uBO and uBOL both use a trusted variant of the scriptlet: json-edit.js
First issue I have with this scriptlet (which has a trusted and non-trusted variant) is that it is 1,575 lines of code!
That is not a scriptlet, that is rewriting functionality of the browser.
Second issue I have with the trusted variant is that it is used to strip out specific fields from a site's own data — an ad-slot config buried in a JSON blob, a tracking flag in an API response, a consent-popup trigger baked into a page's initial state object — without touching the rest of the object.
In plain terms: the non-trusted version can only delete a piece of data. The trusted version can also replace it with something else entirely — and it can do that to data flowing both ways, not just what you see on screen.
A few concrete pictures of what that difference means:
USE AT YOUR OWN RISK!
I am also afraid Mv4 will forbid this (mis)usage and will limit use of scriptlet (is javascript injection) further (and make it harder for adblockers to block ads).
@Sampei.Nihira thanks for challenging me to add some more scritplets in uBS, investigating how I could implement extra scriptlets without reducing security is why I stumbled on this madness.
First issue I have with this scriptlet (which has a trusted and non-trusted variant) is that it is 1,575 lines of code!
That is not a scriptlet, that is rewriting functionality of the browser.
Second issue I have with the trusted variant is that it is used to strip out specific fields from a site's own data — an ad-slot config buried in a JSON blob, a tracking flag in an API response, a consent-popup trigger baked into a page's initial state object — without touching the rest of the object.
In plain terms: the non-trusted version can only delete a piece of data. The trusted version can also replace it with something else entirely — and it can do that to data flowing both ways, not just what you see on screen.
A few concrete pictures of what that difference means:
- A price on a checkout page. The non-trusted version could hide a "you've been shown this ad" flag. The trusted version could rewrite the price itself — or, since it also works on the actual data a page sends to its server (via fetch/XHR), rewrite the order amount in the request before it ever leaves your browser.
- A login or account page. It could quietly change a field being submitted — an account number, a permission setting, a quantity — without anything visibly different on the page you're looking at.
- A "you have new messages" flag, or similar state. The non-trusted version can only remove that flag. The trusted version could set it to whatever value someone wants, on a site that trusts its own JSON blindly.
USE AT YOUR OWN RISK!
I am also afraid Mv4 will forbid this (mis)usage and will limit use of scriptlet (is javascript injection) further (and make it harder for adblockers to block ads).
@Sampei.Nihira thanks for challenging me to add some more scritplets in uBS, investigating how I could implement extra scriptlets without reducing security is why I stumbled on this madness.
Last edited: