UX on "ClickFix" feature is hostile, user unfriendly #4110
Prerequisites
I tried to reproduce the issue when...
DescriptionThere is a "ClickFix" feature in uBlock Origin which attempts to prevent sites from covertly copying damaging shellscripts into the clipboard via JavaScript. For about an hour there this week— see uBlockOrigin/uAssets#34321 — this was triggering for all attempts to copy via JavaScript on all sites. The bug was fixed, but even with the fix the bug reveals deeper, outstanding issues with the design of this feature. When triggered, the feature looks like this:
As presentation to the user, this is unclear, inadequately helpful, and hostile in the case of a spurious trigger (which can still happen even in the "fixed" version). A specific URL where the issue occurs.https://imgbb.com/ (fixed) ( see https://github.com/uBlockOrigin/uAssets/discussions/27472#discussioncomment-18224466 )
(I continued seeing the problem sporadically on https://blacksky.community after the fix landed, but I haven't rebooted my browser.)Steps to ReproduceCheckout the version of UBO immediately before the fix for #34321 and follow the steps in #34321. Observed behaviorThe injected message, as shown above, is deficient in several ways:
Expected behaviorI think any of the following changes would be good, from least to most disruptive:
ConfigurationDetailsuBlock Origin: 1.73.0
Firefox: 140
filterset (summary):
network: 182921
cosmetic: 43691
scriptlet: 34791
html: 3780
listset (total-discarded, last-updated):
default:
user-filters: 8-0, never
ublock-filters: 54104-72, 45m Δ
ublock-badware: 10349-17, 45m Δ
ublock-privacy: 4129-2, 45m Δ
ublock-unbreak: 2866-1, 45m Δ
ublock-quick-fixes: 516-13, 45m Δ
easylist: 87190-142, 45m Δ
easyprivacy: 56480-44, 45m Δ
urlhaus-1: 47470-6, 45m
plowe-0: 3539-1041, 1d.6h.45m
filterset (user): [array of 8 redacted]
trustedset:
added: [array of 5 redacted]
userSettings: [none]
hiddenSettings: [none]
supportStats:
allReadyAfter: 269 ms (selfie)
maxAssetCacheWait: 92 ms
cacheBackend: indexedDB |
Replies: 3 comments 12 replies
|
Anyone is free to make PRs to the projects based on their ideas. This is community FOSS project. We are volunteers and we won't have time to adjust based on every single person's long essays of complaints. |
|
Any update on this? the "protection" feature is disruptive and impossible to disable. |
Theoretically, anyone with better English than mine can make a description on the draft Wiki: https://github.com/uBlockOrigin/uBlock-issues/wiki/_history I assume you could then do EOT. |

If it's a public site, just tell us so we can exclude that domain in the filter lists for other users as well. If no one wants to report the public websites and just come here to complain without details, nothing can be done.
If it's a private site, just turn uBO off or add
If you are using uBOL on that private site, set uBOL filtering mode in the popup slider to
Basic.But in general, you should not use uBO or any extensions in your private sites. uBO is not the suitable tool for that case.
Don't come here just to ask
Any update on this?after we said thatAnyone is free to make PRs to the projects based on their ideas.