mirror of
https://github.com/garrytan/gstack.git
synced 2026-10-03 01:46:55 +02:00
* fix: support Windows Opera and Opera GX cookie imports Fixes #2957 * fix: repair Windows cookie decryption and make Opera import failures actionable - strip the SHA-256(host_key) prefix Chromium adds to v10 values (DB meta v24+) on Windows - keep receipts and name `$B handoff` recovery for App-Bound rows in browsers without native extraction - explain missing browsers, missing profiles and ambiguous profile selection with next steps - add windowsNative/resolveBrowserInfo, the operagx alias and sorted failure reasons in CLI output - cover the Node server runtime with a real-DPAPI Windows test * docs: document Windows Opera cookie import and guard browser lists against drift * chore: file cookie-import follow-ups from the Opera fix wave review * test: keep Opera receipt tests independent of the shared key cache * test: declare generated gstack/llms.txt as a command-reference input for PR selection * chore: release v1.91.4.0 * test: reconstruct the historical cookie-workflow approval after the Opera BROWSER.md additions * test: run the real-DPAPI Windows check with the runner's environment PowerShell launched with a stripped environment took ~18-21s on the Windows runner (measured on a throwaway diagnostics run), past dpapiDecrypt's 10s deadline; with the full environment it returns in ~0.3s. Only APPDATA is redirected to the fixture's Opera root. --------- Co-authored-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com>
167 lines
11 KiB
TypeScript
167 lines
11 KiB
TypeScript
import { afterAll, beforeAll, describe, expect, test } from 'bun:test';
|
|
import { Database } from 'bun:sqlite';
|
|
import { spawnSync } from 'node:child_process';
|
|
import { createCipheriv, createHash, randomBytes } from 'node:crypto';
|
|
import { copyFileSync, mkdtempSync, mkdirSync, readFileSync, realpathSync, rmSync, writeFileSync } from 'node:fs';
|
|
import { tmpdir } from 'node:os';
|
|
import path from 'node:path';
|
|
import { pathToFileURL } from 'node:url';
|
|
|
|
const root = realpathSync(mkdtempSync(path.join(tmpdir(), 'cookie-node-')));
|
|
const bundle = path.join(root, 'importer.mjs');
|
|
const node = Bun.which('node');
|
|
if (!node) throw new Error('Node.js is required for importer runtime coverage');
|
|
|
|
beforeAll(() => {
|
|
const build = spawnSync(process.execPath, ['build', path.resolve(import.meta.dir, '../src/cookie-import-browser.ts'), '--target=node', '--outfile', bundle], {
|
|
encoding: 'utf8', timeout: 30_000,
|
|
});
|
|
expect(build.status).toBe(0);
|
|
const profile = path.join(root, '.config/chromium/Default');
|
|
mkdirSync(profile, { recursive: true });
|
|
expect(realpathSync(profile).startsWith(root + path.sep)).toBe(true);
|
|
const dbPath = path.join(profile, 'Cookies');
|
|
const database = new Database(dbPath);
|
|
database.run('CREATE TABLE cookies (host_key TEXT, name TEXT, value TEXT, encrypted_value BLOB, path TEXT, expires_utc INTEGER, is_secure INTEGER, is_httponly INTEGER, has_expires INTEGER, samesite INTEGER)');
|
|
