Repository navigation
fix: Cloudflare/CAPTCHA verification failures in browser panel - #1877
Conversation
CAPTCHA providers (reCAPTCHA, hCaptcha, Cloudflare Turnstile) detect environment tampering in their cross-origin iframes. With forMainFrameOnly: false, the telemetry hooks (overridden console.*) and address bar focus tracker (__cmux* globals) run inside CAPTCHA iframes, causing challenges to fail or score the session as a bot. Change forMainFrameOnly from false to true on: - telemetryHookBootstrapScriptSource - addressBarFocusTrackingBootstrapScript Both only need to run in the top-level page context. Fixes manaflow-ai#1429
|
@Jesssullivan is attempting to deploy a commit to the Manaflow Team on Vercel. A member of the Team first needs to authorize it. |
📝 WalkthroughWalkthroughModified two WKUserScript injections in BrowserPanel to restrict execution to main frames only by changing Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~8 minutes Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment Tip You can enable review details to help with troubleshooting, context usage and more.Enable the |
Greptile SummaryThis PR fixes CAPTCHA verification failures (Cloudflare Turnstile, reCAPTCHA, hCaptcha) on the browser panel by changing
Confidence Score: 4/5
Important Files Changed
Sequence DiagramsequenceDiagram
participant WK as WKWebView
participant Main as Main Frame (claude.ai)
participant CF as Cloudflare CAPTCHA iframe
Note over WK,CF: BEFORE (forMainFrameOnly: false)
WK->>Main: inject telemetryHookBootstrap + addressBarFocusTracking
WK->>CF: inject telemetryHookBootstrap + addressBarFocusTracking
CF-->>CF: __cmux* globals & console.* overrides detected
CF-->>Main: ❌ CAPTCHA fails (bot fingerprint detected)
Note over WK,CF: AFTER (forMainFrameOnly: true)
WK->>Main: inject telemetryHookBootstrap + addressBarFocusTracking
WK--xCF: scripts NOT injected into cross-origin iframe
CF-->>CF: clean JS environment, no __cmux* pollution
CF-->>Main: ✅ CAPTCHA passes
|
There was a problem hiding this comment.
No issues found across 1 file
Since this is your first cubic review, here's how it works:
- cubic automatically reviews your code and comments on bugs and improvements
- Teach cubic by replying to its comments. cubic learns from your replies and gets better over time
- Add one-off context when rerunning by tagging
@cubic-dev-aiwith guidance or docs links (includingllms.txt) - Ask questions if you need clarification on any suggestion
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@Sources/Panels/BrowserPanel.swift`:
- Around line 2497-2502: The bootstrap script was added with forMainFrameOnly
true which prevents same-origin iframes from tagging focused controls; instead,
add the user script to all frames (remove/false the forMainFrameOnly flag on the
addUserScript call) and change Self.addressBarFocusTrackingBootstrapScript to
gate itself: run normally only when the frame is same-origin with the top
(detect with a try/catch that accesses a top-level property like
window.top.document or window.top.location to see if it throws and return early
on cross-origin), otherwise continue to install the iframe focus-relay logic so
addressBarFocusCaptureScript can see and restore focus for same-origin embedded
editors/forms.
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: e81236ec-7798-4f67-836b-02d73c81e756
📒 Files selected for processing (1)
Sources/Panels/BrowserPanel.swift
| // Main frame only — same CAPTCHA interference concern as telemetry hooks. | ||
| configuration.userContentController.addUserScript( | ||
| WKUserScript( | ||
| source: Self.addressBarFocusTrackingBootstrapScript, | ||
| injectionTime: .atDocumentStart, | ||
| forMainFrameOnly: false | ||
| forMainFrameOnly: true |
There was a problem hiding this comment.
This drops same-origin iframe focus restore.
addressBarFocusCaptureScript only sees the top document’s activeElement. The child-frame bootstrap is what tags focused controls inside iframes and relays that state upward, so making it main-frame-only means embedded same-origin editors/forms will no longer regain focus after the user leaves and re-enters the omnibar. If the CAPTCHA issue is limited to cross-origin frames, gate the bootstrap inside the script instead of disabling all subframes.
