Skip to content

Record input elements with no events - #389

Merged
kingthorin merged 1 commit into
zaproxy:mainfrom
psiinon:recorder/js-fields
Oct 6, 2026
Merged

kingthorin merged 1 commit into
zaproxy:mainfrom
psiinon:recorder/js-fields

Conversation

@psiinon

@psiinon psiinon commented Oct 5, 2026

Copy link
Copy Markdown
Member

The ZAP recorder failed to record a field that uses jQuery Inputmask v3.3.4.
The Inputmask hooks keydown/keypress events on the field, so the value is only changed by scripting and the only "notification" of that change is a non-native, jQuery-internal synthetic event, no real native change (or input) event is ever fired on that element, not on each keystroke and not on blur either.
ZAP's recorder adds a plain native element.addEventListener('change', this.handleChange...) listener, and that's the only mechanism it has for capturing typed text (there is no input/keyup listener, and the MutationObserver it uses only watches for added nodes.
Since no native change event is ever dispatched for the field, handleChange is simply never called, and the value is silently dropped.

Fix (source/ContentScript/recorder.ts):

  • Fallback on blur: the recorder now has a capture-phase focusout fallback. If the user typed in or pasted into a text field and its value on blur differs from its value at focus, it records the value as if a change event had fired.
  • How it avoids duplicates: the fallback only runs for fields with no change event since the user's edit. A change event resets the tracking, so fields that fire it normally are recorded once.
  • Which keys count: only character keys, Backspace, Delete and paste mark a field as edited. Tab or arrow keys don't, and a field the page clears after Enter isn't recorded again.

@psiinon

psiinon commented Oct 5, 2026 •

Copy link
Copy Markdown
Member Author

Logo
Checkmarx One – Scan Summary & Details – 7f459df1-4aba-45b5-9813-5d7ed6184117

Great job! No new security vulnerabilities introduced in this pull request


Use @Checkmarx to take action directly from this PR:

  • Rescan the PR

Try it: @Checkmarx how can you help? · @Checkmarx rescan this PR

Signed-off-by: Simon Bennetts <psiinon@gmail.com>
@psiinon
psiinon force-pushed the recorder/js-fields branch from 93b2373 to 50e98f5 Compare October 5, 2026 16:05
@thc202

thc202 commented Oct 6, 2026

Copy link
Copy Markdown
Member

Thank you!

@kingthorin
kingthorin merged commit 5c60652 into zaproxy:main Oct 6, 2026
9 of 18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants