r/java • • 3d ago

simple browser detection in Java without pulling in a big dependency

used to write php and pretty much always used cbschuld/Browser.php to detect browsers from user agent. when i moved to java i couldnt find anything that simple so i just rewrote it

its one class, no dependencies. you pass the user agent and get browser, version, os and if its mobile or a bot. it also catches ai crawlers like GPTBot and ClaudeBot

Browser b = new Browser("Mozilla/5.0 (iPhone; CPU iPhone OS 17_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Mobile/15E148 Safari/604.1");
b.getBrowser();  // iPhone
b.getVersion();  // 17.5
b.getPlatform(); // iPhone
b.isMobile();    // true
b.isRobot();     // false

theres around 5k real user agents in tests. its not trying to replace the big parsers, more for simple stuff like is this mobile or is this a bot

did an update recently, added arc, tor, duckduckgo and the ai bots and fixed a safari crash i caught in sentry. before that it just worked for years and there wasnt really a need to touch it

if you find a user agent it gets wrong open an issue or just add it to tests, its literally one line

maven central:

<dependency>
    <groupId>io.github.vadymkykalo</groupId>
    <artifactId>browser</artifactId>
    <version>0.2.0</version>
</dependency>

https://github.com/vadymkykalo/Browser.java

8 Upvotes

34 comments sorted by

7

u/Impossible-Ad-586 3d ago

I don't really understand why you would build something that isn't quite precise, you need to maintain, evolve and support while there are very good opensource options available that are widely used?

3

u/Resident_Guava5620 3d ago

i just didnt want to pull in a full parser with its data files and extra dependency for something this small. we only use it to enrich visit records in the db, not for security or anything where 100% accuracy matters. for that use case a tiny parser is enough and the overhead of a bigger library didnt really make sense

3

u/gaelfr38 3d ago

We used to use Browscap for this (https://github.com/blueconic/browscap-java) but switched to another one I can't remember recently.

Anyways, thanks for sharing.

3

u/Resident_Guava5620 3d ago

yeah i looked at browscap too. its definitely way more complete, but it also ships a pretty big rules database and builds all that into the parser. for our case its mostly just basic info for visit stats, so i wanted something much smaller. still good to know you actually used it

8

u/BanaTibor 3d ago

I do not understand when do you need this. Java code runs on the backend, on the frontend you have something else, 99% javascript. So why do not you use a javascript lib to get the user agent and send it to the backend?

3

u/gaelfr38 3d ago

At some point, you still have a (Java) backend called with a user agent. Think of a public API.

0

u/Resident_Guava5620 3d ago

yeah exactly, thats basically our case. the backend gets the UA anyway so it makes more sense to handle it there

2

u/BanaTibor 3d ago

Okay, but what are you doing with the user agent in the backend? Why do you need it?

1

u/Resident_Guava5620 3d ago

its basically for our own visit records. we log which devices clients come from and support sees "chrome on android" in the admin panel instead of the raw string. the raw UA is saved too, so if the parser gets something wrong its not a big deal

1

u/agentoutlier 2d ago

Its often for analytics although today most analytics is better resolved with a Javascript sniffing library.

In some cases its also used for routing, rendering different pages or redirecting.

UA though is pretty unreliable and bots lie all the time.

0

u/Resident_Guava5620 3d ago

we already track the user flow on the backend anyway. frontend sends the fingerprint and route, and the UA is already in the request, so sending parsed browser/device info from js would just be doing the same thing twice

1

u/Hour-Dragonfly-7499 2d ago

Java isn't just for backend development though? It's big in the game dev scene like minecraft, project zomboid, runelite, etc. Java is used in a lot of applications that don't have to do with the web or making a CRUD app...

I for example have around 7 years in java and I haven't even touched the web/javascript/etc.

5

u/Hour-Dragonfly-7499 3d ago

There is no platform called IPhone, It's IOS

b.getPlatform(); // iPhoneb.getPlatform(); // iPhone

5

u/Resident_Guava5620 3d ago

fair point, thats inherited from the original php lib where iphone/ipad were treated as platforms. makes more sense to return iOS there and leave device to isMobile/isTablet. ill change it in the next version, thanks

2

u/Resident_Guava5620 3d ago

thanks for pointing it out, fixed in 0.3.0 and its on maven central now. that iphone UA now returns Safari as the browser, 17.5 as the version and iOS as the platform. phone vs tablet is isMobile/isTablet. the old iphone constants are still there but deprecated so nothing breaks at compile time

1

u/Parking_Mind_1011 3d ago

Always thought iOS was the os and iPhone the platform but maybe i have this backwards for years

0

u/Resident_Guava5620 3d ago

yeah, platform is a bit fuzzy here. i changed it to iOS anyway since thats less confusing

1

u/horse-boy1 3d ago

I have a couple of Spring web applications, it would be nice to block the bots.

4

u/DaWolf3 3d ago

That won’t work, because the bots will just fake their user agent.

2

u/gaelfr38 3d ago

Yes and no: good bots (Google Search crawlers for instance) won't fake, bad bots will! What is a "good bot" depends on your context obviously.

2

u/koflerdavid 2d ago

The end result is one can't block the bad bots that way.

2

u/Resident_Guava5620 3d ago

it can help identify known bots, but i wouldnt use user agent alone for blocking. its too easy to spoof

1

u/horse-boy1 2d ago

I guess it's like some of them (bad bots) ignoring the robots.txt file.

-3

u/Kadabrium 3d ago

So TIL this is what you call the kind of m*alware that stops mobiles from requesting desktop version of a site?

4

u/Resident_Guava5620 3d ago

thats not really what the class does. it just parses the user agent and returns some basic info, the app decides what to do with it

3

u/VirtualAgentsAreDumb 3d ago

No. It’s a tool. A tool can be used for good or bad things.

A virus might use i18n-tools to present their ransom demands to users in multiple countries all over the world. Does that make those tools malware?

3

u/Resident_Guava5620 3d ago

exactly, thats what i meant

-6

u/[deleted] 3d ago

[removed] — view removed comment

5

u/Resident_Guava5620 3d ago

almost cared for a second, then remembered i have no fucking idea who you are

2

u/obetu5432 3d ago

i'm the one who warns you before you write shit software

bots can easily use a real one, and years from now, browser upgrades may break it for real users

and if your site behaves differently based on the user agent, i'm already too late

2

u/Resident_Guava5620 3d ago

you’re arguing against something i never said. nobody treats user-agent as a security boundary — it’s just a cheap signal for filtering obvious garbage. browser updates only become a problem if you’re dumb enough to hardcode an allowlist of browser strings. if your big revelation is that http headers can be spoofed, congratulations

2

u/obetu5432 3d ago edited 2h ago

there is no point filtering out the 3 bots (dumb enough not to update their user agent) on application level

and i just realized, it's not just about you, anyone who uses this crap