如何在客户端阻止特定网站通过window.location跳转页面
解决方法
方法1:拦截window.location的跳转赋值
直接重写window.location的href属性 setter,当检测到要跳转到目标登录地址时阻止赋值:
// ==UserScript== // @name 阻止登录重定向 // @namespace http://tampermonkey.net/ // @version 0.1 // @match 你的目标网站域名/* // @run-at document-start // @grant none // ==/UserScript== (function() { 'use strict'; const targetUrl = '/Security/Authentication/UserLogin'; const originalLocation = Object.getOwnPropertyDescriptor(window, 'location'); Object.defineProperty(window, 'location', { set: function(newUrl) { if (typeof newUrl === 'string' && newUrl === targetUrl) { console.log('阻止了重定向:', newUrl); return; } originalLocation.set.call(this, newUrl); }, get: originalLocation.get, configurable: true }); })();
这个方法在页面脚本执行前就生效,直接拦截跳转动作,不管触发逻辑是什么,都能拦下目标地址的跳转。
方法2:解绑或覆盖jQuery的ajaxComplete事件
因为网站用的是jQuery绑定ajaxComplete,可以从事件绑定环节入手阻止跳转逻辑生效:
方式A:解绑已绑定的事件
// ==UserScript== // @name 解绑ajaxComplete重定向事件 // @namespace http://tampermonkey.net/ // @version 0.1 // @match 你的目标网站域名/* // @run-at document-idle // @grant none // ==/UserScript== (function() { 'use strict'; // 解绑document上的所有ajaxComplete事件 $(document).off('ajaxComplete'); // 若需要保留其他ajaxComplete事件,可自行补充重新绑定逻辑 })();
注意要设置@run-at document-idle,确保网站的内联脚本已经执行完毕再执行解绑操作。
方式B:提前覆盖$.ajaxComplete,阻止目标事件绑定
// ==UserScript== // @name 阻止ajaxComplete事件绑定 // @namespace http://tampermonkey.net/ // @version 0.1 // @match 你的目标网站域名/* // @run-at document-start // @grant none // ==/UserScript== (function() { 'use strict'; // 保存原始的ajaxComplete方法 const originalAjaxComplete = $.ajaxComplete; $.ajaxComplete = function(callback) { // 检查回调函数内容,过滤目标重定向逻辑 const callbackStr = callback.toString(); if (callbackStr.includes('window.location = \'/Security/Authentication/UserLogin\'') || callbackStr.includes('8ba7aa83-447f-4e1f-b9fa-380e514f2140')) { console.log('阻止了目标ajaxComplete事件绑定'); return this; } // 其他回调正常执行原始逻辑 return originalAjaxComplete.call(this, callback); }; })();
这个方法在页面加载初期就覆盖jQuery的方法,当网站脚本调用$(document).ajaxComplete时,会自动过滤掉触发重定向的回调。
方法3:修改AJAX响应的状态和内容
从根源上让触发跳转的条件不成立,拦截AJAX请求并修改返回的状态码或响应文本:
// ==UserScript== // @name 修改AJAX响应避免重定向 // @namespace http://tampermonkey.net/ // @version 0.1 // @match 你的目标网站域名/* // @run-at document-start // @grant none // ==/UserScript== (function() { 'use strict'; const originalXhrOpen = XMLHttpRequest.prototype.open; XMLHttpRequest.prototype.open = function(method, url) { const originalOnLoad = this.onload; this.onload = function() { // 修改601状态码为200,避免触发跳转判断 if (this.status === 601) { Object.defineProperty(this, 'status', { value: 200 }); } // 移除响应文本中的特定UUID if (this.responseText.includes('8ba7aa83-447f-4e1f-b9fa-380e514f2140')) { Object.defineProperty(this, 'responseText', { value: this.responseText.replace('8ba7aa83-447f-4e1f-b9fa-380e514f2140', '') }); } if (originalOnLoad) originalOnLoad.call(this); }; originalXhrOpen.call(this, method, url); }; })();
网站的脚本检测不到601状态或指定UUID,自然不会执行跳转逻辑。
内容的提问来源于stack exchange,提问作者Chaudry SAM
相关产品推荐
相关产品推荐

