1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
use std::time::Duration;
use serde_json::json;
use crate::cdp::client::CdpClient;
use crate::cdp::types::{EvaluateResult, NavigateParams, NavigateResult};
pub struct GotoResult {
pub url: String,
pub title: String,
/// Where the navigation ended up relative to where it was aimed.
pub landed: crate::landing::Landing,
}
/// Parse a `"Name: Value"` header string into its (name, value) pair.
///
/// Splits on the FIRST colon so values may themselves contain colons
/// (e.g. `"X-Trace: a:b:c"`). Both sides are trimmed. Errors when there is no
/// colon or the name is empty.
pub fn parse_header(raw: &str) -> Result<(String, String), crate::BoxError> {
let (name, value) = raw
.split_once(':')
.ok_or_else(|| format!("Invalid --header {raw:?}: expected \"Name: Value\""))?;
let name = name.trim();
if name.is_empty() {
return Err(format!("Invalid --header {raw:?}: header name is empty").into());
}
Ok((name.to_string(), value.trim().to_string()))
}
pub async fn run(
client: &CdpClient,
url: &str,
timeout_secs: u64,
headers: &[(String, String)],
) -> Result<GotoResult, crate::BoxError> {
// Auto-prefix https:// if no scheme is provided
let url = if url.contains("://") {
url.to_string()
} else {
format!("https://{url}")
};
let url = url.as_str();
// Ensure Page domain is enabled so we receive loadEventFired
client.enable("Page").await?;
// Apply extra HTTP headers (auth tokens, multi-tenant routing, etc.) before
// navigating. Requires the Network domain.
if !headers.is_empty() {
client.enable("Network").await?;
let map: serde_json::Map<String, serde_json::Value> = headers
.iter()
.map(|(k, v)| (k.clone(), serde_json::Value::String(v.clone())))
.collect();
client
.send("Network.setExtraHTTPHeaders", json!({ "headers": map }))
.await?;
}
// Subscribe to events BEFORE navigating so a fast/cached load that fires
// Page.loadEventFired before we start waiting is not missed (which would
// otherwise stall until the full timeout).
let mut events = client.events();
let nav_result: NavigateResult = client
.call(
"Page.navigate",
NavigateParams {
url: url.to_string(),
referrer: None,
transition_type: None,
frame_id: None,
},
)
.await?;
if let Some(error_text) = &nav_result.error_text {
// The URL is in the message because the hint needs it: `hints::error_hint` gets a
// string and nothing else, and rule 2 of its contract wants a command with real
// values in it. Without this, five distinct network failures could only ever be
// answered with a sentence that named neither the host nor the scheme.
return Err(format!("Navigation failed for {url}: {error_text}").into());
}
// Wait for Page.loadEventFired on the pre-navigate subscription.
let _ = CdpClient::wait_for_event_on(
&mut events,
"Page.loadEventFired",
Duration::from_secs(timeout_secs),
)
.await;
// Wait for the DOM to stabilize (SPAs often render after loadEventFired): resolve once
// nothing has changed for QUIET, and never later than HARD.
//
// Both bounds matter. The quiet window starts immediately, so a page where nothing ever
// mutates resolves in QUIET rather than being charged the whole budget to discover that.
// And the ceiling is never cleared by a mutation, so a page that never goes quiet — a
// chat window, a live dashboard, a rotating ad slot — still returns. `awaitPromise` has
// no deadline of its own, so a probe that can fail to resolve holds the command open
// for as long as the page keeps moving.
let _ = client
.call::<_, serde_json::Value>(
"Runtime.evaluate",
json!({
"expression": r"new Promise(resolve => {
const QUIET = 200, HARD = 3000;
let settled = false, quiet = null, obs = null;
const finish = () => {
if (settled) return;
settled = true;
clearTimeout(quiet);
clearTimeout(hard);
if (obs) obs.disconnect();
resolve();
};
quiet = setTimeout(finish, QUIET);
const hard = setTimeout(finish, HARD);
obs = new MutationObserver(() => {
clearTimeout(quiet);
quiet = setTimeout(finish, QUIET);
});
obs.observe(document.body || document.documentElement, { childList: true, subtree: true });
})",
"awaitPromise": true,
"returnByValue": true,
}),
)
.await;
// Read the settled page state from the renderer. Page.navigate only echoes
// the requested URL; after an HTTP/client-side redirect the authoritative
// URL is location.href.
//
// The status rides on the same read. Navigation Timing is the stealth-safe path the
// retroactive network capture already uses: no `Network.enable`, so `--stealth` keeps
// its promise, and no extra round trip. `responseStatus` is missing on older Chrome and
// 0 on a document with no HTTP response, both of which `Landing` reports as absence.
//
// The document's SHAPE rides on it too, for `serving.rs` to judge — three numbers, no
// interpretation in the page. Deliberately not the accessibility tree: `goto` takes no
// snapshot on purpose, `getFullAXTree` on every navigation is the cost that decision
// avoids, and the two signals that matter (a frame's `src`, whether an anchor resolves to
// http) are DOM facts the tree does not carry.
//
// Every measurement below over-counts rather than under-counts — hidden text is counted,
// an off-screen button is counted — because over-counting produces `serving: "page"`,
// which is silence, and silence is the direction this rule errs in. Text is walked with a
// TreeWalker and capped rather than read from `innerText`: `innerText` forces layout,
// and a bound of 4096 characters ends the walk on the first paragraph of any real page.
let eval_result: EvaluateResult = client
.call(
"Runtime.evaluate",
json!({
"expression": r"(() => {
let status = null;
try {
const nav = performance.getEntriesByType('navigation')[0];
if (nav && typeof nav.responseStatus === 'number') status = nav.responseStatus;
} catch (e) {}
let shape = null;
try {
const root = document.body || document.documentElement;
// Frames AND scripts: Cloudflare's interstitial injects into an
// `about:blank` frame whose `src` is empty, and its only vendor-hosted
// URL is the Turnstile script (measured on nowsecure.nl). DataDome
// puts the URL on the frame. Query strings are dropped: they carry a
// per-visit id and nothing the vendor table matches on.
const resources = [];
const collect = (selector, cap) => {
let taken = 0;
for (const el of document.querySelectorAll(selector)) {
if (taken >= cap) break;
if (!el.src) continue;
resources.push(el.src.split('?')[0]);
taken++;
}
};
collect('iframe,frame', 20);
collect('script[src]', 60);
const controls = root.querySelectorAll(
'button,select,textarea,input:not([type=hidden]),[role=button],[contenteditable]'
).length;
let links = 0;
for (const a of root.querySelectorAll('a[href]')) {
// A `javascript:` anchor is not a destination — the F5 refusal
// notice's only link is one, and counting it would hide the page
// this whole probe exists to see.
if (a.protocol !== 'http:' && a.protocol !== 'https:') continue;
if (++links >= 64) break;
}
const scripts = document.querySelectorAll('script[src]').length;
let text = 0;
const walker = document.createTreeWalker(root, NodeFilter.SHOW_TEXT);
while (text < 4096) {
const node = walker.nextNode();
if (!node) break;
const tag = node.parentNode && node.parentNode.nodeName;
if (tag === 'SCRIPT' || tag === 'STYLE' || tag === 'NOSCRIPT' || tag === 'TEMPLATE') continue;
text += node.data.trim().length;
}
shape = { resources, controls, links, scripts, text };
} catch (e) { shape = null; }
return { url: location.href, title: document.title, status, shape };
})()",
"returnByValue": true,
}),
)
.await?;
let page_state = eval_result
.result
.value
.as_ref()
.and_then(serde_json::Value::as_object);
let settled_url = page_state
.and_then(|state| state.get("url"))
.and_then(serde_json::Value::as_str)
.unwrap_or(url)
.to_string();
let title = page_state
.and_then(|state| state.get("title"))
.and_then(serde_json::Value::as_str)
.unwrap_or("")
.to_string();
let status = page_state
.and_then(|state| state.get("status"))
.and_then(serde_json::Value::as_u64)
.and_then(|code| u16::try_from(code).ok());
// Absent rather than defaulted: a zero-valued shape reads as "an empty document", which
// is the strongest thing `serving` can say, from having measured nothing at all.
let shape = crate::serving::PageShape::from_probe(
page_state.and_then(|state| state.get("shape")),
);
// `url`, not the caller's raw argument: the https:// prefixing above is the tool's own
// normalisation, and comparing against the pre-normalised form would report a redirect
// on every `goto example.com`.
let landed = crate::landing::Landing::new(url, &settled_url, status, shape.as_ref());
Ok(GotoResult {
url: settled_url,
title,
landed,
})
}
#[cfg(test)]
mod tests {
use super::parse_header;
#[test]
fn parses_and_trims() {
let (n, v) = parse_header("Authorization: Bearer xyz").unwrap();
assert_eq!(n, "Authorization");
assert_eq!(v, "Bearer xyz");
}
#[test]
fn keeps_colons_in_value() {
let (n, v) = parse_header("X-Trace: a:b:c ").unwrap();
assert_eq!(n, "X-Trace");
assert_eq!(v, "a:b:c");
}
#[test]
fn empty_value_is_allowed() {
let (n, v) = parse_header("X-Empty:").unwrap();
assert_eq!(n, "X-Empty");
assert_eq!(v, "");
}
#[test]
fn trims_nonempty_name_and_whitespace_value() {
// Guards against a partial-trim regression that the empty-name test can't catch.
let (n, v) = parse_header(" X-Foo : ").unwrap();
assert_eq!(n, "X-Foo");
assert_eq!(v, "");
}
#[test]
fn rejects_missing_colon() {
assert!(parse_header("NoColonHere").is_err());
}
#[test]
fn rejects_empty_name() {
assert!(parse_header(" : value").is_err());
}
}