Rule proposal: form-prefill-sanitize — extend checkout-checkbox-sanitize to text/email/select prefills
Maintainer thường phản hồi trong vòng 3 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 38/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Ít trao đổi
- Công nghệ
- typescript
Hướng nghiên cứu
Start by reading the existing checkout-checkbox-sanitize and cart-addon-annotate rules and reuse their checkout URL gate. Define the new rule around DOMContentLoaded, the listed control types, hidden-input allowlist and denylist, focus checks, select field restrictions, and host kill-switch; done means covered behavior is tested without touching protected fields or non-checkout forms.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Category
New defense rule (extension of the checkout-checkbox-sanitize family)
What problem does this solve?
checkout-checkbox-sanitize clears pre-checked checkboxes on checkout pages so the agent doesn't inherit silent opt-ins. The same dark pattern — Mathur et al.'s Preselection — exists for non-checkbox inputs:
- Pre-populated
<select>defaults that pick the costliest shipping speed - Pre-filled hidden inputs carrying affiliate / referral / promo IDs that bias pricing or attribution
- Pre-filled email/phone fields nudging the user toward marketing signup
- Pre-selected radio defaults on tipping prompts ("18% / 20% / 22% / Custom" with 22% pre-checked)
The agent is then expected to re-select what it actually wants, same contract as the existing checkbox rule.
Proposed solution
On the same checkout-shaped URL gate, walk form controls and:
- Clear pre-populated
<input type="text|email|tel|number">values when the page state suggests pre-fill (value present without user input — detectable on initial DOM). - Reset
<select>to its first option (or a blank option if one exists) when the default differs from the natural-first choice. - Reset
<input type="radio">groups to unchecked when a default is server-supplied. - Clear
valueon<input type="hidden">whosenamematches a curated affiliate/referral/promo pattern (*aff*,*ref*,*promo*,*utm_*,coupon_id,discount_code) — but only on payment/order pages.
Out of scope for v1: role="textbox" / contenteditable widgets, complex date pickers, anything inside a payment-processor iframe.
Alternatives considered
- Bundle into
checkout-checkbox-sanitizeinstead of a new rule. Reasonable; the toggle becomes a bigger hammer. Splitting keeps user control finer-grained because text-field clearing has higher FP risk than checkbox clearing. - Synthetic blur/change event after clearing. Some sites recalc totals on input events; consider v2 if sites silently re-prefill on
inputwithout it.
Controlling false positives
- Strict URL gate. Payment/order paths only (
/cart,/checkout,/basket,/bag,/payment,/order) — never login or arbitrary forms. Reuse the exact gate ofcart-addon-annotateandcheckout-checkbox-sanitizeso the surface is identical to a rule that's already in production. - Hard denylist for safety-critical hidden inputs. Never clear
<input type="hidden">whosenamematches CSRF/cart/session shapes:_csrf,csrf_token,authenticity_token,cart_id,order_id,session*,nonce,state,_token, anything containingsignature. Failure mode here is the form silently rejecting submit, which is worse than the original dark pattern. - Allowlist for hidden-input clearing. Only clear hidden inputs whose
namematches the affiliate/promo pattern set above. Anything outside the allowlist is preserved. <select>: only reset when the default value is NOT the first option. If the first option is selected (natural default — common pattern is<option value="">Select…</option>or<option>Standard shipping</option>first), the rule does nothing. Avoids clobbering legitimate first-option defaults.- Timing. Run on
DOMContentLoaded, before browser autofill. Browser autofill that runs after the rule is preserved — meaning the user's password manager and saved addresses still work for inputs the rule has already cleared. Document the ordering explicitly so the contract is clear. - Geofencing-aware select defaults. Country/state preselection based on geo is usually legitimate. Mitigation: only reset
<select>when the default deviates from the first option AND the field name is in a sneaking-prone set (shipping speed, tip percent, delivery slot, donation amount, insurance plan). Don't touch country/state/region selects. - Per-host kill-switch. Loyalty-program checkouts where saved details reappear by design (Amazon 1-Click, Apple Pay flows) can be denylisted by host. These flows are the user's intent.
- No-op on inputs the user has actually focused. If
document.activeElementor:focus-visiblematched a field at any point, skip clearing it on rescan. - Graceful-failure mode. The worst user-facing outcome is "I need to retype" — recoverable. Document this so a user can clearly attribute the friction to the rule and toggle it off.
Prior art / references
- Mathur et al. (CSCW 2019), Dark Patterns at Scale. — Preselection category; already cited.
- Brignull, deceptive.design — Preselection.
- WHATWG HTML autocomplete attribute spec — informs which fields are legitimate autofill targets vs. server-pushed prefills.
- Adjacent OSS: Consent-O-Matic sets values to opt out on consent forms — same mechanic, different intent.
Tagged Impact L–M / Complexity M.
- Ngôn ngữ chính
- TypeScript
- Star
- 34
- Fork
- 3
- Merge trung bình
- 3 ngày 3 giờ
- Pull request đã merge (30 ngày)
- 35
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của pixiebrix/agent-browser-shield
-
enhancement question
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 30/100
pixiebrix/agent-browser-shield#178 ·
Maintainer thường phản hồi trong vòng 3 ngày
-
Rule proposal: canvas-text-annotate — flag canvas/video text surfaces invisible to DOM walkersĐang mởenhancement rule-proposal
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 28/100
pixiebrix/agent-browser-shield#123 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 3 ngày
-
enhancement rule-proposal
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
pixiebrix/agent-browser-shield#122 ·
Maintainer thường phản hồi trong vòng 3 ngày
-
enhancement rule-proposal
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
pixiebrix/agent-browser-shield#120 ·
Maintainer thường phản hồi trong vòng 3 ngày
Tất cả issue của pixiebrix/agent-browser-shield
Issue tương tự
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 82/100
siyuan-note/siyuan#20313 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 92/100
alunduil/projects-v2-sync#14 ·
-
Service process inherits the caller's cwd at first use, holding that folder open on Windows (EBUSY)Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
-
DevTools page styles leak into the host app in developmentCó thể đã có người làm @onmax đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
nuxt-modules/better-auth#567 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày