Skip to content

Add no-JS ad frame endpoint (/api/ads/frame) - #90

Merged
ralyodio merged 1 commit into
masterfrom
feat/no-js-ad-frame
Jul 7, 2026
Merged

ralyodio merged 1 commit into
masterfrom
feat/no-js-ad-frame

Conversation

@ralyodio

@ralyodio ralyodio commented Jul 7, 2026

Copy link
Copy Markdown
Contributor

Why

The current ad tag (<div data-cp-ad> + ad.js) renders nothing until JS runs, and even then injects a sandboxed srcdoc iframe whose click link can be interfered with by the host page's JS. It also can't work at all where JS is unavailable/blocked (e.g. Tor hidden services in Safer/Safest mode).

What

New GET /api/ads/frame?slot=<id>&format=<fmt> returns the ad as a full HTML document (not JSON), so publishers can embed a plain, script-free tag:

<iframe src="https://crawlproof.com/api/ads/frame?slot=<id>&format=banner_300x250"
        width="300" height="250" frameborder="0" scrolling="no"
        style="border:0;max-width:100%" loading="lazy"></iframe>
  • Renders + is clickable with zero host-page JavaScript.
  • Click link (target="_blank") lives inside CrawlProof's own cross-origin document → the host page can never intercept the click-through.
  • Embeddable cross-origin by design (content-security-policy: frame-ancestors *, no X-Frame-Options) — works on .onion publishers who can only cut-n-paste.
  • Impressions metered server-side via the existing serveAd (bots → house ad, paid clicks tracked through /api/ads/click). No new tracking code.
  • Best-effort: any failure returns a blank document, never a broken frame.

Reuses serveAd + renderCreativeHtml; mirrors /api/ads/serve (which stays for the ad.js path).

🤖 Generated with Claude Code

Serves an ad as a full HTML document so publishers can embed a plain
cross-origin <iframe src=...> that renders and is clickable with zero
JavaScript on the host page. Enables embedding on JS-restricted contexts
(e.g. Tor hidden services) and keeps the click link inside CrawlProof's
own document so the host page can't intercept it. Impressions are metered
server-side in serveAd, same as the JSON /api/ads/serve path.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Jul 7, 2026

Copy link
Copy Markdown

vu1nz Security Review

0 finding(s) in PR #?

No security issues found.

@ralyodio
ralyodio merged commit 7eed571 into master Jul 7, 2026
8 checks passed
@ralyodio
ralyodio deleted the feat/no-js-ad-frame branch July 7, 2026 11:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant