# Is run\_at page\_start in manifest.json really working?

**URL:** <https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432>\
**Category:** Development\
**Created:** [September 21, 2017, 9:11pm UTC](https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432 "2017-09-21T21:11:28Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![dehe25](https://avatars.discourse-cdn.com/v4/letter/d/aca169/32.png) [@dehe25](https://discourse.mozilla.org/u/dehe25)\
**Post date:** [September 21, 2017, 9:11pm UTC](https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432/1 "2017-09-21T21:11:28Z")

</div>

You can define to load a page at a certain time of building DOM using run\_at: for example with parameter page\_start. this isn’t working either. it seems to me that either the script is being run asynchronous, or there is some other reason for this not to be working:

aall=document.getElementsByTagName("\*");  
for (var i=0, max=aall.length; i \< max; i++) {  
aall[i].addEventListener=function(a,b,c){ console.log(“Log”); return false; };  
}  
console.log(“Log”); is never being called, even though an event has been added to the element using addEventListener in the test html file. My current solution for this is an own firefox fork that overwrites the functions in the javascript engine, which is kind of overdosed.

---

<div class="post-metadata">

**Author:** ![NilkasG](https://avatars.discourse-cdn.com/v4/letter/n/0ea827/32.png) [@NilkasG](https://discourse.mozilla.org/u/NilkasG)\
**Post date:** [September 22, 2017, 3:06pm UTC](https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432/2 "2017-09-22T15:06:53Z")

</div>

You didn’t say what you actually want to do. Do you want to overwrite `Element.prototype.addEventListener` (from the web pages perspective)?

If so, you should read this:

> **[Content scripts](https://developer.mozilla.org/en-US/Add-ons/WebExtensions/Content_scripts#Content_script_environment)**
>
> A content script is a part of your extension that runs in the context of a particular web page (as opposed to background scripts which are part of the extension, or scripts which are part of the web site itself, such as those loaded using the script...

And also you should overwrite `Element.prototype.addEventListener`, not cover up every individual elements `.addEventListener` property.

---

<div class="post-metadata">

**Author:** ![dehe25](https://avatars.discourse-cdn.com/v4/letter/d/aca169/32.png) [@dehe25](https://discourse.mozilla.org/u/dehe25)\
**Post date:** [September 23, 2017, 7:46am UTC](https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432/3 "2017-09-23T07:46:14Z")

</div>

Hello,  
thanks for your imput. that’s exactly what i’m trying to do. Element.prototype.addEventListener failed, too. But i’m gonna check again to get sure. The reason is that i want to be able to block external scripts or scripts from the page itself from adding blacklisted events.  
so injecting javascript that will get executed before anything else gets executed would be great.  
i’m using a content script, run\_at is only for content scripts, as far as i know.

Regards,  
Dennis

---

<div class="post-metadata">

**Author:** ![dehe25](https://avatars.discourse-cdn.com/v4/letter/d/aca169/32.png) [@dehe25](https://discourse.mozilla.org/u/dehe25)\
**Post date:** [September 23, 2017, 8:05am UTC](https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432/4 "2017-09-23T08:05:25Z")

</div>

okay, update. this one seems to be working:

var actualCode = ‘Element.prototype.addEventListener=function(a,b,c){alert(a);}’;  
document.documentElement.setAttribute(‘onreset’, actualCode);  
document.documentElement.dispatchEvent(new CustomEvent(‘reset’));  
document.documentElement.removeAttribute(‘onreset’)

so run\_at is working correctly.  
the problem is, that inline events can be blocked, so i’m still looking for a better possibility.

---

<div class="post-metadata">

**Author:** ![NilkasG](https://avatars.discourse-cdn.com/v4/letter/n/0ea827/32.png) [@NilkasG](https://discourse.mozilla.org/u/NilkasG)\
**Post date:** [September 23, 2017, 8:37am UTC](https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432/5 "2017-09-23T08:37:13Z")

</div>

You Reely ned to read and understand the article I linked above, especially the things about Xray vision.

* * *

Regarding your actual aim, overwriting the addEventListener function is not the best way to achieve it. You should instead attach a capturing listener on the document and call .stopImmidiatePropagation on it.

---

<div class="post-metadata">

**Author:** ![dehe25](https://avatars.discourse-cdn.com/v4/letter/d/aca169/32.png) [@dehe25](https://discourse.mozilla.org/u/dehe25)\
**Post date:** [September 23, 2017, 9:20am UTC](https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432/6 "2017-09-23T09:20:11Z")

</div>

it’s working perfectly now using  
var actualCode = ‘Element.prototype.\_addEventListener=Element.prototype.addEventListener;Element.prototype.addEventListener=function(a,b,c){if(a!=“mouseenter”){this.\_addEventListener(a,b,c);}};’;

your input lead my on the right track, allthough i allready knew the page you were linking to - thanks alot for your help!