database.run("INSERT INTO cookies VALUES ('.fixture.test', 'synthetic', 'fixture-value', x'', '/', 0, 0, 1, 0, 1)");
|
|
database.close();
|
|
const windows = path.join(root, 'AppData/Local/Chromium/User Data/Default');
|
|
mkdirSync(windows, { recursive: true });
|
|
expect(realpathSync(windows).startsWith(root + path.sep)).toBe(true);
|
|
copyFileSync(dbPath, path.join(windows, 'Cookies'));
|
|
|
|
const writePlain = (directory: string, domain: string, name: string, value: string) => {
|
|
mkdirSync(directory, { recursive: true });
|
|
expect(realpathSync(directory).startsWith(root + path.sep)).toBe(true);
|
|
const database = new Database(path.join(directory, 'Cookies'));
|
|
database.run('CREATE TABLE cookies (host_key TEXT, name TEXT, value TEXT, encrypted_value BLOB, path TEXT, expires_utc INTEGER, is_secure INTEGER, is_httponly INTEGER, has_expires INTEGER, samesite INTEGER)');
|
|
database.run('INSERT INTO cookies VALUES (?, ?, ?, ?, ?, 0, 0, 1, 0, 1)', [domain, name, value, Buffer.alloc(0), '/']);
|
|
database.close();
|
|
};
|
|
writePlain(path.join(root, 'OperaRoaming/Opera Software/Opera Stable/Default/Network'), '.opera.fixture', 'opera-cookie', 'opera-plaintext');
|
|
writePlain(path.join(root, 'OperaRoaming/Opera Software/Opera Stable/User Data/Default/Network'), '.opera.fixture', 'opera-cookie', 'user-data-decoy');
|
|
writePlain(path.join(root, 'OperaRoaming/Opera Software/Opera GX Stable/Profile 2/Network'), '.gx.fixture', 'gx-cookie', 'gx-plaintext');
|
|
writePlain(path.join(root, 'AppData/Local/Opera Software/Opera Stable/Default/Network'), '.opera.fixture', 'opera-cookie', 'local-decoy');
|
|
writePlain(path.join(root, 'AppData/Local/Opera Software/Opera GX Stable/Default/Network'), '.gx.fixture', 'gx-cookie', 'local-gx-decoy');
|
|
});
|
|
|
|
afterAll(() => rmSync(root, { recursive: true, force: true }));
|
|
|
|
describe('actual Node importer runtime', () => {
|
|
test('lists and imports cookies through the bundled production module', () => {
|
|
const child = spawnSync(node!, ['--input-type=module', '-e', `
|
|
const { listDomains, importCookies } = await import(process.argv[1]);
|
|
const domains = listDomains('chromium');
|
|
const result = await importCookies('chromium', ['fixture.test']);
|
|
console.log(JSON.stringify({ domains, count: result.count, failed: result.failed, scope: Object.keys(result.domainCounts), cookieName: result.cookies[0]?.name }));
|
|
`, pathToFileURL(bundle).href], {
|
|
encoding: 'utf8', timeout: 15_000,
|
|
env: { HOME: root, USERPROFILE: root, LOCALAPPDATA: path.join(root, 'AppData/Local'), TEMP: root, TMP: root, NODE_NO_WARNINGS: '1', PATH: path.dirname(node!), ...(process.env.SystemRoot ? { SystemRoot: process.env.SystemRoot } : {}) },
|
|
});
|
|
expect(child.error).toBeUndefined();
|
|
expect(child.status).toBe(0);
|
|
expect(child.stderr).toBe('');
|
|
expect(JSON.parse(child.stdout)).toEqual({ domains: { browser: 'Chromium', domains: [{ domain: '.fixture.test', count: 1 }] }, count: 1, failed: 0, scope: ['.fixture.test'], cookieName: 'synthetic' });
|
|
});
|
|
|
|
// Path and SQLite coverage for the bundled module. This does not exercise Windows DPAPI.
|
|
test('discovers and imports plaintext Opera and Opera GX cookies through the bundled module', () => {
|
|
const child = spawnSync(node!, ['--input-type=module', '-e', `
|
|
const { findInstalledBrowsers, listDomains, listProfiles, listSupportedBrowserNames, importCookies } = await import(process.argv[1]);
|
|
const opera = await importCookies('opera', ['opera.fixture']);
|
|
const gx = await importCookies('Opera GX', ['gx.fixture'], 'Profile 2');
|
|
const skipped = await importCookies('opera', ['gx.fixture']);
|
|
console.log(JSON.stringify({
|
|
platform: process.platform,
|
|
discovered: findInstalledBrowsers().map(browser => browser.name).sort(),
|
|
supported: listSupportedBrowserNames(),
|
|
operaDomains: listDomains('opera').domains.map(entry => entry.domain).sort(),
|
|
gxProfiles: listProfiles('opera-gx').map(profile => profile.name),
|
|
gxDomains: listDomains('opera-gx', 'Profile 2').domains.map(entry => entry.domain),
|
|
opera: { count: opera.count, failed: opera.failed, name: opera.cookies[0]?.name, value: opera.cookies[0]?.value },
|
|
gx: { count: gx.count, failed: gx.failed, name: gx.cookies[0]?.name, value: gx.cookies[0]?.value },
|
|
skipped: skipped.count,
|
|
}));
|
|
`, pathToFileURL(bundle).href], {
|
|
encoding: 'utf8', timeout: 15_000,
|
|
env: {
|
|
HOME: root, USERPROFILE: root, LOCALAPPDATA: path.join(root, 'AppData/Local'),
|
|
APPDATA: path.join(root, 'OperaRoaming'), TEMP: root, TMP: root, NODE_NO_WARNINGS: '1',
|
|
PATH: path.dirname(node!), ...(process.env.SystemRoot ? { SystemRoot: process.env.SystemRoot } : {}),
|
|
},
|
|
});
|
|
expect(child.error).toBeUndefined();
|
|
expect(child.status).toBe(0);
|
|
expect(child.stderr).toBe('');
|
|
const parsed = JSON.parse(child.stdout);
|
|
expect(parsed.discovered).toEqual(expect.arrayContaining(['Opera', 'Opera GX']));
|
|
expect(parsed.platform === 'win32'
|
|
? parsed.supported.includes('Opera') && parsed.supported.includes('Opera GX')
|
|
: !parsed.supported.includes('Opera') && !parsed.supported.includes('Opera GX')).toBe(true);
|
|
expect(parsed.operaDomains).toEqual(['.opera.fixture']);
|
|
expect(parsed.gxProfiles).toEqual(['Profile 2']);
|
|
expect(parsed.gxDomains).toEqual(['.gx.fixture']);
|
|
expect(parsed.opera).toEqual({ count: 1, failed: 0, name: 'opera-cookie', value: 'opera-plaintext' });
|
|
expect(parsed.gx).toEqual({ count: 1, failed: 0, name: 'gx-cookie', value: 'gx-plaintext' });
|
|
expect(parsed.skipped).toBe(0);
|
|
});
|
|
|
|
// Real Windows DPAPI through the production Node polyfill; no credential subprocess mock.
|
|
test.skipIf(process.platform !== 'win32')('decrypts a host-bound Opera v10 cookie with real DPAPI under the Node server runtime', () => {
|
|
const systemRoot = process.env.SystemRoot || 'C:\\Windows';
|
|
const powershellDir = path.win32.join(systemRoot, 'System32', 'WindowsPowerShell', 'v1.0');
|
|
const key = randomBytes(32);
|
|
const protect = spawnSync(path.win32.join(powershellDir, 'powershell.exe'), ['-NoProfile', '-NonInteractive', '-Command',
|
|
'Add-Type -AssemblyName System.Security; $b = [Convert]::FromBase64String([Console]::In.ReadToEnd().Trim()); [Convert]::ToBase64String([System.Security.Cryptography.ProtectedData]::Protect($b, $null, [System.Security.Cryptography.DataProtectionScope]::CurrentUser))',
|
|
], { input: key.toString('base64'), encoding: 'utf8', timeout: 30_000, windowsHide: true });
