fix: scanner ignoriert metadaten-links (gmpg.org rel=profile); version 1.2.0

- Nur ladende <link rel=...> (stylesheet/preload/icon/...) werden gezaehlt;
  rel=profile/canonical/pingback etc. (z.B. gmpg.org) sind keine Requests mehr.
- Plugin-Version + Header auf 1.2.0 (passend zu readme), Changelog-Eintrag.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
s4luorth
2026-06-07 16:57:09 +02:00
parent b03f18a794
commit de4f16fefa
4 changed files with 33 additions and 6 deletions

View File

@@ -3,7 +3,7 @@
* Plugin Name: GDPR Content Blocker * Plugin Name: GDPR Content Blocker
* Plugin URI: https://lucas-orth.de * Plugin URI: https://lucas-orth.de
* Description: DSGVO-konformer Consent-Blocker für externe iframes. Lädt Drittinhalte erst nach aktiver Einwilligung. * Description: DSGVO-konformer Consent-Blocker für externe iframes. Lädt Drittinhalte erst nach aktiver Einwilligung.
* Version: 1.1.0 * Version: 1.2.0
* Author: Lucas Orth * Author: Lucas Orth
* Author URI: https://lucas-orth.de * Author URI: https://lucas-orth.de
* Text Domain: gdpr-content-blocker * Text Domain: gdpr-content-blocker
@@ -15,7 +15,7 @@
defined( 'ABSPATH' ) || exit; defined( 'ABSPATH' ) || exit;
define( 'CB_VERSION', '1.1.0' ); define( 'CB_VERSION', '1.2.0' );
define( 'CB_FILE', __FILE__ ); define( 'CB_FILE', __FILE__ );
define( 'CB_DIR', plugin_dir_path( __FILE__ ) ); define( 'CB_DIR', plugin_dir_path( __FILE__ ) );
define( 'CB_URL', plugin_dir_url( __FILE__ ) ); define( 'CB_URL', plugin_dir_url( __FILE__ ) );

View File

@@ -4,7 +4,7 @@ Tags: dsgvo, gdpr, consent, iframe, datenschutz, gdpr-content-blocker
Requires at least: 6.0 Requires at least: 6.0
Tested up to: 6.7 Tested up to: 6.7
Requires PHP: 8.1 Requires PHP: 8.1
Stable tag: 1.1.0 Stable tag: 1.2.0
License: GPL-2.0-or-later License: GPL-2.0-or-later
License URI: https://www.gnu.org/licenses/gpl-2.0.html License URI: https://www.gnu.org/licenses/gpl-2.0.html
@@ -93,6 +93,12 @@ ZIP muss einen Ordner `gdpr-content-blocker/` auf oberster Ebene enthalten.
== Changelog == == Changelog ==
= 1.2.0 =
* Shortcodes in eigenen Tab; „Über das Plugin"-Tab
* Belegte Domains als Liste mit Papierkorb; Lizenz-Status live aktualisiert
* Pfeil-Icon zum Ein-/Ausklappen; diverse UI-Korrekturen
* Cache-Busting der Admin-Skripte
= 1.1.0 = = 1.1.0 =
* Vorlagen für Google Maps, YouTube, OpenStreetMap, Vimeo * Vorlagen für Google Maps, YouTube, OpenStreetMap, Vimeo
* Client-seitige Erkennung (Elementor-Videos, per JS nachgeladene iframes) * Client-seitige Erkennung (Elementor-Videos, per JS nachgeladene iframes)

View File

@@ -13,6 +13,16 @@ function normHost(h) {
return String(h || '').toLowerCase().replace(/:.*$/, '').replace(/^www\./, ''); return String(h || '').toLowerCase().replace(/:.*$/, '').replace(/^www\./, '');
} }
// Only these <link rel="…"> values actually fetch/connect to a resource.
// Everything else (profile, canonical, alternate, pingback, EditURI, wlwmanifest,
// shortlink, https://api.w.org/, …) is pure metadata and triggers no request —
// e.g. gmpg.org via rel="profile" must NOT be reported.
const LINK_LOADING_RELS = new Set([
'stylesheet', 'preload', 'modulepreload', 'preconnect', 'dns-prefetch',
'prefetch', 'prerender', 'icon', 'shortcut icon', 'apple-touch-icon',
'apple-touch-icon-precomposed', 'mask-icon', 'manifest', 'fetch',
]);
/** Extract absolute resource URLs (with a type tag) from one HTML document. */ /** Extract absolute resource URLs (with a type tag) from one HTML document. */
export function extractResources(html, baseUrl) { export function extractResources(html, baseUrl) {
const out = []; const out = [];
@@ -23,9 +33,16 @@ export function extractResources(html, baseUrl) {
const body = m[2]; const body = m[2];
let raw = ''; let raw = '';
if (tag === 'object') raw = attr(body, 'data'); if (tag === 'object') {
else if (tag === 'link') raw = attr(body, 'href'); raw = attr(body, 'data');
else raw = attr(body, 'src'); } else if (tag === 'link') {
// Skip metadata links that never load anything (rel="profile" etc.).
const rel = attr(body, 'rel').toLowerCase().trim();
if (!LINK_LOADING_RELS.has(rel)) continue;
raw = attr(body, 'href');
} else {
raw = attr(body, 'src');
}
if (!raw) continue; if (!raw) continue;
if (/^(data:|blob:|javascript:|mailto:|tel:|#|about:)/i.test(raw)) continue; if (/^(data:|blob:|javascript:|mailto:|tel:|#|about:)/i.test(raw)) continue;

View File

@@ -8,6 +8,8 @@ const ok = (name, cond, extra = '') => {
const html = ` const html = `
<!DOCTYPE html><html><head> <!DOCTYPE html><html><head>
<link rel="profile" href="https://gmpg.org/xfn/11">
<link rel="canonical" href="https://other.example/x">
<link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Roboto"> <link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Roboto">
<script src="/wp-includes/js/jquery.js"></script> <script src="/wp-includes/js/jquery.js"></script>
<script src="https://www.googletagmanager.com/gtag/js?id=G-XYZ"></script> <script src="https://www.googletagmanager.com/gtag/js?id=G-XYZ"></script>
@@ -31,6 +33,8 @@ ok('finds external script (gtm)', resources.some((r) => r.type === 'script' && r
ok('resolves relative script to absolute', resources.some((r) => r.url === 'https://example.com/wp-includes/js/jquery.js')); ok('resolves relative script to absolute', resources.some((r) => r.url === 'https://example.com/wp-includes/js/jquery.js'));
ok('finds external img', resources.some((r) => r.type === 'img' && r.url.includes('cdn.example.com'))); ok('finds external img', resources.some((r) => r.type === 'img' && r.url.includes('cdn.example.com')));
ok('finds link stylesheet', resources.some((r) => r.type === 'link' && r.url.includes('fonts.googleapis.com'))); ok('finds link stylesheet', resources.some((r) => r.type === 'link' && r.url.includes('fonts.googleapis.com')));
ok('ignores rel=profile (gmpg.org)', !resources.some((r) => r.url.includes('gmpg.org')));
ok('ignores rel=canonical', !resources.some((r) => r.url.includes('other.example')));
ok('finds object data (vimeo)', resources.some((r) => r.type === 'object' && r.url.includes('player.vimeo.com'))); ok('finds object data (vimeo)', resources.some((r) => r.type === 'object' && r.url.includes('player.vimeo.com')));
ok('ignores anchor href', !resources.some((r) => r.url.includes('twitter.com'))); ok('ignores anchor href', !resources.some((r) => r.url.includes('twitter.com')));