mirror of
https://github.com/garrytan/gstack.git
synced 2026-10-04 02:16:56 +02:00
* fix: support Windows Opera and Opera GX cookie imports Fixes #2957 * fix: repair Windows cookie decryption and make Opera import failures actionable - strip the SHA-256(host_key) prefix Chromium adds to v10 values (DB meta v24+) on Windows - keep receipts and name `$B handoff` recovery for App-Bound rows in browsers without native extraction - explain missing browsers, missing profiles and ambiguous profile selection with next steps - add windowsNative/resolveBrowserInfo, the operagx alias and sorted failure reasons in CLI output - cover the Node server runtime with a real-DPAPI Windows test * docs: document Windows Opera cookie import and guard browser lists against drift * chore: file cookie-import follow-ups from the Opera fix wave review * test: keep Opera receipt tests independent of the shared key cache * test: declare generated gstack/llms.txt as a command-reference input for PR selection * chore: release v1.91.4.0 * test: reconstruct the historical cookie-workflow approval after the Opera BROWSER.md additions * test: run the real-DPAPI Windows check with the runner's environment PowerShell launched with a stripped environment took ~18-21s on the Windows runner (measured on a throwaway diagnostics run), past dpapiDecrypt's 10s deadline; with the full environment it returns in ~0.3s. Only APPDATA is redirected to the fixture's Opera root. --------- Co-authored-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com>
This commit is contained in:
1 parent
01593aa67c
commit
d2a0bbcf4c
21 files changed
+1022
-69
No files matched your search
@@ -1,7 +1,8 @@
|
||||
import { afterAll, beforeAll, describe, expect, test } from 'bun:test';
|
||||
import { Database } from 'bun:sqlite';
|
||||
import { spawnSync } from 'node:child_process';
|
||||
import { copyFileSync, mkdtempSync, mkdirSync, readFileSync, realpathSync, rmSync } from 'node:fs';
|
||||
import { createCipheriv, createHash, randomBytes } from 'node:crypto';
|
||||
import { copyFileSync, mkdtempSync, mkdirSync, readFileSync, realpathSync, rmSync, writeFileSync } from 'node:fs';
|
||||
import { tmpdir } from 'node:os';
|
||||
import path from 'node:path';
|
||||
import { pathToFileURL } from 'node:url';
|
||||
@@ -28,6 +29,20 @@ beforeAll(() => {
|
||||
mkdirSync(windows, { recursive: true });
|
||||
expect(realpathSync(windows).startsWith(root + path.sep)).toBe(true);
|
||||
copyFileSync(dbPath, path.join(windows, 'Cookies'));
|
||||
|
||||
const writePlain = (directory: string, domain: string, name: string, value: string) => {
|
||||
mkdirSync(directory, { recursive: true });
|
||||
expect(realpathSync(directory).startsWith(root + path.sep)).toBe(true);
|
||||
const database = new Database(path.join(directory, 'Cookies'));
|
||||
database.run('CREATE TABLE cookies (host_key TEXT, name TEXT, value TEXT, encrypted_value BLOB, path TEXT, expires_utc INTEGER, is_secure INTEGER, is_httponly INTEGER, has_expires INTEGER, samesite INTEGER)');
|
||||
database.run('INSERT INTO cookies VALUES (?, ?, ?, ?, ?, 0, 0, 1, 0, 1)', [domain, name, value, Buffer.alloc(0), '/']);
|
||||
database.close();
|
||||
};
|
||||
writePlain(path.join(root, 'OperaRoaming/Opera Software/Opera Stable/Default/Network'), '.opera.fixture', 'opera-cookie', 'opera-plaintext');
|
||||
writePlain(path.join(root, 'OperaRoaming/Opera Software/Opera Stable/User Data/Default/Network'), '.opera.fixture', 'opera-cookie', 'user-data-decoy');
|
||||
writePlain(path.join(root, 'OperaRoaming/Opera Software/Opera GX Stable/Profile 2/Network'), '.gx.fixture', 'gx-cookie', 'gx-plaintext');
|
||||
writePlain(path.join(root, 'AppData/Local/Opera Software/Opera Stable/Default/Network'), '.opera.fixture', 'opera-cookie', 'local-decoy');
|
||||
writePlain(path.join(root, 'AppData/Local/Opera Software/Opera GX Stable/Default/Network'), '.gx.fixture', 'gx-cookie', 'local-gx-decoy');
|
||||
});
|
||||
|
||||
afterAll(() => rmSync(root, { recursive: true, force: true }));
|
||||
@@ -49,6 +64,101 @@ describe('actual Node importer runtime', () => {
|
||||
expect(JSON.parse(child.stdout)).toEqual({ domains: { browser: 'Chromium', domains: [{ domain: '.fixture.test', count: 1 }] }, count: 1, failed: 0, scope: ['.fixture.test'], cookieName: 'synthetic' });
|
||||
});
|
||||
|
||||
// Path and SQLite coverage for the bundled module. This does not exercise Windows DPAPI.