|
|
expect(protect.status).toBe(0);
|
|
const blob = Buffer.from(protect.stdout.trim(), 'base64');
|
|
expect(blob.length).toBeGreaterThan(32);
|
|
|
|
const appData = path.join(root, 'DpapiRoaming');
|
|
const browserRoot = path.join(appData, 'Opera Software', 'Opera Stable');
|
|
const network = path.join(browserRoot, 'Default', 'Network');
|
|
mkdirSync(network, { recursive: true });
|
|
expect(realpathSync(network).startsWith(root + path.sep)).toBe(true);
|
|
writeFileSync(path.join(browserRoot, 'Local State'), JSON.stringify({ os_crypt: { encrypted_key: Buffer.concat([Buffer.from('DPAPI'), blob]).toString('base64') } }));
|
|
const seal = (sealKey: Buffer, plaintext: Buffer) => {
|
|
const nonce = randomBytes(12);
|
|
const cipher = createCipheriv('aes-256-gcm', sealKey, nonce);
|
|
const ciphertext = Buffer.concat([cipher.update(plaintext), cipher.final()]);
|
|
return Buffer.concat([Buffer.from('v10'), nonce, ciphertext, cipher.getAuthTag()]);
|
|
};
|
|
const expected = 'dpapi-synthetic-session';
|
|
const hostHash = createHash('sha256').update('.dpapi.fixture').digest();
|
|
const database = new Database(path.join(network, 'Cookies'));
|
|
database.run('CREATE TABLE cookies (host_key TEXT, name TEXT, value TEXT, encrypted_value BLOB, path TEXT, expires_utc INTEGER, is_secure INTEGER, is_httponly INTEGER, has_expires INTEGER, samesite INTEGER)');
|
|
database.run('INSERT INTO cookies VALUES (?, ?, ?, ?, ?, 0, 1, 1, 0, 1)', ['.dpapi.fixture', 'session', '', seal(key, Buffer.concat([hostHash, Buffer.from(expected)])), '/']);
|
|
database.run('INSERT INTO cookies VALUES (?, ?, ?, ?, ?, 0, 1, 1, 0, 1)', ['.dpapi.fixture', 'wrong-key', '', seal(randomBytes(32), Buffer.concat([hostHash, Buffer.from('other')])), '/']);
|
|
database.close();
|
|
|
|
const child = spawnSync(node!, ['--input-type=module', '-e', `
|
|
import { createRequire } from 'node:module';
|
|
createRequire(import.meta.url)(process.argv[1]);
|
|
const { importCookies } = await import(process.argv[2]);
|
|
const result = await importCookies('opera', ['dpapi.fixture']);
|
|
console.log(JSON.stringify({ count: result.count, failed: result.failed, reasons: result.failureReasons, matches: result.cookies[0]?.value === process.argv[3] }));
|
|
`, path.resolve(import.meta.dir, '../src/bun-polyfill.cjs'), pathToFileURL(bundle).href, expected], {
|
|
encoding: 'utf8', timeout: 45_000, windowsHide: true,
|
|
// Keep the runner's full environment: PowerShell started with a stripped
|
|
// environment takes ~20s on Windows CI (measured), past dpapiDecrypt's 10s
|
|
// deadline. Only APPDATA moves, to the fixture's Opera root.
|
|
env: { ...process.env, APPDATA: appData, NODE_NO_WARNINGS: '1' },
|
|
});
|
|
expect(child.error).toBeUndefined();
|
|
expect(child.stderr).toBe('');
|
|
expect(child.status).toBe(0);
|
|
expect(JSON.parse(child.stdout)).toEqual({ count: 1, failed: 1, reasons: { decryption_failed: 1 }, matches: true });
|
|
expect(child.stdout).not.toContain(expected);
|
|
expect(child.stdout).not.toContain(key.toString('base64'));
|
|
}, 90_000);
|
|
|
|
test('Node server build does not stub away the database', () => {
|
|
const script = readFileSync(path.resolve(import.meta.dir, '../scripts/build-node-server.sh'), 'utf8');
|
|
expect(script).not.toContain('const Database = null');
|
|
});
|
|
});
|