Files
AshfaqandNatasha Gorshunova ae0aaef884 fix: reject --blockedUrlPattern/--allowedUrlPattern hostname regexp groups (#2796)
## Problem

`--blockedUrlPattern`/`--allowedUrlPattern` accept any URLPattern
string, including hostnames that use a regexp group (for example
`*://(127\.\d+\.\d+\.\d+):*/*`, meant to cover a whole IP range). That
pattern is enforced correctly by the target-attach check
(`TargetManager#isUrlAllowed`, using the real `URLPattern.test()`), but
the actual network-level blocking runs through the CDP command
`Network.emulateNetworkConditionsByRule`, passing the raw pattern string
as `NetworkConditions.urlPattern`. That command's native matching does
not apply the pattern consistently on redirects, so a page allowed to
load can redirect straight through a blocked host range while an
exact-hostname pattern stays blocked in both cases.

Root-caused and written up in more detail on #2777.

This isn't something fixable from this repo's side (the mismatch is
between the documented CDP `urlPattern` semantics and the underlying
Chromium implementation for `emulateNetworkConditionsByRule`, not in
`puppeteer-core` or `chrome-devtools-mcp`), so instead of leaving the
gap silent, this rejects patterns this repo can't currently guarantee
are enforced.

## Fix

- Added `findUnenforceableHostnamePattern` (`src/utils/url.ts`), which
parses each pattern with `URLPattern` and flags one whose canonicalized
`hostname` contains a regexp group (`(`). Wildcard (`*`) and named-group
(`:name`) hostnames are unaffected and continue to work as before; a
regexp group outside the hostname (e.g. in the pathname) is also left
alone, since only the hostname case is demonstrated as broken.
- Wired it into the `blockedUrlPattern`/`allowedUrlPattern` CLI option
`coerce`, so an offending pattern fails fast at startup with a clear
error instead of silently only half-working.
- Updated both options' `describe` text and regenerated
`docs/configuration.md` via `npm run gen`.

## Testing

- Added unit tests in `tests/utils/url.test.ts` covering: a hostname
regexp group (flagged), multiple patterns (first offender returned), an
exact hostname, a wildcard hostname, a named-group hostname, a regexp
group outside the hostname, and a pattern that fails to construct.
- `npx tsc` and `npx eslint` both pass clean on the changed files.
- Verified the new function's behavior against Puppeteer's own vendored
`URLPattern` polyfill
(`node_modules/puppeteer-core/lib/third_party/urlpattern-polyfill`),
matching every case in the new test suite - my local Node (22.22)
predates Node's global `URLPattern` support that this repo's `.nvmrc`
(v24) assumes, so I couldn't run the built test file directly against
the global here, but the polyfill is the same spec implementation and
gave identical results for all cases.

Fixes #2777

---------

Co-authored-by: Natasha Gorshunova <47688881+nattallius@users.noreply.github.com>
2026-09-25 15:48:12 +00:00
..