Bookmarklet to append a string to a URL

Viewed 327

I tried to insert a link at the beginning of a URL in Chrome using a bookmark. I want the URL to change from:

https://raw.githubusercontent.com/kguidonimartins/csv_example/master/1946_proposicoes.csv

To:

chrome-extension://ibfcfelnbfhlbpelldnngdcklnndhael/viewer.html?url=https://raw.githubusercontent.com/kguidonimartins/csv_example/master/1946_proposicoes.csv

I put this in the URL field of a bookmark:

javascript:location=location.href.replace(location,"chrome-extension://ibfcfelnbfhlbpelldnngdcklnndhael/viewer.html?url=" + location)

But that failed. Then, I tried this:

javascript:(function(){window.open('chrome-extension://ibfcfelnbfhlbpelldnngdcklnndhael/viewer.html?url='+encodeURIComponent(location.href));})();

And that also failed.

Any idea how to solve this?

2 Answers

Try this code:

javascript:(function() {
    location.href = "chrome-extension://ibfcfelnbfhlbpelldnngdcklnndhael/viewer.html?url=" + location.href;
})();

You got the error

Blocked script execution in 'https://raw.githubusercontent.com/kguidonimartins/csv_example/master/1946_proposicoes.csv' because the document's frame is sandboxed and the 'allow-scripts' permission is not set.

I bumped into this error as well (for a different GitHub URL), and had a look at the HTTP headers that are being served which match very well with the headers returned from my URL:

# curl -s -D - -o /dev/null https://raw.githubusercontent.com/kguidonimartins/csv_example/master/1946_proposicoes.csv
HTTP/2 404 
content-security-policy: default-src 'none'; style-src 'unsafe-inline'; sandbox
strict-transport-security: max-age=31536000
x-content-type-options: nosniff
x-frame-options: deny
x-xss-protection: 1; mode=block
content-type: text/plain; charset=utf-8
x-github-request-id: 7CFE:2788:FC6BD:193830:6235F1EF
accept-ranges: bytes
date: Sat, 19 Mar 2022 15:08:54 GMT
via: 1.1 varnish
x-served-by: cache-ams21046-AMS
x-cache: HIT
x-cache-hits: 1
x-timer: S1647702535.805381,VS0,VE0
vary: Authorization,Accept-Encoding,Origin
access-control-allow-origin: *
x-fastly-request-id: a7f167928977f2bff7a2d78679aa13f287777567
expires: Sat, 19 Mar 2022 15:13:54 GMT
source-age: 23
content-length: 14

The cause of the error you see is in the first header:

content-security-policy: default-src 'none'; style-src 'unsafe-inline'; sandbox

It is documented in MDN Web Docs on at CSP: Sandbox:

The HTTP Content-Security-Policy (CSP) sandbox directive enables a sandbox for the requested resource similar to the <iframe> sandbox attribute. It applies restrictions to a page's actions including preventing popups, preventing the execution of plugins and scripts, and enforcing a same-origin policy.

By not returning a value for sandbox, GitHub tells Chrome that the served page cannot run any scripts. This means that scripts by Bookmarklets are excluded.

I did try finding a setting to workaround this in all the URLs mentioned at List of Chrome URLs and their purpose - gHacks Tech News, but could not find any.

I have not tried it yet, as I don't want a global risk in my Chrome session, but you might use the --flags --allow-scripts which for instance is suggested in an answer to javascript - is triggered for no reason in Chrome - Super User.

So I have to end with that now the cause is explained, but there is no real solution.

Related