Skip to content
TORNLIFE More

Tampermonkey Attack Log Script

Started by KatasTrophy [2187384] on in Tools & Userscripts.

9 replies · 375 views · thread synced · 4 days ago · View on torn.com
About this thread

Posts archived: 10 / 10 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Counted by TornLife from the archived posts.

Archived posts
10
Discussion span
→
People posting
5
Likes on archived posts
3
Authority score
50 / 100
Historical score
21 / 100
Story score
30 / 100
Engagement score
56 / 100

Most-liked replies

KatasTrophy [2187384]
I made a script from the API PHP example to list user i have previously attacked and I can use the respect_gain to display target that gives me high respect like >= 3. I tested it on my Laptop is works but i want it to run a the blacklist page, that mean I have to make in JavaScript, which i did and it work on my laptop.

With my rookie idea on JavaScript am able to add something below the blacklist page. but when I tested the real code it doesn't work with error

Refused to connect to 'https://api.torn.com/user/2187384?selections=attacks&key=[API key removed]' because it violates the following Content Security Policy directive: "connect-src 'self' wss://*.torn.com wss://*.torncity.com".

Am i making API ajax call the wrong way

[image: i.imgur.com]

[image: i.imgur.com]
Sulsay [2173590] Tester
The Content Security Policy prevents you from running arbitrary javascript. This is meant to prevent malicious scripts doing harm in case of an XSS vulnerability. 

More info on the CSP: https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP

(Chrome) extensions are "trusted" (whereas injected javascript is not) and can therefor be used to work around the CSP. You could make a chrome extension (even if just for yourself) and load that in development mode to achieve your end goal.
Sulsay [2173590] Tester
It doesn’t matter where you host your javascript. Simply trying to execute any script that isn’t explicitly whitelisted in the CSP will fail.

I believe there are two exceptions: using an extension like I mentioned in my previous post; and using a grease/tampermonkey script. I am not sure about the latter, maybe someone who offers userscripts can confirm. 

I ran into the same issue making ArsonWarehouse, for which I chose to use a chrome extension rather than a grease/tampermonkey script in favor of a more “integrated” user experience. Making an extension isn’t that hard, maybe explore that option?
LordBusiness [2052465]
If you host it on a server as a Node.JS application, you don't have any CSP problems.

And TBH, if the OP is the only one using the script he is making, he can simply disable CSP on his browser (Firefox about:config, or Chrome flags)