♻️ Possible fix
configuration.userContentController.addUserScript(
WKUserScript(
source: Self.addressBarFocusTrackingBootstrapScript,
injectionTime: .atDocumentStart,
- forMainFrameOnly: true
+ forMainFrameOnly: false
)
) (() => {
try {
+ if (window.top !== window) {
+ try {
+ if (window.top.location.origin !== window.location.origin) return true;
+ } catch (_) {
+ return true;
+ }
+ }
if (window.__cmuxAddressBarFocusTrackerInstalled) return true;
window.__cmuxAddressBarFocusTrackerInstalled = true;🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@Sources/Panels/BrowserPanel.swift` around lines 2497 - 2502, The bootstrap
script was added with forMainFrameOnly true which prevents same-origin iframes
from tagging focused controls; instead, add the user script to all frames
(remove/false the forMainFrameOnly flag on the addUserScript call) and change
Self.addressBarFocusTrackingBootstrapScript to gate itself: run normally only
when the frame is same-origin with the top (detect with a try/catch that
accesses a top-level property like window.top.document or window.top.location to
see if it throws and return early on cross-origin), otherwise continue to
install the iframe focus-relay logic so addressBarFocusCaptureScript can see and
restore focus for same-origin embedded editors/forms.
|
I've tested this against glab, gh; so far so good. 👀 Testing against both #1876 and an alternative JS bridge based implementation for less prescriptive webauthn context management. |
|
Thank you for the contribution! |
|
is this released yet? |
|
tried on nightly and got no luck with gitlab |
@michaelangeloio I think nightly does not have this yet, at least as of 13 hours ago- some other issues with nightly parity as well re. attestation 👀 |
Ingests all upstream fixes since 2026-03-22 including: - Fix Cmd+N crash: retain snapshot workspaces (manaflow-ai#2183, manaflow-ai#2181, manaflow-ai#2178, manaflow-ai#2173) - Fix browser pane restore after reopen (manaflow-ai#2141) - Fix Ghostty resize_split keybind (manaflow-ai#1899) - Reduce shell integration prompt latency (manaflow-ai#2109) - Fix command palette focus after terminal find (manaflow-ai#2089) - Add Codex CLI hooks (manaflow-ai#2103) - Add cmux.json custom commands (manaflow-ai#2011) - Fix window position restore on relaunch (manaflow-ai#2129) Conflict resolution: - BrowserPanel.swift: accepted upstream configureWebViewConfiguration() refactor (already includes our forMainFrameOnly:true CAPTCHA fix from PR manaflow-ai#1877) Fork-specific files preserved: - Sources/Panels/WebAuthn{Coordinator,BridgeJavaScript}.swift - Sources/FIDO2/module.modulemap - vendor/ctap2 submodule - cmux.entitlements (with camera/audio-input removed) - cmux.embedded.entitlements - .github/workflows/fork-{ci,release}.yml
…-upstream fix: Cloudflare/CAPTCHA verification failures in browser panel
Fixes #1429
telemetryHookBootstrapScriptSourceandaddressBarFocusTrackingBootstrapScriptare injected withforMainFrameOnly: false, so they run inside cross-origin CAPTCHA iframes (challenges.cloudflare.com,google.com/recaptcha,hcaptcha.com).CAPTCHA providers fingerprint the JS environment inside their iframe and detect:
console.log/warn/error/info/debug(the telemetry hook replaces all five)window.__cmux*globals (__cmuxHooksInstalled,__cmuxConsoleLog,__cmuxErrorLog,__cmuxAddressBarFocusState, etc.)This causes Cloudflare Turnstile, reCAPTCHA, and hCaptcha to fail or score the session as a bot — which is the behavior described in #1429 (Cloudflare verification stuck on
claude.aiand other protected sites).Fix:
forMainFrameOnly: false→forMainFrameOnly: true. Both scripts only need to run in the top-level page context — sub-frame telemetry isn't needed, and address bar focus tracking only applies to the main document.-Jess
Summary by cubic
Fixes CAPTCHA verification failures in the browser panel by scoping injected scripts to the main frame only. Prevents console overrides and
__cmux*globals from running inside cross-origin CAPTCHA iframes.forMainFrameOnly: truefortelemetryHookBootstrapScriptSourceandaddressBarFocusTrackingBootstrapScriptto avoid running in CAPTCHA iframes (reCAPTCHA, hCaptcha, Cloudflare Turnstile).Written for commit 9394774. Summary will update on new commits.
Summary by CodeRabbit