Skip to content

fix: ignore background Cloudflare scripts on ChatGPT - #26

Merged
JJLiebig merged 1 commit into
mainfrom
fix/ignore-background-challenge-scripts
Sep 30, 2026
Merged

JJLiebig merged 1 commit into
mainfrom
fix/ignore-background-challenge-scripts

Conversation

@JJLiebig

@JJLiebig JJLiebig commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

ChatGPT loads a background Cloudflare challenge-platform script on signed-in pages. ask-pro treated its presence as a blocking challenge, even while the composer and an unrelated "Library is now Space" notice were visible.

Ignore script presence and require the Cloudflare interstitial title with no visible enabled composer before reporting a navigation challenge. Active login, MFA and CAPTCHA detection remains in place.

Validation:

  • Reproduced the failure in managed Chrome. With the fix, the same page passes navigation, passive authentication and composer readiness without submitting a prompt.
  • Regression coverage for background scripts, a stale title and a genuine interstitial; all 318 tests pass.
  • Plugin validator, build, lint/typecheck, formatting and package dry-run pass.
  • Review Suite fast: both reviewers report no findings, finalized green on commit 8969cf6.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: a991ff89-45e4-487d-b775-0ae05f927d2b

📥 Commits

Reviewing files that changed from the base of the PR and between 8980b33 and 8969cf6.

📒 Files selected for processing (5)
  • CHANGELOG.md
  • docs/windows-work.md
  • src/browser/actions/navigation.ts
  • src/browser/constants.ts
  • tests/browser/index.test.ts
💤 Files with no reviewable changes (1)
  • src/browser/constants.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Navigation now reports a Cloudflare challenge only when the page title matches the interstitial title and no visible, enabled composer is available. The challenge script selector was removed, and tests cover title, composer visibility, and script presence.

Changes

Cloudflare challenge detection

Layer / File(s) Summary
Detection logic and validation
src/browser/constants.ts, src/browser/actions/navigation.ts, tests/browser/index.test.ts, docs/windows-work.md, CHANGELOG.md
Navigation checks the title and whether a usable composer is present. Tests cover combinations of title, composer visibility, and script presence. The Windows note and changelog describe the updated behavior.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix · Severity of issue fixed: Low

Merge Risk: ⚪ Minimal · up to 8969c

The change avoids false challenge reports on usable ChatGPT pages while retaining detection of genuine interstitials. No actionable merge-blocking risk is identified; merge after normal checks pass.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 8969c

The revised check changes when navigation pauses for a challenge, not browser privileges or authentication requirements. Separate login and human-challenge checks remain. Remaining uncertainty concerns consumers of the removed export and behavior across live challenge variants.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The demonstrated exposure is the decision to continue or interrupt an existing browser navigation. The changed predicate introduces no credential operation, new destination, privileged browser command, or persistent-state write.

Security Findings and Attack Paths

  • inferred — Page-controlled title and DOM content can influence the navigation classification. Full control of those inputs could already evade the former title/script heuristic by omitting both signals. The inspected change does not establish a new independently attackable authority boundary; this does not establish that all existing browser automation paths are secure.

Trust Boundaries and Controls

  • observed — Passing the Cloudflare classifier is not itself login validation. The inspected caller subsequently invokes waitForLogin, which propagates failed checks or turns recoverable manual-login failure into a login-required interruption rather than success.

Resilience and Maintainability Implications

  • observed — The revised predicate is a read-only evaluation and creates no state requiring rollback or cleanup. Both primary and fallback navigation retain the guard before readiness; guard failures propagate, and the fallback still occurs only after readiness failure. No new retry, reservation, or ownership transition is introduced by this change.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 2 files. (2 skipped: 2 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: ignoring background Cloudflare scripts during ChatGPT navigation challenge detection.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 2 files. (2 skipped: 2 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@JJLiebig
JJLiebig merged commit 16796d7 into main Sep 30, 2026
5 checks passed
@JJLiebig
JJLiebig deleted the fix/ignore-background-challenge-scripts branch September 30, 2026 12:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant