"The more dedicated cheaters will hit the button API outside of the browser, which is pretty hard to stop"
How this would be accomplished, I guess from the command line ?
EDIT: found what Monkeypatch means.
It doesn't do anything to intercept people pushing the button.
window.setTimeout = function setTimeout(fn, ms) {
alert("No you don't, cheater!");
assign_button_color_of_shame();
original_setTimeout(fn, ms);
}This would be a really easy "security" measure to circumvent, though - I could literally just delete your monkey patch, for a start!
Though, you do raise a valid point, so let's see how it plays out.
setTimeout = function(){...}
delete setTimeout // true - you've removed the patch
window.setTimeout = function(){...}
delete window.setTimeout // true - you've removed the patch
window.constructor.prototype.setTimeout = function(){...}
delete window.constructor.prototype.setTimeout // false - the patch is still there!
I don't know about the hierarchy of the prototype chain up at this level but it seems to work.Maybe there's some other way of getting to the built-in setTimeout so you can create your own version to mask the one I added?
EDIT you can embed an iframe and rip the native setTimeout from there.
The only real way to detect this is through usage pattern analysis and detection on the web socket side, because if you can write something in JS that catches people, someone can make minor modifications to their code to make it work again.
I've found a way to get access to the original setTimeout again by embedding an iframe into the page and extracting it from there.
Would be interested in hearing other methods of getting a handle to the original setTimeout again.
I guess you could simulate it by using some other mechanism, say firing off an async request to a server that returns after a certain time and running a callback.