Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 6 additions & 2 deletions Sources/Panels/BrowserPanel.swift
Original file line number Diff line number Diff line change
Expand Up @@ -2482,20 +2482,24 @@ final class BrowserPanel: Panel, ObservableObject {
// Enable JavaScript
configuration.defaultWebpagePreferences.allowsContentJavaScript = true
// Keep browser console/error/dialog telemetry active from document start on every navigation.
// Main frame only — injecting into cross-origin iframes causes CAPTCHA providers
// (reCAPTCHA, hCaptcha, Cloudflare Turnstile) to detect the overridden console.*
// methods and __cmux* globals as environment tampering, failing the challenge.
configuration.userContentController.addUserScript(
WKUserScript(
source: Self.telemetryHookBootstrapScriptSource,
injectionTime: .atDocumentStart,
forMainFrameOnly: false
forMainFrameOnly: true
)
)
// Track the last editable focused element continuously so omnibar exit can
// restore page input focus even if capture runs after first-responder handoff.
// Main frame only — same CAPTCHA interference concern as telemetry hooks.
configuration.userContentController.addUserScript(
WKUserScript(
source: Self.addressBarFocusTrackingBootstrapScript,
injectionTime: .atDocumentStart,
forMainFrameOnly: false
forMainFrameOnly: true
Comment on lines +2497 to +2502

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor

This drops same-origin iframe focus restore.

addressBarFocusCaptureScript only sees the top document’s activeElement. The child-frame bootstrap is what tags focused controls inside iframes and relays that state upward, so making it main-frame-only means embedded same-origin editors/forms will no longer regain focus after the user leaves and re-enters the omnibar. If the CAPTCHA issue is limited to cross-origin frames, gate the bootstrap inside the script instead of disabling all subframes.

♻️ Possible fix
         configuration.userContentController.addUserScript(
             WKUserScript(
                 source: Self.addressBarFocusTrackingBootstrapScript,
                 injectionTime: .atDocumentStart,
-                forMainFrameOnly: true
+                forMainFrameOnly: false
             )
         )
     (() => {
       try {
+        if (window.top !== window) {
+          try {
+            if (window.top.location.origin !== window.location.origin) return true;
+          } catch (_) {
+            return true;
+          }
+        }
         if (window.__cmuxAddressBarFocusTrackerInstalled) return true;
         window.__cmuxAddressBarFocusTrackerInstalled = true;
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@Sources/Panels/BrowserPanel.swift` around lines 2497 - 2502, The bootstrap
script was added with forMainFrameOnly true which prevents same-origin iframes
from tagging focused controls; instead, add the user script to all frames
(remove/false the forMainFrameOnly flag on the addUserScript call) and change
Self.addressBarFocusTrackingBootstrapScript to gate itself: run normally only
when the frame is same-origin with the top (detect with a try/catch that
accesses a top-level property like window.top.document or window.top.location to
see if it throws and return early on cross-origin), otherwise continue to
install the iframe focus-relay logic so addressBarFocusCaptureScript can see and
restore focus for same-origin embedded editors/forms.

)
)
}
Expand Down
Loading