mirror of
https://github.com/ChromeDevTools/chrome-devtools-mcp.git
synced 2026-09-28 03:12:57 +08:00
## Problem `--blockedUrlPattern`/`--allowedUrlPattern` accept any URLPattern string, including hostnames that use a regexp group (for example `*://(127\.\d+\.\d+\.\d+):*/*`, meant to cover a whole IP range). That pattern is enforced correctly by the target-attach check (`TargetManager#isUrlAllowed`, using the real `URLPattern.test()`), but the actual network-level blocking runs through the CDP command `Network.emulateNetworkConditionsByRule`, passing the raw pattern string as `NetworkConditions.urlPattern`. That command's native matching does not apply the pattern consistently on redirects, so a page allowed to load can redirect straight through a blocked host range while an exact-hostname pattern stays blocked in both cases. Root-caused and written up in more detail on #2777. This isn't something fixable from this repo's side (the mismatch is between the documented CDP `urlPattern` semantics and the underlying Chromium implementation for `emulateNetworkConditionsByRule`, not in `puppeteer-core` or `chrome-devtools-mcp`), so instead of leaving the gap silent, this rejects patterns this repo can't currently guarantee are enforced. ## Fix - Added `findUnenforceableHostnamePattern` (`src/utils/url.ts`), which parses each pattern with `URLPattern` and flags one whose canonicalized `hostname` contains a regexp group (`(`). Wildcard (`*`) and named-group (`:name`) hostnames are unaffected and continue to work as before; a regexp group outside the hostname (e.g. in the pathname) is also left alone, since only the hostname case is demonstrated as broken. - Wired it into the `blockedUrlPattern`/`allowedUrlPattern` CLI option `coerce`, so an offending pattern fails fast at startup with a clear error instead of silently only half-working. - Updated both options' `describe` text and regenerated `docs/configuration.md` via `npm run gen`. ## Testing - Added unit tests in `tests/utils/url.test.ts` covering: a hostname regexp group (flagged), multiple patterns (first offender returned), an exact hostname, a wildcard hostname, a named-group hostname, a regexp group outside the hostname, and a pattern that fails to construct. - `npx tsc` and `npx eslint` both pass clean on the changed files. - Verified the new function's behavior against Puppeteer's own vendored `URLPattern` polyfill (`node_modules/puppeteer-core/lib/third_party/urlpattern-polyfill`), matching every case in the new test suite - my local Node (22.22) predates Node's global `URLPattern` support that this repo's `.nvmrc` (v24) assumes, so I couldn't run the built test file directly against the global here, but the polyfill is the same spec implementation and gave identical results for all cases. Fixes #2777 --------- Co-authored-by: Natasha Gorshunova <47688881+nattallius@users.noreply.github.com>