True)
def _force_linux(monkeypatch):
"""Run as if on Linux unless a test overrides it (seeding is Linux-only)."""
monkeypatch.setattr(widevine.platform, "system", lambda: "Linux")
monkeypatch.delenv("CLOAKBROWSER_WIDEVINE", raising=False)
monkeypatch.delenv("CLOAKBROWSER_WIDEVINE_CDM", raising=False)
def _make_cdm(dirpath):
"""Create a fake WidevineCdm dir with a manifest.json."""
dirpath.mkdir(parents=True, exist_ok=True)
(dirpath / "manifest.json").write_text('{"version": "4.10.3050.0"}')
return dirpath
def _binary(tmp_path):
"""Return a fake chrome binary path inside its own dir."""
bdir = tmp_path / "bin"
bdir.mkdir(parents=True, exist_ok=True)
return bdir / "chrome"
def test_seeds_hint_next_to_binary(tmp_path):
"""CDM in <binary dir>/WidevineCdm -> hint file written with abs Path."""
binary = _binary(tmp_path)
cdm = _make_cdm(binary.parent / "WidevineCdm")
profile = tmp_path / "profile"
seed_widevine_hint(profile, binary)
hint = profile / _HINT
assert hint.is_file()
assert json.loads(hint.read_text())["Path"] == str(cdm.resolve())
def test_seeds_hint_from_env_var(tmp_path, monkeypatch):
"""CLOAKBROWSER_WIDEVINE_CDM takes priority and is used as the Path."""
cdm = _make_cdm(tmp_path / "custom_cdm")
monkeypatch.setenv("CLOAKBROWSER_WIDEVINE_CDM", str(cdm))
profile = tmp_path / "profile"
seed_widevine_hint(profile, _binary(tmp_path))
assert json.loads((profile / _HINT).read_text())["Path"] == str(cdm.resolve())
def test_no_cdm_no_file(tmp_path):
"""No CDM present -> nothing written, no exception."""
profile = tmp_path / "profile"
seed_widevine_hint(profile, _binary(tmp_path))
assert not (profile / _HINT).exists()
def test_kill_switch_disables(tmp_path, monkeypatch):
"""CLOAKBROWSER_WIDEVINE=0 disables seeding even when a CDM exists."""
monkeypatch.setenv("CLOAKBROWSER_WIDEVINE_CDM", str(_make_cdm(tmp_path / "custom_cdm")))
monkeypatch.setenv("CLOAKBROWSER_WIDEVINE", "0")
profile = tmp_path / "profile"
seed_widevine_hint(profile, _binary(tmp_path))
assert not (profile / _HINT).exists()
def test_idempotent(tmp_path, monkeypatch):
"""Seeding twice leaves the same correct content and doesn't error."""
cdm = _make_cdm(tmp_path / "custom_cdm")
monkeypatch.setenv("CLOAKBROWSER_WIDEVINE_CDM", str(cdm))
profile = tmp_path / "profile"
binary = _binary(tmp_path)
seed_widevine_hint(profile, binary)
seed_widevine_hint(profile, binary)
assert json.loads((profile / _HINT).read_text())["Path"] == str(cdm.resolve())
def test_noop_on_non_linux(tmp_path, monkeypatch):
"""On non-Linux, seeding is a no-op even with a CDM present."""
monkeypatch.setattr(widevine.platform, "system", lambda: "Windows")
monkeypatch.setenv("CLOAKBROWSER_WIDEVINE_CDM", str(_make_cdm(tmp_path / "cdm")))
profile = tmp_path / "profile"
seed_widevine_hint(profile, _binary(tmp_path))
assert not (profile / _HINT).exists()
def test_resolve_requires_manifest(tmp_path, monkeypatch):
"""A WidevineCdm dir without manifest.json is not treated as a CDM."""
bogus = tmp_path / "custom_cdm"
bogus.mkdir()
monkeypatch.setenv("CLOAKBROWSER_WIDEVINE_CDM", str(bogus))
assert resolve_widevine_cdm_dir(_binary(tmp_path)) is None
def test_env_var_is_exclusive(tmp_path, monkeypatch):
"""An invalid CLOAKBROWSER_WIDEVINE_CDM skips seeding — no fallback to binary dir."""
binary = _binary(tmp_path)
_make_cdm(binary.parent / "WidevineCdm") # valid CDM next to binary
bogus = tmp_path / "bogus"
bogus.mkdir() # set but no manifest.json
monkeypatch.setenv("CLOAKBROWSER_WIDEVINE_CDM", str(bogus))
assert resolve_widevine_cdm_dir(binary) is None
def test_empty_env_var_is_exclusive(tmp_path, monkeypatch):
"""An empty (but set) CLOAKBROWSER_WIDEVINE_CDM is exclusive — no binary-dir fallback."""
binary = _binary(tmp_path)
_make_cdm(binary.parent / "WidevineCdm") # valid CDM next to binary
monkeypatch.setenv("CLOAKBROWSER_WIDEVINE_CDM", "")
monkeypatch.chdir(tmp_path) # so a stray ./manifest.json can't match
assert resolve_widevine_cdm_dir(binary) is None
def test_empty_user_data_dir_skips(tmp_path, monkeypatch):
"""Empty user_data_dir (ephemeral profile) -> no CWD pollution, no seeding."""
cdm = _make_cdm(tmp_path / "custom_cdm")
monkeypatch.setenv("CLOAKBROWSER_WIDEVINE_CDM", str(cdm))
monkeypatch.chdir(tmp_path)
seed_widevine_hint("", _binary(tmp_path))
assert not (tmp_path / "WidevineCdm").exists()
def test_never_raises_on_write_failure(tmp_path, monkeypatch):
"""A write failure (hint dir path is a file) must not raise — launch must not break."""
cdm = _make_cdm(tmp_path / "custom_cdm")
monkeypatch.setenv("CLOAKBROWSER_WIDEVINE_CDM", str(cdm))
profile = tmp_path / "profile"
profile.mkdir()
# Block mkdir of <profile>/WidevineCdm by occupying that path with a file.
(profile / "WidevineCdm").write_text("not a dir")
seed_widevine_hint(profile, _binary(tmp_path)) # must not raise
def test_rewrites_corrupt_existing_hint(tmp_path, monkeypatch):
"""A non-UTF8 / mismatched existing hint is overwritten, without raising."""
cdm = _make_cdm(tmp_path / "custom_cdm")
monkeypatch.setenv("CLOAKBROWSER_WIDEVINE_CDM", str(cdm))
profile = tmp_path / "profile"
hint = profile / "WidevineCdm" / _HINT.split("/")[-1]
hint.parent.mkdir(parents=True)
hint.write_bytes(b"\xff\xfe not valid utf-8")
seed_widevine_hint(profile, _binary(tmp_path)) # must not raise
# corrupt content replaced with a valid hint pointing at the CDM
assert json.loads(hint.read_text())["Path"] == str(cdm.resolve())