feat: third-party-scripts blockieren (server + client-guard)
Loest die YouTube/Vimeo-API-Luecke: viele dienste laden ueber <script> (z. B. youtube.com/iframe_api, www-widgetapi.js, analytics) statt iframes - oft per JavaScript nachgeladen, daher fuer den scanner unsichtbar. - Pro dienst aktivierbar ueber das (umbenannte) feld "Zugehoerige Skripte blockieren (z. B. YouTube-/Vimeo-API)" = das vorhandene loads_script-flag. Presets (YouTube, Vimeo, Maps) haben es bereits an. - Server-seitig: passende <script src> werden zu type="text/plain" (src -> data-cb-src) neutralisiert, laden also nicht. - Client-seitig: winziger guard ganz frueh im <head> patcht appendChild/insertBefore/replaceChild und neutralisiert dynamisch injizierte scripts VOR dem einfuegen -> kein request. Faengt damit auch die per JS nachgeladene iframe_api ab. - Einwilligung (per-dienst-consent, z. B. ueber den video-platzhalter) schaltet die scripts via cbActivateScripts frei und laedt sie nach. - Neuer shortcode [content_blocker_consent id="…"] als einwilligungs-button fuer reine skript-dienste ohne sichtbaren platzhalter. - guard-logik mit DOM-mock getestet (block + reinject), server-regex isoliert geprueft. i18n DE/EN ergaenzt (127 strings). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -26,8 +26,26 @@
|
||||
} catch ( e ) {
|
||||
// localStorage unavailable; allow the load for this session only.
|
||||
}
|
||||
// Release any third-party <script> blocked for this service (handled by
|
||||
// the early head guard, which exposes cbActivateScripts).
|
||||
if ( typeof window.cbActivateScripts === 'function' ) {
|
||||
window.cbActivateScripts( serviceId );
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Public: grant consent for a service from a custom control
|
||||
* ([content_blocker_consent]) — used for script-only services that have no
|
||||
* visible embed. Reloads so blocked scripts/embeds load cleanly.
|
||||
*/
|
||||
window.cbConsent = function ( serviceId ) {
|
||||
if ( ! serviceId ) {
|
||||
return;
|
||||
}
|
||||
grantConsent( serviceId );
|
||||
window.location.reload();
|
||||
};
|
||||
|
||||
/* ───────────────────────── iframe loading ────────────────────────── */
|
||||
|
||||
/** Replace a .cb-blocker element with the real iframe. src comes from data-src. */
|
||||
|
||||
Reference in New Issue
Block a user