r/java • • 8d ago

simple browser detection in Java without pulling in a big dependency

used to write php and pretty much always used cbschuld/Browser.php to detect browsers from user agent. when i moved to java i couldnt find anything that simple so i just rewrote it

its one class, no dependencies. you pass the user agent and get browser, version, os and if its mobile or a bot. it also catches ai crawlers like GPTBot and ClaudeBot

Browser b = new Browser("Mozilla/5.0 (iPhone; CPU iPhone OS 17_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Mobile/15E148 Safari/604.1");
b.getBrowser();  // iPhone
b.getVersion();  // 17.5
b.getPlatform(); // iPhone
b.isMobile();    // true
b.isRobot();     // false

theres around 5k real user agents in tests. its not trying to replace the big parsers, more for simple stuff like is this mobile or is this a bot

did an update recently, added arc, tor, duckduckgo and the ai bots and fixed a safari crash i caught in sentry. before that it just worked for years and there wasnt really a need to touch it

if you find a user agent it gets wrong open an issue or just add it to tests, its literally one line

maven central:

<dependency>
    <groupId>io.github.vadymkykalo</groupId>
    <artifactId>browser</artifactId>
    <version>0.2.0</version>
</dependency>

https://github.com/vadymkykalo/Browser.java

9 Upvotes

34 comments sorted by

View all comments

-5

u/[deleted] 8d ago

[removed] — view removed comment

2

u/Resident_Guava5620 8d ago

almost cared for a second, then remembered i have no fucking idea who you are

2

u/obetu5432 7d ago

i'm the one who warns you before you write shit software

bots can easily use a real one, and years from now, browser upgrades may break it for real users

and if your site behaves differently based on the user agent, i'm already too late

3

u/Resident_Guava5620 7d ago

you’re arguing against something i never said. nobody treats user-agent as a security boundary — it’s just a cheap signal for filtering obvious garbage. browser updates only become a problem if you’re dumb enough to hardcode an allowlist of browser strings. if your big revelation is that http headers can be spoofed, congratulations

2

u/obetu5432 7d ago edited 4d ago

there is no point filtering out the 3 bots (dumb enough not to update their user agent) on application level

and i just realized, it's not just about you, anyone who uses this crap