Skip to content

Automagically add default-browser UA/CH mitigations to sites in unprotected-temporary - #5490

Open
laghee wants to merge 3 commits into
mainfrom
kmc/unprotected-temporary-ua-ch-fba6
Open

laghee wants to merge 3 commits into
mainfrom
kmc/unprotected-temporary-ua-ch-fba6

Conversation

@laghee

@laghee laghee commented Jul 3, 2026

Copy link
Copy Markdown
Contributor

Asana Task/Github Issue: https://app.asana.com/1/137249556945/project/72649045549333/task/1215329534182321?focus=true

Description

In order to make unprotected-temporary more useful as a first-aid option, even beyond normal breakage rotations, I've added a mechanism to bundle user agent and client hints mitigations on the affected domain for whatever platform (or all, in the case of global) as well.

Feature change process:

  • I have added a schema to validate this feature change.
  • I have tested this change locally in all supported browsers by building locally and inspecting the files.
  • This code for the config change is ready to merge.
  • This feature was covered by a tech design.

@laghee
laghee requested review from a team as code owners July 3, 2026 17:55
@github-actions
github-actions Bot requested a review from jonathanKingston July 3, 2026 17:55
github-actions Bot pushed a commit that referenced this pull request Jul 3, 2026
@github-actions

github-actions Bot commented Jul 3, 2026

Copy link
Copy Markdown
Contributor

👋 Don't forget to add an individual reviewer (in addition to those auto-added), as this will create a task for them in Asana.

👉 Please mark this as DRAFT unless there's an intention to merge this immediately.
👉 Click "Merge when ready" if you're happy for this to be automatically merged once reviewed. (If not available, ensure you've signed in to DuckDuckGo oauth.)
👉 Don't forget to add schema changes to validate if you're adding/changing a feature.

@github-actions

github-actions Bot commented Jul 3, 2026 •

Copy link
Copy Markdown
Contributor

Generated file outputs:

Time updated: Tue, 07 Jul 2026 14:09:32 GMT

legacy
21 files identical
  • trackers-unprotected-temporary.txt
  • v3/extension-brave-config.json
  • v3/extension-bravemv3-config.json
  • v3/extension-chrome-config.json
  • v3/extension-chromemv3-config.json
  • v3/extension-config.json
  • v3/extension-edg-config.json
  • v3/extension-edge-config.json
  • v3/extension-edgmv3-config.json
  • v3/extension-firefox-config.json
  • v3/extension-safarimv3-config.json
  • v4/extension-brave-config.json
  • v4/extension-bravemv3-config.json
  • v4/extension-chrome-config.json
  • v4/extension-chromemv3-config.json
  • v4/extension-config.json
  • v4/extension-edg-config.json
  • v4/extension-edge-config.json
  • v4/extension-edgmv3-config.json
  • v4/extension-firefox-config.json
  • v4/extension-safarimv3-config.json

⚠️ File is identical

2 files changed
  • v3/android-config.json
  • v4/android-config.json
--- v4/android-config.json (and 1 other files)
+++ v4/android-config.json
@@ -32696,8 +32696,16 @@
                     },
                     {
                         "domain": "www.audible.com",
                         "brand": "CHROME"
+                    },
+                    {
+                        "domain": "marvel.com",
+                        "brand": "CHROME"
+                    },
+                    {
+                        "domain": "noaprints.com",
+                        "brand": "CHROME"
                     }
                 ]
             },
             "state": "enabled",
v3/ios-config.json
--- v3/ios-config.json
+++ v3/ios-config.json
@@ -32036,8 +32036,16 @@
                     },
                     {
                         "domain": "hulu.com",
                         "reason": "https://github.com/duckduckgo/privacy-configuration/pull/5327"
+                    },
+                    {
+                        "domain": "marvel.com",
+                        "reason": "https://github.com/duckduckgo/privacy-configuration/issues/1194"
+                    },
+                    {
+                        "domain": "noaprints.com",
+                        "reason": "https://github.com/duckduckgo/privacy-configuration/pull/2143"
                     }
                 ],
                 "ddgDefaultSites": [
                     {
@@ -32263,8 +32271,16 @@
                     },
                     {
                         "domain": "hulu.com",
                         "reason": "https://github.com/duckduckgo/privacy-configuration/pull/5327"
+                    },
+                    {
+                        "domain": "marvel.com",
+                        "reason": "https://github.com/duckduckgo/privacy-configuration/issues/1194"
+                    },
+                    {
+                        "domain": "noaprints.com",
+                        "reason": "https://github.com/duckduckgo/privacy-configuration/pull/2143"
                     }
                 ],
                 "omitVersionSites": []
             },
2 files changed
  • v3/macos-config.json
  • v4/macos-config.json
--- v4/macos-config.json (and 1 other files)
+++ v4/macos-config.json
@@ -31234,8 +31234,16 @@
                     },
                     {
                         "domain": "hulu.com",
                         "reason": "https://github.com/duckduckgo/privacy-configuration/pull/5327"
+                    },
+                    {
+                        "domain": "marvel.com",
+                        "reason": "https://github.com/duckduckgo/privacy-configuration/issues/1194"
+                    },
+                    {
+                        "domain": "noaprints.com",
+                        "reason": "https://github.com/duckduckgo/privacy-configuration/pull/2143"
                     }
                 ],
                 "webViewDefault": [
                     {
v3/windows-config.json
--- v3/windows-config.json
+++ v3/windows-config.json
@@ -32545,8 +32545,16 @@
                     },
                     {
                         "domain": "www.smythstoys.com",
                         "brand": "Google Chrome"
+                    },
+                    {
+                        "domain": "marvel.com",
+                        "brand": "Google Chrome"
+                    },
+                    {
+                        "domain": "noaprints.com",
+                        "brand": "Google Chrome"
                     }
                 ]
             },
             "state": "enabled"
@@ -46208,18 +46216,9 @@
             "state": "disabled"
         },
         "uaChBrands": {
             "state": "enabled",
-            "exceptions": [
-                {
-                    "domain": "marvel.com",
-                    "reason": "https://github.com/duckduckgo/privacy-configuration/issues/1194"
-                },
-                {
-                    "domain": "noaprints.com",
-                    "reason": "https://github.com/duckduckgo/privacy-configuration/pull/2143"
-                }
-            ],
+            "exceptions": [],
             "settings": {
                 "conditionalChanges": [
                     {
                         "condition": {
@@ -46267,8 +46266,32 @@
                                 "path": "/brandName",
                                 "value": "Google Chrome"
                             }
                         ]
+                    },
+                    {
+                        "condition": {
+                            "domain": "marvel.com"
+                        },
+                        "patchSettings": [
+                            {
+                                "op": "add",
+                                "path": "/brandName",
+                                "value": "Google Chrome"
+                            }
+                        ]
+                    },
+                    {
+                        "condition": {
+                            "domain": "noaprints.com"
+                        },
+                        "patchSettings": [
+                            {
+                                "op": "add",
+                                "path": "/brandName",
+                                "value": "Google Chrome"
+                            }
+                        ]
                     }
                 ]
             }
         },
v4/ios-config.json
--- v4/ios-config.json
+++ v4/ios-config.json
@@ -31557,8 +31557,16 @@
                     },
                     {
                         "domain": "hulu.com",
                         "reason": "https://github.com/duckduckgo/privacy-configuration/pull/5327"
+                    },
+                    {
+                        "domain": "marvel.com",
+                        "reason": "https://github.com/duckduckgo/privacy-configuration/issues/1194"
+                    },
+                    {
+                        "domain": "noaprints.com",
+                        "reason": "https://github.com/duckduckgo/privacy-configuration/pull/2143"
                     }
                 ],
                 "ddgDefaultSites": [
                     {
@@ -31730,8 +31738,14 @@
                         "domain": "xvideos.com"
                     },
                     {
                         "domain": "hulu.com"
+                    },
+                    {
+                        "domain": "marvel.com"
+                    },
+                    {
+                        "domain": "noaprints.com"
                     }
                 ],
                 "omitVersionSites": []
             },
v4/windows-config.json
--- v4/windows-config.json
+++ v4/windows-config.json
@@ -32080,8 +32080,16 @@
                     },
                     {
                         "domain": "www.smythstoys.com",
                         "brand": "Google Chrome"
+                    },
+                    {
+                        "domain": "marvel.com",
+                        "brand": "Google Chrome"
+                    },
+                    {
+                        "domain": "noaprints.com",
+                        "brand": "Google Chrome"
                     }
                 ]
             },
             "state": "enabled"
@@ -45150,16 +45158,9 @@
             "state": "disabled"
         },
         "uaChBrands": {
             "state": "enabled",
-            "exceptions": [
-                {
-                    "domain": "marvel.com"
-                },
-                {
-                    "domain": "noaprints.com"
-                }
-            ],
+            "exceptions": [],
             "settings": {
                 "conditionalChanges": [
                     {
                         "condition": {
@@ -45207,8 +45208,32 @@
                                 "path": "/brandName",
                                 "value": "Google Chrome"
                             }
                         ]
+                    },
+                    {
+                        "condition": {
+                            "domain": "marvel.com"
+                        },
+                        "patchSettings": [
+                            {
+                                "op": "add",
+                                "path": "/brandName",
+                                "value": "Google Chrome"
+                            }
+                        ]
+                    },
+                    {
+                        "condition": {
+                            "domain": "noaprints.com"
+                        },
+                        "patchSettings": [
+                            {
+                                "op": "add",
+                                "path": "/brandName",
+                                "value": "Google Chrome"
+                            }
+                        ]
                     }
                 ]
             }
         },
latest
v5/android-config.json
--- v5/android-config.json
+++ v5/android-config.json
@@ -32696,8 +32696,16 @@
                     },
                     {
                         "domain": "www.audible.com",
                         "brand": "CHROME"
+                    },
+                    {
+                        "domain": "marvel.com",
+                        "brand": "CHROME"
+                    },
+                    {
+                        "domain": "noaprints.com",
+                        "brand": "CHROME"
                     }
                 ]
             },
             "state": "enabled",
10 files identical
  • v5/extension-brave-config.json
  • v5/extension-bravemv3-config.json
  • v5/extension-chrome-config.json
  • v5/extension-chromemv3-config.json
  • v5/extension-config.json
  • v5/extension-edg-config.json
  • v5/extension-edge-config.json
  • v5/extension-edgmv3-config.json
  • v5/extension-firefox-config.json
  • v5/extension-safarimv3-config.json

⚠️ File is identical

v5/ios-config.json
--- v5/ios-config.json
+++ v5/ios-config.json
@@ -31557,8 +31557,16 @@
                     },
                     {
                         "domain": "hulu.com",
                         "reason": "https://github.com/duckduckgo/privacy-configuration/pull/5327"
+                    },
+                    {
+                        "domain": "marvel.com",
+                        "reason": "https://github.com/duckduckgo/privacy-configuration/issues/1194"
+                    },
+                    {
+                        "domain": "noaprints.com",
+                        "reason": "https://github.com/duckduckgo/privacy-configuration/pull/2143"
                     }
                 ],
                 "ddgDefaultSites": [
                     {
@@ -31730,8 +31738,14 @@
                         "domain": "xvideos.com"
                     },
                     {
                         "domain": "hulu.com"
+                    },
+                    {
+                        "domain": "marvel.com"
+                    },
+                    {
+                        "domain": "noaprints.com"
                     }
                 ],
                 "omitVersionSites": []
             },
v5/macos-config.json
--- v5/macos-config.json
+++ v5/macos-config.json
@@ -31234,8 +31234,16 @@
                     },
                     {
                         "domain": "hulu.com",
                         "reason": "https://github.com/duckduckgo/privacy-configuration/pull/5327"
+                    },
+                    {
+                        "domain": "marvel.com",
+                        "reason": "https://github.com/duckduckgo/privacy-configuration/issues/1194"
+                    },
+                    {
+                        "domain": "noaprints.com",
+                        "reason": "https://github.com/duckduckgo/privacy-configuration/pull/2143"
                     }
                 ],
                 "webViewDefault": [
                     {
v5/windows-config.json
--- v5/windows-config.json
+++ v5/windows-config.json
@@ -32080,8 +32080,16 @@
                     },
                     {
                         "domain": "www.smythstoys.com",
                         "brand": "Google Chrome"
+                    },
+                    {
+                        "domain": "marvel.com",
+                        "brand": "Google Chrome"
+                    },
+                    {
+                        "domain": "noaprints.com",
+                        "brand": "Google Chrome"
                     }
                 ]
             },
             "state": "enabled"
@@ -45150,16 +45158,9 @@
             "state": "disabled"
         },
         "uaChBrands": {
             "state": "enabled",
-            "exceptions": [
-                {
-                    "domain": "marvel.com"
-                },
-                {
-                    "domain": "noaprints.com"
-                }
-            ],
+            "exceptions": [],
             "settings": {
                 "conditionalChanges": [
                     {
                         "condition": {
@@ -45207,8 +45208,32 @@
                                 "path": "/brandName",
                                 "value": "Google Chrome"
                             }
                         ]
+                    },
+                    {
+                        "condition": {
+                            "domain": "marvel.com"
+                        },
+                        "patchSettings": [
+                            {
+                                "op": "add",
+                                "path": "/brandName",
+                                "value": "Google Chrome"
+                            }
+                        ]
+                    },
+                    {
+                        "condition": {
+                            "domain": "noaprints.com"
+                        },
+                        "patchSettings": [
+                            {
+                                "op": "add",
+                                "path": "/brandName",
+                                "value": "Google Chrome"
+                            }
+                        ]
                     }
                 ]
             }
         },

@daxtheduck

daxtheduck commented Jul 3, 2026 •

Copy link
Copy Markdown
Contributor

JSON approval analysis:

Time updated: Tue, 07 Jul 2026 14:09:38 GMT

legacy

✅ Auto-Approved Files

  • v3/ios-config.json (8 changes)
  • v3/macos-config.json (4 changes)
  • v4/ios-config.json (6 changes)
  • v4/macos-config.json (4 changes)

❌ Manual Review Required

  • v3/android-config.json (4 total changes)
    Disallowed paths that require review:
    • /features/clientBrandHint/settings/domains/3/brand (add)
    • /features/clientBrandHint/settings/domains/3/domain (add)
    • /features/clientBrandHint/settings/domains/2/brand (add)
    • /features/clientBrandHint/settings/domains/2/domain (add)
  • v3/windows-config.json (10 total changes)
    Disallowed paths that require review:
    • /features/uaChBrands/settings/conditionalChanges/5/condition (add)
    • /features/uaChBrands/settings/conditionalChanges/5/patchSettings (add)
    • /features/uaChBrands/settings/conditionalChanges/4/condition (add)
    • /features/uaChBrands/settings/conditionalChanges/4/patchSettings (add)
    • /features/uaChBrands/exceptions/1 (replace)
    • /features/uaChBrands/exceptions/0 (replace)
    • /features/clientBrandHint/settings/domains/10/brand (add)
    • /features/clientBrandHint/settings/domains/10/domain (add)
    • /features/clientBrandHint/settings/domains/9/brand (add)
    • /features/clientBrandHint/settings/domains/9/domain (add)
  • v4/android-config.json (4 total changes)
    Disallowed paths that require review:
    • /features/clientBrandHint/settings/domains/3/brand (add)
    • /features/clientBrandHint/settings/domains/3/domain (add)
    • /features/clientBrandHint/settings/domains/2/brand (add)
    • /features/clientBrandHint/settings/domains/2/domain (add)
  • v4/windows-config.json (10 total changes)
    Disallowed paths that require review:
    • /features/uaChBrands/settings/conditionalChanges/5/condition (add)
    • /features/uaChBrands/settings/conditionalChanges/5/patchSettings (add)
    • /features/uaChBrands/settings/conditionalChanges/4/condition (add)
    • /features/uaChBrands/settings/conditionalChanges/4/patchSettings (add)
    • /features/uaChBrands/exceptions/1 (replace)
    • /features/uaChBrands/exceptions/0 (replace)
    • /features/clientBrandHint/settings/domains/10/brand (add)
    • /features/clientBrandHint/settings/domains/10/domain (add)
    • /features/clientBrandHint/settings/domains/9/brand (add)
    • /features/clientBrandHint/settings/domains/9/domain (add)
latest

✅ Auto-Approved Files

  • v5/ios-config.json (6 changes)
  • v5/macos-config.json (4 changes)

❌ Manual Review Required

  • v5/android-config.json (4 total changes)
    Disallowed paths that require review:
    • /features/clientBrandHint/settings/domains/3/brand (add)
    • /features/clientBrandHint/settings/domains/3/domain (add)
    • /features/clientBrandHint/settings/domains/2/brand (add)
    • /features/clientBrandHint/settings/domains/2/domain (add)
  • v5/windows-config.json (10 total changes)
    Disallowed paths that require review:
    • /features/uaChBrands/settings/conditionalChanges/5/condition (add)
    • /features/uaChBrands/settings/conditionalChanges/5/patchSettings (add)
    • /features/uaChBrands/settings/conditionalChanges/4/condition (add)
    • /features/uaChBrands/settings/conditionalChanges/4/patchSettings (add)
    • /features/uaChBrands/exceptions/1 (replace)
    • /features/uaChBrands/exceptions/0 (replace)
    • /features/clientBrandHint/settings/domains/10/brand (add)
    • /features/clientBrandHint/settings/domains/10/domain (add)
    • /features/clientBrandHint/settings/domains/9/brand (add)
    • /features/clientBrandHint/settings/domains/9/domain (add)

🎯 OVERALL APPROVAL STATUS

❌ MANUAL REVIEW REQUIRED

Comment thread index.js
}
}

addUnprotectedTemporaryUserAgentMitigations(platform, platformConfig, [

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should this be part of the same if statement above?

        if (platformOverride.unprotectedTemporary) {

Comment thread util.js
Comment on lines +231 to +242
const customUserAgentSettings = config.features.customUserAgent?.settings;
if (platform === 'ios') {
appendMissingDomainEntries(customUserAgentSettings?.ddgFixedSites, exceptions, (entry) => ({ ...entry }));
appendMissingDomainEntries(customUserAgentSettings?.omitApplicationSites, exceptions, (entry) => ({ ...entry }));
} else if (platform === 'macos') {
appendMissingDomainEntries(customUserAgentSettings?.defaultSites, exceptions, (entry) => ({ ...entry }));
} else if (platform === 'android') {
addClientBrandHintDomains(config, exceptions, 'CHROME');
} else if (platform === 'windows') {
addClientBrandHintDomains(config, exceptions, 'Google Chrome');
addWindowsUaChBrands(config, exceptions);
}

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This does seem correct.

Are you able to add an unprotected, temporary demo your domain to a follow-up PR that's based off this one, and create a draft PR, and then validate the output? (perhaps even in the client too)

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants