| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
fix(config): default the behaviour-changing anti-bot knobs to opt-in Four defaults changed so an existing install behaves exactly as it does today on every path. The machinery is unchanged and one env var away. WIGOLO_PROXY_BYPASS_ON_CHALLENGE true -> false Silently retrying direct defeats a proxy the operator deliberately configured and leaks their real IP to the origin. That is a consent decision, not an optimization, and no escalation logic makes it safe to inherit. WIGOLO_CRAWL_COOLDOWN_MAX_MS 300000 -> 30000 A crawl hitting repeated 403/429 backed off to five minutes per request, which is indistinguishable from a hang. Raise it deliberately for a domain worth waiting on. WIGOLO_BROWSER_CHANNEL auto -> chromium Defaulting to the host's installed browser makes rendering vary per machine for no measured gain — the levers that decide a bot-wall outcome measured as classifier + IP, not browser identity. WIGOLO_STEALTH_DRIVER auto -> playwright The decisive one. launchDedicatedStealthBrowser resolves the launcher ONCE and every launch site uses it — the only try/catch falls back from channel:'chrome' to bundled through the SAME launcher. Nothing ever falls back to the standard driver, and resolveStealthLauncher only verifies the module imports, never that it can launch. The hardened driver resolves a Chromium revision it neither installs nor owns; today both packages want rev 1223 and are exact-pinned, but no test or CI check asserts that alignment. A playwright bump without a matching patchright bump would silently break every anti-bot fetch, with no fallback. All four remain reachable: WIGOLO_*=true/auto. WIGOLO_HARDCORE still flips channel and driver to their aggressive values, which is the right home for them. The missing launch-time fallback is a real latent bug and wants its own fix; defaulting off removes the exposure meanwhile. Tests that exercise these paths now opt in explicitly rather than inheriting, so each one states the behaviour it depends on. | 2 个月前 | |
fix(config): default humanize + autoPass to off, completing the opt-in posture WIGOLO_HUMANIZE auto -> off WIGOLO_AUTO_PASS auto -> off Both rungs are reactive — they only run once a fetch has already hit a challenge, so neither ever slowed a successful fetch. But both added time to a fetch that ends up blocked anyway, and neither has a measured win: behavioural interaction did not change a wall outcome in this project's own testing (passive render sufficed), and the auto-pass gesture has never converted a block into a pass on a live target. With these off, an existing install now behaves as it did before on the FAILURE path too, not just the happy path. Measured on glassdoor, cache-busted, same blocked_by_challenge verdict throughout: origin/main 15.5s this PR as submitted 226.0s after the widget-probe fix 19.3s now 2.7s Faster than the baseline, because the vendor-agnostic wall-shape rule recognises the wall at the HTTP tier and skips a browser escalation that was never going to clear it. Happy path unchanged: wikipedia 1.7s via method=http. Unknown values now normalize to 'off' rather than 'auto', so a typo can no longer silently enable a rung. WIGOLO_HARDCORE still flips both to 'on' — that preset is the right home for the aggressive posture. Tests that exercise either rung now enable it explicitly and clean the env up after, so no test inherits a default it depends on. | 2 个月前 | |
feat(config): keychain-backed credential model for proxy/solver/reader URLs Split inline user:pass from proxy/solver/reader URLs into the OS keychain on the write path; keep only the credential-free host in config.json. Refuse a hand-edited config.json's inline userinfo on the read path (strip + warn). Recompose at resolve time from bare URL + keychain userinfo. Add solverUrl / hostedReaderUrl config fields (off unless set) and TUI wizard fields covering both init paths. | 2 个月前 | |
feat(config): keychain-backed credential model for proxy/solver/reader URLs Split inline user:pass from proxy/solver/reader URLs into the OS keychain on the write path; keep only the credential-free host in config.json. Refuse a hand-edited config.json's inline userinfo on the read path (strip + warn). Recompose at resolve time from bare URL + keychain userinfo. Add solverUrl / hostedReaderUrl config fields (off unless set) and TUI wizard fields covering both init paths. | 2 个月前 | |
feat: opt-in Reddit OAuth-API fetch path (credential-gated escape hatch) reddit.com blocks wigolo at the IP-reputation edge; the sanctioned reliable path is the OAuth API. When Reddit app credentials are configured AND the URL is a Reddit URL, fetch via oauth.reddit.com and map the JSON to the fetch result (fetch_method='reddit-api'). Credentials absent falls through to the normal ladder (which honestly hits the block) — never a hard requirement. - src/fetch/reddit-api.ts: isRedditUrl, URL->endpoint mapper, app-only token manager (cached + refreshed), JSON->RawFetchResult mapping, SSRF-guarded fixed-host egress, Retry-After/429 handling. - src/config.ts: redditClientId / redditClientSecret (keychain-backed) / redditUserAgent knobs + redditApiConfigured() helper. - src/persisted-config.ts: redditClientSecret added to secrets denylist. - src/fetch/router.ts: early credential-gated Reddit routing, degrades to the normal ladder on unsupported shape / token failure / rate limit. - src/types.ts: FetchMethod + RawFetchResult.method gain 'reddit-api'. | 2 个月前 |
| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
| 2 个月前 | ||
| 2 个月前 | ||
| 2 个月前 | ||
| 2 个月前 | ||
| 2 个月前 |