Drupal core officially declares support for UC Browser. This setting is stored in core’s package.json (https://git.drupalcode.org/project/drupal/-/blob/9.4.x/core/package.json...), which is then read by core’s PostCSS and Babel processes to compile the CSS and JS.
What is UC Browser?
- UC Browser is a web browser developed by mobile internet company UCWeb, a subsidiary of the Alibaba Group.
- It is based on the Chromium browser engine, but that is not kept up to date.
Small browser market share
UC Browser has a global market share of 0.97% as of October 2021 according to Stats Counter.
Privacy concerns
According to WikiPedia:
It has been the subject of several security and privacy controversies, and was banned in India on June 29, 2020
and
In May 2015, National Security Agency (NSA) documents leaked by whistleblower Edward Snowden indicated that UC Browser leaks sensitive data like international mobile subscriber identities, international mobile station equipment identities, MSISDN's, Android ID's, MAC addresses, and geolocation and Wi-Fi-related data without any encryption.[18] These leaks were used by intelligence agencies to track users. The documents also revealed that the Australian Signals Directorate (ASD) had identified UC Browser as a security weak point. Its widespread use in China, India and Indonesia made it particularly attractive to ASD. The documents revealed that in cooperation with its Five Eyes partners, ASD hacked the UC Browser and infected smartphones with spyware. The ASD declined to comment in relation to the revelations.[19]
No support for CSS :where() pseudo-selector
The original reason that i started looking at UC Browser is because it is the only Drupal 10 supported browser that does not support the :where() selector. This selector gives CSS authors the ability to customize CSS specificity with selector-level granularity and promises the ability to radically simplify Drupal’s CSS while making it more resilient at the same time.
Draft release note
Drupal has remove explicit support for older versions of UC browser that relied on a forked version of chrome. Newer versions of the browser that rely on WebView should be unaffected.
| Comment | File | Size | Author |
|---|---|---|---|
| #18 | 3251384-17.patch | 118.99 KB | mherchel |
| #15 | Cursor_and_Browser_Market_Share_China___Statcounter_Global_Stats.png | 299.31 KB | xjm |
Comments
Comment #2
bradjones1Is there a policy somewhere that specifies which browsers are targeted by Drupal core's CSS and JS?
Comment #3
lauriii@bradjones1 Is this https://www.drupal.org/docs/system-requirements/browser-requirements what you are looking for?
Comment #4
bradjones1That would be the artifact of the decision, yes - I suppose the real underlying question is, who makes that list and how is it updated? E.g., this then becomes a
[Policy, no patch]type issue, that would then spawn the code change in question?Comment #5
cilefen commentedI think this is a "policy, no patch" issue and should be renamed. Example: #3155358: [policy, no patch] Drop IE11 support from Drupal 10.0.x
Comment #6
bradjones1Comment #7
longwaveComment #8
markconroy commentedGiven that UC is not kept up to date (if it was, and is based on Chromium, we'd probably support it by virtue of the fact that we are supporting chrome on Android rather than by any extra effort) and given the security concerns raised, and given the tiny browser market share it has, I think I'm in agreement about dropping support for this.
Comment #9
nod_Comment #10
catch@bradjones1 there is an open issue to define a policy for removing and adding browsers to the support list here: #3080068: [policy, no patch] Define usage heuristics for browser support. Until that's resolved, we have to do individual issues like this one.
If there's no indication that UC browser ever updates the browser engine, that's a compelling reason to remove support. But looked at usage too to get an idea.
UC browser was removed from android app stores in China last year - not clear if that was permanent, but if it was, that's likely going to kill it off entirely soon.
https://www.cnbc.com/2021/03/16/alibabas-uc-browser-deleted-from-android...
According to https://gs.statcounter.com/browser-market-share
Internationally: 1.45% in December 2020, 0.94% in December 2021 - so under 1% usage and on a downward trajectory.
Indonesia: 2.2% December 2020 to 1.45% December 2021 - negligible.
China: 19% in March 2021 (peak) to 11% December 2021 - not negligible but low and going down.
