@@ -1,235 +0,0 @@
|
||||
/**
|
||||
* Browser cookie extraction for Twitter authentication.
|
||||
* Delegates to @steipete/sweet-cookie for Safari/Chrome/Firefox reads.
|
||||
*/
|
||||
|
||||
import { getCookies } from '@steipete/sweet-cookie';
|
||||
|
||||
export interface TwitterCookies {
|
||||
authToken: string | null;
|
||||
ct0: string | null;
|
||||
cookieHeader: string | null;
|
||||
source: string | null;
|
||||
}
|
||||
|
||||
export interface CookieExtractionResult {
|
||||
cookies: TwitterCookies;
|
||||
warnings: string[];
|
||||
}
|
||||
|
||||
export type CookieSource = 'safari' | 'chrome' | 'firefox';
|
||||
|
||||
const TWITTER_COOKIE_NAMES = ['auth_token', 'ct0'] as const;
|
||||
const TWITTER_URL = 'https://x.com/';
|
||||
const TWITTER_ORIGINS: string[] = ['https://x.com/', 'https://twitter.com/'];
|
||||
const DEFAULT_COOKIE_TIMEOUT_MS = 30_000;
|
||||
|
||||
function normalizeValue(value: unknown): string | null {
|
||||
if (typeof value !== 'string') {
|
||||
return null;
|
||||
}
|
||||
const trimmed = value.trim();
|
||||
return trimmed.length > 0 ? trimmed : null;
|
||||
}
|
||||
|
||||
function cookieHeader(authToken: string, ct0: string): string {
|
||||
return `auth_token=${authToken}; ct0=${ct0}`;
|
||||
}
|
||||
|
||||
function buildEmpty(): TwitterCookies {
|
||||
return { authToken: null, ct0: null, cookieHeader: null, source: null };
|
||||
}
|
||||
|
||||
function readEnvCookie(cookies: TwitterCookies, keys: readonly string[], field: 'authToken' | 'ct0'): void {
|
||||
if (cookies[field]) {
|
||||
return;
|
||||
}
|
||||
for (const key of keys) {
|
||||
const value = normalizeValue(process.env[key]);
|
||||
if (!value) {
|
||||
continue;
|
||||
}
|
||||
cookies[field] = value;
|
||||
if (!cookies.source) {
|
||||
cookies.source = `env ${key}`;
|
||||
}
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
function resolveSources(cookieSource?: CookieSource | CookieSource[]): CookieSource[] {
|
||||
if (Array.isArray(cookieSource)) {
|
||||
return cookieSource;
|
||||
}
|
||||
if (cookieSource) {
|
||||
return [cookieSource];
|
||||
}
|
||||
return ['safari', 'chrome', 'firefox'];
|
||||
}
|
||||
|
||||
function labelForSource(source: CookieSource, profile?: string): string {
|
||||
if (source === 'safari') {
|
||||
return 'Safari';
|
||||
}
|
||||
if (source === 'chrome') {
|
||||
return profile ? `Chrome profile "${profile}"` : 'Chrome default profile';
|
||||
}
|
||||
return profile ? `Firefox profile "${profile}"` : 'Firefox default profile';
|
||||
}
|
||||
|
||||
function pickCookieValue(
|
||||
cookies: Array<{ name?: string; value?: string; domain?: string }>,
|
||||
name: (typeof TWITTER_COOKIE_NAMES)[number],
|
||||
): string | null {
|
||||
const matches = cookies.filter((c) => c?.name === name && typeof c.value === 'string');
|
||||
if (matches.length === 0) {
|
||||
return null;
|
||||
}
|
||||
|
||||
const preferred = matches.find((c) => (c.domain ?? '').endsWith('x.com'));
|
||||
if (preferred?.value) {
|
||||
return preferred.value;
|
||||
}
|
||||
|
||||
const twitter = matches.find((c) => (c.domain ?? '').endsWith('twitter.com'));
|
||||
if (twitter?.value) {
|
||||
return twitter.value;
|
||||
}
|
||||
|
||||
return matches[0]?.value ?? null;
|
||||
}
|
||||
|
||||
async function readTwitterCookiesFromBrowser(options: {
|
||||
source: CookieSource;
|
||||
chromeProfile?: string;
|
||||
firefoxProfile?: string;
|
||||
cookieTimeoutMs?: number;
|
||||
}): Promise<CookieExtractionResult> {
|
||||
const warnings: string[] = [];
|
||||
const out = buildEmpty();
|
||||
|
||||
const { cookies, warnings: providerWarnings } = await getCookies({
|
||||
url: TWITTER_URL,
|
||||
origins: TWITTER_ORIGINS,
|
||||
names: [...TWITTER_COOKIE_NAMES],
|
||||
browsers: [options.source],
|
||||
mode: 'merge',
|
||||
chromeProfile: options.chromeProfile,
|
||||
firefoxProfile: options.firefoxProfile,
|
||||
timeoutMs: options.cookieTimeoutMs,
|
||||
});
|
||||
warnings.push(...providerWarnings);
|
||||
|
||||
const authToken = pickCookieValue(cookies, 'auth_token');
|
||||
const ct0 = pickCookieValue(cookies, 'ct0');
|
||||
if (authToken) {
|
||||
out.authToken = authToken;
|
||||
}
|
||||
if (ct0) {
|
||||
out.ct0 = ct0;
|
||||
}
|
||||
|
||||
if (out.authToken && out.ct0) {
|
||||
out.cookieHeader = cookieHeader(out.authToken, out.ct0);
|
||||
out.source = labelForSource(
|
||||
options.source,
|
||||
options.source === 'chrome' ? options.chromeProfile : options.firefoxProfile,
|
||||
);
|
||||
return { cookies: out, warnings };
|
||||
}
|
||||
|
||||
if (options.source === 'safari') {
|
||||
warnings.push('No Twitter cookies found in Safari. Make sure you are logged into x.com in Safari.');
|
||||
} else if (options.source === 'chrome') {
|
||||
warnings.push('No Twitter cookies found in Chrome. Make sure you are logged into x.com in Chrome.');
|
||||
} else {
|
||||
warnings.push(
|
||||
'No Twitter cookies found in Firefox. Make sure you are logged into x.com in Firefox and the profile exists.',
|
||||
);
|
||||
}
|
||||
|
||||
return { cookies: out, warnings };
|
||||
}
|
||||
|
||||
export async function extractCookiesFromSafari(): Promise<CookieExtractionResult> {
|
||||
return readTwitterCookiesFromBrowser({ source: 'safari' });
|
||||
}
|
||||
|
||||
export async function extractCookiesFromChrome(profile?: string): Promise<CookieExtractionResult> {
|
||||
return readTwitterCookiesFromBrowser({ source: 'chrome', chromeProfile: profile });
|
||||
}
|
||||
|
||||
export async function extractCookiesFromFirefox(profile?: string): Promise<CookieExtractionResult> {
|
||||
return readTwitterCookiesFromBrowser({ source: 'firefox', firefoxProfile: profile });
|
||||
}
|
||||
|
||||
/**
|
||||
* Resolve Twitter credentials from multiple sources.
|
||||
* Priority: CLI args > environment variables > browsers (ordered).
|
||||
*/
|
||||
export async function resolveCredentials(options: {
|
||||
authToken?: string;
|
||||
ct0?: string;
|
||||
cookieSource?: CookieSource | CookieSource[];
|
||||
chromeProfile?: string;
|
||||
firefoxProfile?: string;
|
||||
cookieTimeoutMs?: number;
|
||||
}): Promise<CookieExtractionResult> {
|
||||
const warnings: string[] = [];
|
||||
const cookies = buildEmpty();
|
||||
const cookieTimeoutMs =
|
||||
typeof options.cookieTimeoutMs === 'number' &&
|
||||
Number.isFinite(options.cookieTimeoutMs) &&
|
||||
options.cookieTimeoutMs > 0
|
||||
? options.cookieTimeoutMs
|
||||
: process.platform === 'darwin'
|
||||
? DEFAULT_COOKIE_TIMEOUT_MS
|
||||
: undefined;
|
||||
|
||||
if (options.authToken) {
|
||||
cookies.authToken = options.authToken;
|
||||
cookies.source = 'CLI argument';
|
||||
}
|
||||
if (options.ct0) {
|
||||
cookies.ct0 = options.ct0;
|
||||
if (!cookies.source) {
|
||||
cookies.source = 'CLI argument';
|
||||
}
|
||||
}
|
||||
|
||||
readEnvCookie(cookies, ['AUTH_TOKEN', 'TWITTER_AUTH_TOKEN'], 'authToken');
|
||||
readEnvCookie(cookies, ['CT0', 'TWITTER_CT0'], 'ct0');
|
||||
|