|
||||
test('discovers and imports plaintext Opera and Opera GX cookies through the bundled module', () => {
|
||||
const child = spawnSync(node!, ['--input-type=module', '-e', `
|
||||
const { findInstalledBrowsers, listDomains, listProfiles, listSupportedBrowserNames, importCookies } = await import(process.argv[1]);
|
||||
const opera = await importCookies('opera', ['opera.fixture']);
|
||||
const gx = await importCookies('Opera GX', ['gx.fixture'], 'Profile 2');
|
||||
const skipped = await importCookies('opera', ['gx.fixture']);
|
||||
console.log(JSON.stringify({
|
||||
platform: process.platform,
|
||||
discovered: findInstalledBrowsers().map(browser => browser.name).sort(),
|
||||
supported: listSupportedBrowserNames(),
|
||||
operaDomains: listDomains('opera').domains.map(entry => entry.domain).sort(),
|
||||
gxProfiles: listProfiles('opera-gx').map(profile => profile.name),
|
||||
gxDomains: listDomains('opera-gx', 'Profile 2').domains.map(entry => entry.domain),
|
||||
opera: { count: opera.count, failed: opera.failed, name: opera.cookies[0]?.name, value: opera.cookies[0]?.value },
|
||||
gx: { count: gx.count, failed: gx.failed, name: gx.cookies[0]?.name, value: gx.cookies[0]?.value },
|
||||
skipped: skipped.count,
|
||||
}));
|
||||
`, pathToFileURL(bundle).href], {
|
||||
encoding: 'utf8', timeout: 15_000,
|
||||
env: {
|
||||
HOME: root, USERPROFILE: root, LOCALAPPDATA: path.join(root, 'AppData/Local'),
|
||||
APPDATA: path.join(root, 'OperaRoaming'), TEMP: root, TMP: root, NODE_NO_WARNINGS: '1',
|
||||
PATH: path.dirname(node!), ...(process.env.SystemRoot ? { SystemRoot: process.env.SystemRoot } : {}),
|
||||
},
|
||||
});
|
||||
expect(child.error).toBeUndefined();
|
||||
expect(child.status).toBe(0);
|
||||
expect(child.stderr).toBe('');
|
||||
const parsed = JSON.parse(child.stdout);
|
||||
expect(parsed.discovered).toEqual(expect.arrayContaining(['Opera', 'Opera GX']));
|
||||
expect(parsed.platform === 'win32'
|
||||
? parsed.supported.includes('Opera') && parsed.supported.includes('Opera GX')
|
||||
: !parsed.supported.includes('Opera') && !parsed.supported.includes('Opera GX')).toBe(true);
|
||||
expect(parsed.operaDomains).toEqual(['.opera.fixture']);
|
||||
expect(parsed.gxProfiles).toEqual(['Profile 2']);
|
||||
expect(parsed.gxDomains).toEqual(['.gx.fixture']);
|
||||
expect(parsed.opera).toEqual({ count: 1, failed: 0, name: 'opera-cookie', value: 'opera-plaintext' });
|
||||
expect(parsed.gx).toEqual({ count: 1, failed: 0, name: 'gx-cookie', value: 'gx-plaintext' });
|
||||
expect(parsed.skipped).toBe(0);
|
||||
});
|
||||
|
||||
// Real Windows DPAPI through the production Node polyfill; no credential subprocess mock.