India: 5.43% Jan 2021 to 2.33% December 2021 - negligible.
So Indonesia it was not that popular last year anyway. India, usage halved down to < 2.5%. China, usage has halved in 9 months.
Looks like it's going to be more or less gone by the time Drupal 10 is released or not long after, so I think we should just drop it in 10.x.
Comment #11
droplet commentedI tested UC browser (playstore ver).
I believe this is an embed webview because their user agent is TOTALLY the same as my Android webview version.
That means we need to make decisions based on the Android System version (Android Browser??) rather than UC.
And some random research showed the same result:
https://user-agents.net/browsers/uc-browser/versions/13-0
Comment #12
catchIf it's webview, I think we need a separate issue to define if/how we support that as a 'browser' in its own right. But that probably pushes this issue even more in the direction of dropping explicit support for UC browser.
Comment #13
ckrinaI don't want to dismiss its market share in China, but as @catch is suggesting it'll probably go down over time. IMHO the cons are bigger than the pros.
On a front-end perspective a browser that doesn't give support to new important features (and won't give it in the future) can really slow us down and affect Drupal competitiveness on several ways.
So +1 for removing support for D10.
Comment #14
droplet commentedFrom what I found in #11, I think we need to fix it in the next release (9.4?)
The upstream data is incorrect I believe (just someone using a particular Android OS version to contribute the data)
So fixing in https://github.com/browserslist/caniuse-lite is another way to disconnect it.
If we don't totally drop it in 9.4, then I think we need to find the closest Chrome version and add it to our list
https://caniuse.com/ciu/comparison
(this page isn't 100% correct IMO, some features are missing)
** Note: I can't find a way to test UC 12.12 listed on caniuse.com. This is keeping crashed! I've tried diff Android OS versions already :s)
Comment #15
xjmThis one is tricky. It's still the second-most-used browser in China, and the initial decline after it was removed from the App store seems to have leveled off:

(Source: https://gs.statcounter.com/browser-market-share/all/china/#monthly-20200...)
On the other hand, this seems pretty clearly like an extenuating circumstance to me based on the IS.
#11 sounds like the right approach to me, although I'm not sure how to square it with our current policy.
Comment #16
andy-blumThis issue is "Policy, no patch", but lists browser support entries in package.json. Should a different issue be opened to change the package.json file or should this issue's title be changed?
Comment #17
mherchelPatch attached; title adjusted.
Comment #18
mherchelPatch attached with re-compiled assets.
Comment #19
ckrinaWe just discussed this with @lauriii and @bnjmnm and the 3 of us agreed on removing support for UC Browser. Removing the Needs frontend framework manager review tag.
Comment #20
andy-blumAssuming this is ready for review, I've looked over patch-17/comment-18 and the changes are very straight forward. As far as I can tell, the only adjustment to the compiled assets is replacing
selfwithglobalThis. Does this need any additional review?Comment #21
mherchelFrom what I understand reading the title of #3118147: [meta] Set Drupal 10 platform and browser requirements six months before the release, we need to make this happen by this Tuesday, June 14.
Comment #22
catchTo meet the deadline, the main thing is updating https://www.drupal.org/docs/system-requirements/browser-requirements to add 'Drupal 9 and below only' to UC browser I think.
Tagging for a change record too.
Having said that this is essentially a one line patch + compiled assets, so it looks like an easy commit to me.
Comment #23
catchAlso since this has consensus among the front end framework managers and +1s from both me and @xjm, I think it's OK to make the title just for implementation now.
Comment #24
longwaveI get the same result as #18 when rebuilding all CSS and JS without UC Browser in the browserslist. There are no remaining references to "UC Browser" or "UCAndroid" or variants that I can find in the codebase.
Tried to add a change record at https://www.drupal.org/node/3285017 but I don't know how to explain the difference between the version we are dropping support for and the WebView version which should still continue to work.
Comment #26
catchI think the change record actually explains the extremely confusing situation pretty well.
Committed/pushed to 10.0.x, thanks!
I'll update the docs page now too.