Try and view the source
kurlak.com
kurlak.com
Not a problem at all.
In fact, I had to remember to go back to right clicking and View Source to try and figure out why this was so highly ranked and lots of the comments confused me.
Now I see why... but just like using JavaScript to try and detect right click, using replace state to try and obscure the source isn't likely to be effective in any reasonable way. I guess that's not the point, that this is more fun than anything someone will do, except... I bet someone does it on their live site.
I doubt it, as this method breaks forward/back functionality, thus probably breaking most sites.
Having said that, for all links, you could do a further re-write using the history API, before allowing the redirect to take place. I guess that would actually make it usable even if, as you say, it's futile in the end.
On Twitter if I'm viewing an individual tweet page, and then click onto the authors profile page, and then click "back" in my browser, I will not be redirected to a different page altogether like in the OP's demo.
You can also reproduce the behavior by navigating back, then forwards again - you'll see the "not that easily" page that way, as well (as the "try and view the source" page has been replaced in your history list).
If you try copying the URL to plain-text, you'll see: http://www.kurlak.com/john/%E2%80%AElmth.ecruos
Or alternatively, NoScript is the new lynx.
The problem shown in this example needs fixing in the browser, not by gutting the browser. This example just shows that "view source" should probably make it easier to get at the DOM-generated source. ("View Selection Source" or anything that shows the current DOM will work.)
http://citeomatic.com/_asdf.html
(This one only works in Firefox and Opera, not Chrome, sadly)
With httpfox I got
html:after { padding-left: 5px; content: 'Can you view my source from Firefox or Opera?'; }
Edit: It's also possible to view the source with Firefox JSview, Web Developer addons and curl.
HTTP/1.1 200 OK
Date: Mon, 19 Mar 2012 08:49:27 GMT
Server: Apache
Link: <_asdf.css>;rel="stylesheet";type="text/css";media="all"
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8 curl -v -H 'User-agent: Mozilla/5.0' 'http://www.kurlak.com/john/source.html'That said, pretty neat trick.
<html> <head> <title>Source</title> </head> <body> Can you view my source from Chrome or Firefox? </body> </html>
<html><head> <title>Source</title> <meta charset="UTF-8"> <script type="text/javascript"> history.replaceState(null, null, String.fromCharCode(8238) + 'lmth.ecruos'); </script> </head> <body> <p>Can you view my source from Chrome or Firefox?</p>
</body></html>
$ cat << ! | nc www.kurlak.com 80
> GET /john/source.html HTTP/1.1
> Host: www.kurlak.com
> User-Agent: Mozilla/5.0 Chrome/1
>
> !
HTTP/1.1 200 OK
Date: Mon, 19 Mar 2012 07:44:51 GMT
Server: Apache
Last-Modified: Mon, 19 Mar 2012 00:51:24 GMT
Accept-Ranges: bytes
Content-Length: 295
Content-Type: text/html
<!DOCTYPE html>This is on Firefox version 11.0. The creator of this page forgot the Firefox ecosystem has this nifty plug-in called NoScript.
<!DOCTYPE html> <html> <head> <title>Source</title> <meta charset="UTF-8"> <script type="text/javascript"> history.replaceState(null, null, 'source.html' + String.fromCharCode(8237)); </script> </head> <body> <p>Can you view my source from Chrome?</p> </body> </html>
Chrome is broken on my machine (proxy issues) so I didn't test there, but I assume the same technique would work.
<!DOCTYPE html> <html> <head> <title>Source</title> <meta charset="UTF-8"> <script type="text/javascript"> history.replaceState(null, null, String.fromCharCode(8238) + 'lmth.ecruos'); </script> </head> <body>
Can you view my source from Chrome or Firefox?</p> </body> </html>
Now what?
Great idea though.
Interesting hack nevertheless.
But otherwise, very clever.
most people i know view source this way
An appropriate representation of the requested resource /john/lmth.ecruos could not be found on this server.</p>
Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p> </body></html>