||||
if (cookies.authToken && cookies.ct0) {
|
||||
cookies.cookieHeader = cookieHeader(cookies.authToken, cookies.ct0);
|
||||
return { cookies, warnings };
|
||||
}
|
||||
|
||||
const sourcesToTry = resolveSources(options.cookieSource);
|
||||
for (const source of sourcesToTry) {
|
||||
const res = await readTwitterCookiesFromBrowser({
|
||||
source,
|
||||
chromeProfile: options.chromeProfile,
|
||||
firefoxProfile: options.firefoxProfile,
|
||||
cookieTimeoutMs,
|
||||
});
|
||||
warnings.push(...res.warnings);
|
||||
if (res.cookies.authToken && res.cookies.ct0) {
|
||||
return { cookies: res.cookies, warnings };
|
||||
}
|
||||
}
|
||||
|
||||
if (!cookies.authToken) {
|
||||
warnings.push(
|
||||
'Missing auth_token - provide via --auth-token, AUTH_TOKEN env var, or login to x.com in Safari/Chrome/Firefox',
|
||||
);
|
||||
}
|
||||
if (!cookies.ct0) {
|
||||
warnings.push('Missing ct0 - provide via --ct0, CT0 env var, or login to x.com in Safari/Chrome/Firefox');
|
||||
}
|
||||
if (cookies.authToken && cookies.ct0) {
|
||||
cookies.cookieHeader = cookieHeader(cookies.authToken, cookies.ct0);
|
||||
}
|
||||
|
||||
return { cookies, warnings };
|
||||
}
|
||||
@@ -1,12 +1,3 @@
|
||||
export {
|
||||
type CookieExtractionResult,
|
||||
type CookieSource,
|
||||
extractCookiesFromChrome,
|
||||
extractCookiesFromFirefox,
|
||||
extractCookiesFromSafari,
|
||||
resolveCredentials,
|
||||
type TwitterCookies,
|
||||
} from './cookies.js';
|
||||
export { runtimeQueryIds } from './runtime-query-ids.js';
|
||||
export {
|
||||
type CurrentUserResult,
|
||||
|
||||
@@ -4,6 +4,8 @@ import { type OperationName, QUERY_IDS, TARGET_QUERY_ID_OPERATIONS } from './twi
|
||||
import type { CurrentUserResult, TwitterClientOptions } from './twitter-client-types.js';
|
||||
import { normalizeQuoteDepth } from './twitter-client-utils.js';
|
||||
|
||||
const TRAILING_SLASHES = /\/+$/;
|
||||
|
||||
// biome-ignore lint/suspicious/noExplicitAny: TS mixin base constructor requirement.
|
||||
export type Constructor<T = object> = new (...args: any[]) => T;
|
||||
// biome-ignore lint/suspicious/noExplicitAny: TS mixin base constructor requirement.
|
||||
@@ -13,9 +15,7 @@ export type Mixin<TBase extends AbstractConstructor<TwitterClientBase>, TAdded>
|
||||
) => TwitterClientBase & TAdded;
|
||||
|
||||
export abstract class TwitterClientBase {
|
||||
protected authToken: string;
|
||||
protected ct0: string;
|
||||
protected cookieHeader: string;
|
||||
protected relayBaseUrl: string;
|
||||
protected userAgent: string;
|
||||
protected timeoutMs?: number;
|
||||
protected quoteDepth: number;
|
||||
@@ -24,12 +24,7 @@ export abstract class TwitterClientBase {
|
||||
protected clientUserId?: string;
|
||||
|
||||
constructor(options: TwitterClientOptions) {
|
||||
if (!options.cookies.authToken || !options.cookies.ct0) {
|
||||
throw new Error('Both authToken and ct0 cookies are required');
|
||||
}
|
||||
this.authToken = options.cookies.authToken;
|
||||
this.ct0 = options.cookies.ct0;
|
||||
this.cookieHeader = options.cookies.cookieHeader || `auth_token=${this.authToken}; ct0=${this.ct0}`;
|
||||
this.relayBaseUrl = this.normalizeRelayBaseUrl(options.relayBaseUrl ?? process.env.TWITTER_RELAY_BASE_URL);
|
||||
this.userAgent =
|
||||
options.userAgent ||
|
||||
'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36';
|
||||
@@ -72,14 +67,15 @@ export abstract class TwitterClientBase {
|
||||
}
|
||||
|
||||
protected async fetchWithTimeout(url: string, init: RequestInit): Promise<Response> {
|
||||
const relayUrl = this.toRelayUrl(url);
|
||||
if (!this.timeoutMs || this.timeoutMs <= 0) {
|
||||
return fetch(url, init);
|
||||
return fetch(relayUrl, init);
|
||||
}
|
||||
|
||||
const controller = new AbortController();
|
||||
const timeoutId = setTimeout(() => controller.abort(), this.timeoutMs);
|
||||
try {
|
||||
return await fetch(url, { ...init, signal: controller.signal });
|
||||
return await fetch(relayUrl, { ...init, signal: controller.signal });
|
||||
} finally {
|
||||
clearTimeout(timeoutId);
|
||||
}
|
||||
@@ -93,20 +89,31 @@ export abstract class TwitterClientBase {
|
||||
return randomBytes(16).toString('hex');
|
||||
}
|
||||
|
||||
private normalizeRelayBaseUrl(value: string | undefined): string {
|
||||
const trimmed = value?.trim();
|
||||
if (!trimmed) {
|
||||
throw new Error('TWITTER_RELAY_BASE_URL is required');
|
||||
}
|
||||
return trimmed.replace(TRAILING_SLASHES, '');
|
||||
}
|
||||
|
||||
private toRelayUrl(url: string): string {
|
||||
const parsed = new URL(url);
|
||||
if (!['x.com', 'twitter.com', 'api.twitter.com', 'upload.twitter.com'].includes(parsed.hostname)) {
|
||||
throw new Error(`Unsupported Twitter API host: ${parsed.hostname}`);
|
||||
}
|
||||
return `${this.relayBaseUrl}${parsed.pathname}${parsed.search}`;
|
||||
}
|
||||
|
||||
protected getBaseHeaders(): Record<string, string> {
|
||||
const headers: Record<string, string> = {
|
||||
accept: '*/*',
|
||||
'accept-language': 'en-US,en;q=0.9',
|
||||
authorization:
|
||||
'Bearer AAAAAAAAAAAAAAAAAAAAANRILgAAAAAAnNwIzUejRCOuH5E6I8xnZz4puTs%3D1Zv7ttfk8LF81IUq16cHjhLTvJu4FA33AGWWjCpTnA',
|
||||
'x-csrf-token': this.ct0,
|
||||
'x-twitter-auth-type': 'OAuth2Session',
|
||||
'x-twitter-active-user': 'yes',
|
||||
'x-twitter-client-language': 'en',
|
||||
'x-client-uuid': this.clientUuid,
|
||||
'x-twitter-client-deviceid': this.clientDeviceId,
|
||||
'x-client-transaction-id': this.createTransactionId(),
|
||||
cookie: this.cookieHeader,
|
||||
'user-agent': this.userAgent,
|
||||
origin: 'https://x.com',
|
||||
referer: 'https://x.com/',
|
||||
|
||||
@@ -6,10 +6,6 @@ export const TWITTER_GRAPHQL_POST_URL = 'https://x.com/i/api/graphql';
|
||||
export const TWITTER_UPLOAD_URL = 'https://upload.twitter.com/i/media/upload.json';
|
||||
export const TWITTER_MEDIA_METADATA_URL = 'https://x.com/i/api/1.1/media/metadata/create.json';
|
||||
export const TWITTER_STATUS_UPDATE_URL = 'https://x.com/i/api/1.1/statuses/update.json';
|
||||
export const SETTINGS_SCREEN_NAME_REGEX = /"screen_name":"([^"]+)"/;
|
||||
export const SETTINGS_USER_ID_REGEX = /"user_id"\s*:\s*"(\d+)"/;
|
||||
export const SETTINGS_NAME_REGEX = /"name":"([^"\\]*(?:\\.[^"\\]*)*)"/;
|
||||
|
||||
// Query IDs rotate frequently; the values in query-ids.json are refreshed by
|
||||
// scripts/update-query-ids.ts. The fallback values keep the client usable if
|
||||
// the file is missing or incomplete.
|
||||
|
||||
@@ -1,5 +1,3 @@
|
||||
import type { TwitterCookies } from './cookies.js';
|
||||
|
||||
// Raw media entity from Twitter API
|
||||
export interface GraphqlMediaEntity {
|
||||
id_str?: string;
|
||||
@@ -327,7 +325,7 @@ export interface FollowingResult {
|
||||
}
|
||||
|
||||
export interface TwitterClientOptions {
|
||||
cookies: TwitterCookies;
|
||||
relayBaseUrl?: string;
|
||||
userAgent?: string;
|
||||
timeoutMs?: number;
|
||||
// Max depth for quoted tweets (0 disables). Defaults to 1.
|
||||
|
||||
@@ -1,10 +1,5 @@
|
||||
import type { AbstractConstructor, Mixin, TwitterClientBase } from './twitter-client-base.js';
|
||||
import {
|
||||
SETTINGS_NAME_REGEX,
|
||||
SETTINGS_SCREEN_NAME_REGEX,
|
||||
SETTINGS_USER_ID_REGEX,
|
||||
TWITTER_API_BASE,
|
||||
} from './twitter-client-constants.js';
|
||||
import { TWITTER_API_BASE } from './twitter-client-constants.js';
|
||||
import { buildFollowingFeatures } from './twitter-client-features.js';
|
||||
import type { CurrentUserResult, FollowingResult, TwitterUser } from './twitter-client-types.js';
|
||||
import { extractCursorFromInstructions, parseUsersFromInstructions } from './twitter-client-utils.js';
|
||||
@@ -157,7 +152,7 @@ export function withUsers<TBase extends AbstractConstructor<TwitterClientBase>>(
|
||||
}
|
||||
|
||||
/**
|
||||
* Fetch the account associated with the current cookies
|
||||
* Fetch the account associated with the configured relay.
|
||||
*/
|
||||
async getCurrentUser(): Promise<CurrentUserResult> {
|
||||
const candidateUrls = [
|
||||
@@ -234,48 +229,6 @@ export function withUsers<TBase extends AbstractConstructor<TwitterClientBase>>(
|
||||
}
|
||||
}
|
||||
|
||||
// Fallback: scrape the authenticated settings page (HTML) for screen_name/user_id
|
||||
const profilePages = ['https://x.com/settings/account', 'https://twitter.com/settings/account'];
|
||||
for (const page of profilePages) {
|
||||
try {
|
||||
const response = await this.fetchWithTimeout(page, {
|
||||
headers: {
|
||||
cookie: this.cookieHeader,
|
||||
'user-agent': this.userAgent,
|
||||
},
|
||||
});
|
||||
|
||||
if (!response.ok) {
|
||||
lastError = `HTTP ${response.status} (settings page)`;
|
||||
continue;
|
||||
}
|
||||
|
||||
const html = await response.text();
|
||||
const usernameMatch = SETTINGS_SCREEN_NAME_REGEX.exec(html);
|
||||
const idMatch = SETTINGS_USER_ID_REGEX.exec(html);
|
||||
const nameMatch = SETTINGS_NAME_REGEX.exec(html);
|
||||
|
||||
const username = usernameMatch?.[1];
|
||||
const userId = idMatch?.[1];
|
||||
const name = nameMatch?.[1]?.replace(/\\"/g, '"');
|
||||
|
||||
if (username && userId) {
|
||||
return {
|
||||
success: true,
|
||||
user: {
|
||||
id: userId,
|
||||
username,
|
||||
name: name || username,
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
lastError = 'Could not parse settings page for user info';
|
||||
} catch (error) {
|
||||
lastError = error instanceof Error ? error.message : String(error);
|
||||
}
|
||||
}
|
||||
|
||||
return {
|
||||
success: false,
|
||||
error: lastError ?? 'Unknown error fetching current user',
|
||||
@@ -375,7 +328,7 @@ export function withUsers<TBase extends AbstractConstructor<TwitterClientBase>>(
|
||||
}
|
||||
|
||||
// GraphQL Following can also return 404 (queryId churn / endpoint flakiness).
|
||||
// Fallback to the internal v1.1 REST endpoint used by the web client (cookie-auth; no dev API key).
|
||||
// Fallback to the internal v1.1 REST endpoint used by the web client through the relay.
|
||||
// Note: REST fallback does not support cursor pagination.
|
||||
const restAttempt = await this.getFollowingViaRest(userId, count);
|
||||
if (restAttempt.success) {
|
||||
@@ -481,7 +434,7 @@ export function withUsers<TBase extends AbstractConstructor<TwitterClientBase>>(
|
||||
}
|
||||
|
||||
// GraphQL Followers regularly returns 404 (queryId churn / endpoint flakiness).
|
||||
// Fallback to the internal v1.1 REST endpoint used by the web client (cookie-auth; no dev API key).
|
||||
// Fallback to the internal v1.1 REST endpoint used by the web client through the relay.
|
||||
// Note: REST fallback does not support cursor pagination.
|
||||
const restAttempt = await this.getFollowersViaRest(userId, count);
|
||||
if (restAttempt.success) {
|
||||
|
||||
Reference in New Issue
Block a user