---

<div class="post-metadata">

**Author:** ![NilkasG](https://avatars.discourse-cdn.com/v4/letter/n/0ea827/32.png) [@NilkasG](https://discourse.mozilla.org/u/NilkasG)\
**Post date:** [September 23, 2017, 9:37am UTC](https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432/7 "2017-09-23T09:37:05Z")

</div>

Injecting inline code (which is what you are doing) won’t work on pages with a reasonably strong CSP.

You can try it out on for example [https://github.com/](https://github.com/). Your `actualCode` won’t run there.

`event.stopImmidiatePropagation()` doesn’t have that limitation.

---

<div class="post-metadata">

**Author:** ![dehe25](https://avatars.discourse-cdn.com/v4/letter/d/aca169/32.png) [@dehe25](https://discourse.mozilla.org/u/dehe25)\
**Post date:** [September 23, 2017, 10:22am UTC](https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432/8 "2017-09-23T10:22:56Z")

</div>

fixed it using:  
var script = document.createElement(‘script’);  
script.textContent = actualCode;  
(document.head||document.documentElement).appendChild(script);  
script.remove();

---

<div class="post-metadata">

**Author:** ![NilkasG](https://avatars.discourse-cdn.com/v4/letter/n/0ea827/32.png) [@NilkasG](https://discourse.mozilla.org/u/NilkasG)\
**Post date:** [September 23, 2017, 10:32am UTC](https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432/9 "2017-09-23T10:32:02Z")

</div>

That is generally a cleaner way to inject scripts, but is rejected by CSPs all the same. If the page has a CSP with doesn’t explicitly allow `script-src 'unsafe-inline'` (or `'unsafe-eval'`) you will not be able to inject code into the page **at all**.

---

<div class="post-metadata">

**Author:** ![dehe25](https://avatars.discourse-cdn.com/v4/letter/d/aca169/32.png) [@dehe25](https://discourse.mozilla.org/u/dehe25)\
**Post date:** [September 23, 2017, 10:51am UTC](https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432/10 "2017-09-23T10:51:17Z")

</div>

When using the old method, i do get csp errors in the developers console. with the new version, there don’t seem to be errors.

---

<div class="post-metadata">

**Author:** ![NilkasG](https://avatars.discourse-cdn.com/v4/letter/n/0ea827/32.png) [@NilkasG](https://discourse.mozilla.org/u/NilkasG)\
**Post date:** [September 23, 2017, 5:45pm UTC](https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432/11 "2017-09-23T17:45:24Z")

</div>

That does not necessarily mean that your code was executed. Firefox likes to keep errors like that to itself.

---

<div class="post-metadata">

**Author:** ![dehe25](https://avatars.discourse-cdn.com/v4/letter/d/aca169/32.png) [@dehe25](https://discourse.mozilla.org/u/dehe25)\
**Post date:** [September 24, 2017, 9:32am UTC](https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432/12 "2017-09-24T09:32:04Z")

</div>

it has to be injected somehow because at run\_at document\_start, the dom tree hasn’t loaded yet. the description in the MDN API documentation sounds like the script being loaded asynchronously with run\_at document\_end.  
event.stopImmediateProgragation can only be applyed to existing DOM elements, afaik.

---

<div class="post-metadata">

**Author:** ![NilkasG](https://avatars.discourse-cdn.com/v4/letter/n/0ea827/32.png) [@NilkasG](https://discourse.mozilla.org/u/NilkasG)\
**Post date:** [September 24, 2017, 11:16am UTC](https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432/14 "2017-09-24T11:16:01Z")

</div>

> [@dehe25](#):
>
> event.stopImmediateProgragation can only be applyed to existing DOM elements, afaik.

I’m not quite sure what you mean. You call `.stopImmediateProgragation()` on events when they occur, so of course an event target exists at that time. But you can attach your capturing listener that does the cancelling earlier. For most events you can put it on the `window`, for some few event types you need to use the `document`. Either way you can attach the listener before the first element is present, and it will affect all elements that are later added to the DOM.

---

<div class="post-metadata">

**Author:** ![dehe25](https://avatars.discourse-cdn.com/v4/letter/d/aca169/32.png) [@dehe25](https://discourse.mozilla.org/u/dehe25)\
**Post date:** [September 24, 2017, 1:57pm UTC](https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432/15 "2017-09-24T13:57:15Z")

</div>

i don’t have access to the elements from the content script.

---

<div class="post-metadata">

**Author:** ![NilkasG](https://avatars.discourse-cdn.com/v4/letter/n/0ea827/32.png) [@NilkasG](https://discourse.mozilla.org/u/NilkasG)\
**Post date:** [September 24, 2017, 2:02pm UTC](https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432/16 "2017-09-24T14:02:47Z")

</div>

What do you mean? accessing the DOM is the primary purpose of content scripts. Why do you say you can’t access them?

---

<div class="post-metadata">

**Author:** ![dehe25](https://avatars.discourse-cdn.com/v4/letter/d/aca169/32.png) [@dehe25](https://discourse.mozilla.org/u/dehe25)\
**Post date:** [September 24, 2017, 2:04pm UTC](https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432/17 "2017-09-24T14:04:51Z")

</div>

> **[content\_scripts](https://developer.mozilla.org/en-US/Add-ons/WebExtensions/manifest.json/content_scripts)**
>
> Instructs the browser to load content scripts into web pages whose URL matches a given pattern.

  
it shows you when content scripts are being loaded using run\_at

---

<div class="post-metadata">

**Author:** ![dehe25](https://avatars.discourse-cdn.com/v4/letter/d/aca169/32.png) [@dehe25](https://discourse.mozilla.org/u/dehe25)\
**Post date:** [September 24, 2017, 2:07pm UTC](https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432/18 "2017-09-24T14:07:33Z")

</div>

btw: i tryed several methods by now. script injection was the first that really worked.

aall=document.getElementsByTagName("\*");  
for (var i=0, max=aall.length; i \< max; i++) {  
aall[i].addEventListener=function(a,b,c){ console.log(“Log”); return false; };  
}  
**console.log(“Log”); is never being called**  
also, when using jquery and stopImmediatePropagation or overwriting addEventListener, it doesn’t work.

---

<div class="post-metadata">

**Author:** ![dehe25](https://avatars.discourse-cdn.com/v4/letter/d/aca169/32.png) [@dehe25](https://discourse.mozilla.org/u/dehe25)\
**Post date:** [September 24, 2017, 2:23pm UTC](https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432/19 "2017-09-24T14:23:45Z")

</div>

another thing: why should adding code to the objects representing the page be a problem? it’s not inline scripting, and unsafe-inline shouldn’t concern it.

---

<div class="post-metadata">

**Author:** ![NilkasG](https://avatars.discourse-cdn.com/v4/letter/n/0ea827/32.png) [@NilkasG](https://discourse.mozilla.org/u/NilkasG)\
**Post date:** [September 24, 2017, 2:56pm UTC](https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432/20 "2017-09-24T14:56:20Z")

</div>

> [@dehe25](#):
>
> ```auto
> aall=document.getElementsByTagName("*");
> for (var i=0, max=aall.length; i &lt; max; i++) {
> aall[i].addEventListener=function(a,b,c){ console.log(“Log”); return false; };
> }
> 
> ```
> 
> console.log(“Log”); is never being called

That is to be expected. Due to the Xray vision, the `.addEventListener` function called by the page scripts is a different one (that does the exact same thing).

> why should adding code to the objects representing the page be a problem? it’s not inline scripting, and unsafe-inline shouldn’t concern it.

if you are adding script tags with code to the page, that is an inline script and the CSP will prevent it’s execution. It duesn’t matter where the code string came from.

> also, when using jquery and stopImmediatePropagation […], it doesn’t work.

You can’t use jQuery for this. You need to use [`.addEventListener`](https://developer.mozilla.org/en-US/docs/Web/API/EventTarget/addEventListener) **and set `useCapture`to `true`**. jQuery doesn’t support that. If you attach your listener like that, it can call `.stopImmediatePropagation()`.

---

<div class="post-metadata">

**Author:** ![dehe25](https://avatars.discourse-cdn.com/v4/letter/d/aca169/32.png) [@dehe25](https://discourse.mozilla.org/u/dehe25)\
**Post date:** [September 24, 2017, 3:03pm UTC](https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432/21 "2017-09-24T15:03:36Z")

</div>

sure it’s possible with jquery.  
that’s simply not true, xray vision is concerning content and background script communication, it’s not inline scripting, and so on.  
i’m out of this conversation.  
thank you again for your help, annyway.

[Next page](https://discourse.mozilla.org/t/is-run-at-page-start-in-manifest-json-really-working/19432.md?page=2)