|
||||
test.skipIf(process.platform !== 'win32')('decrypts a host-bound Opera v10 cookie with real DPAPI under the Node server runtime', () => {
|
||||
const systemRoot = process.env.SystemRoot || 'C:\\Windows';
|
||||
const powershellDir = path.win32.join(systemRoot, 'System32', 'WindowsPowerShell', 'v1.0');
|
||||
const key = randomBytes(32);
|
||||
const protect = spawnSync(path.win32.join(powershellDir, 'powershell.exe'), ['-NoProfile', '-NonInteractive', '-Command',
|
||||
'Add-Type -AssemblyName System.Security; $b = [Convert]::FromBase64String([Console]::In.ReadToEnd().Trim()); [Convert]::ToBase64String([System.Security.Cryptography.ProtectedData]::Protect($b, $null, [System.Security.Cryptography.DataProtectionScope]::CurrentUser))',
|
||||
], { input: key.toString('base64'), encoding: 'utf8', timeout: 30_000, windowsHide: true });
|
||||
expect(protect.status).toBe(0);
|
||||
const blob = Buffer.from(protect.stdout.trim(), 'base64');
|
||||
expect(blob.length).toBeGreaterThan(32);
|
||||
|
||||
const appData = path.join(root, 'DpapiRoaming');
|
||||
const browserRoot = path.join(appData, 'Opera Software', 'Opera Stable');
|
||||
const network = path.join(browserRoot, 'Default', 'Network');
|
||||
mkdirSync(network, { recursive: true });
|
||||
expect(realpathSync(network).startsWith(root + path.sep)).toBe(true);
|
||||
writeFileSync(path.join(browserRoot, 'Local State'), JSON.stringify({ os_crypt: { encrypted_key: Buffer.concat([Buffer.from('DPAPI'), blob]).toString('base64') } }));
|
||||
const seal = (sealKey: Buffer, plaintext: Buffer) => {
|
||||
const nonce = randomBytes(12);
|
||||
const cipher = createCipheriv('aes-256-gcm', sealKey, nonce);
|
||||
const ciphertext = Buffer.concat([cipher.update(plaintext), cipher.final()]);
|
||||
return Buffer.concat([Buffer.from('v10'), nonce, ciphertext, cipher.getAuthTag()]);
|
||||
};
|
||||
const expected = 'dpapi-synthetic-session';
|
||||
const hostHash = createHash('sha256').update('.dpapi.fixture').digest();
|
||||
const database = new Database(path.join(network, 'Cookies'));
|
||||
database.run('CREATE TABLE cookies (host_key TEXT, name TEXT, value TEXT, encrypted_value BLOB, path TEXT, expires_utc INTEGER, is_secure INTEGER, is_httponly INTEGER, has_expires INTEGER, samesite INTEGER)');
|
||||
database.run('INSERT INTO cookies VALUES (?, ?, ?, ?, ?, 0, 1, 1, 0, 1)', ['.dpapi.fixture', 'session', '', seal(key, Buffer.concat([hostHash, Buffer.from(expected)])), '/']);
|
||||
database.run('INSERT INTO cookies VALUES (?, ?, ?, ?, ?, 0, 1, 1, 0, 1)', ['.dpapi.fixture', 'wrong-key', '', seal(randomBytes(32), Buffer.concat([hostHash, Buffer.from('other')])), '/']);
|
||||
database.close();
|
||||
|
||||
const child = spawnSync(node!, ['--input-type=module', '-e', `
|
||||
import { createRequire } from 'node:module';
|
||||
createRequire(import.meta.url)(process.argv[1]);
|
||||
const { importCookies } = await import(process.argv[2]);
|
||||
const result = await importCookies('opera', ['dpapi.fixture']);
|
||||
console.log(JSON.stringify({ count: result.count, failed: result.failed, reasons: result.failureReasons, matches: result.cookies[0]?.value === process.argv[3] }));
|
||||
`, path.resolve(import.meta.dir, '../src/bun-polyfill.cjs'), pathToFileURL(bundle).href, expected], {
|
||||
encoding: 'utf8', timeout: 45_000, windowsHide: true,
|
||||
// Keep the runner's full environment: PowerShell started with a stripped
|
||||
// environment takes ~20s on Windows CI (measured), past dpapiDecrypt's 10s
|
||||
// deadline. Only APPDATA moves, to the fixture's Opera root.
|
||||
env: { ...process.env, APPDATA: appData, NODE_NO_WARNINGS: '1' },
|
||||
});
|
||||
expect(child.error).toBeUndefined();
|
||||
expect(child.stderr).toBe('');
|
||||
expect(child.status).toBe(0);
|
||||
expect(JSON.parse(child.stdout)).toEqual({ count: 1, failed: 1, reasons: { decryption_failed: 1 }, matches: true });
|
||||
expect(child.stdout).not.toContain(expected);
|
||||
expect(child.stdout).not.toContain(key.toString('base64'));
|
||||
}, 90_000);
|
||||
|
||||
test('Node server build does not stub away the database', () => {
|
||||
const script = readFileSync(path.resolve(import.meta.dir, '../scripts/build-node-server.sh'), 'utf8');
|
||||
expect(script).not.toContain('const Database = null');
|
||||
|
||||
Reference in new issue
Block a user