Skip to content

Fix CAPTCHA callback delivery and post-solve recovery - #3117

Merged
webbrain-one merged 12 commits into
mainfrom
codex/captcha-callback-recovery
Oct 1, 2026
Merged

webbrain-one merged 12 commits into
mainfrom
codex/captcha-callback-recovery

Conversation

@esokullu

@esokullu esokullu commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

An enabled CAPTCHA provider could return a token that never reached the site's completion callback, leaving the page and agent blocked. Pending provider responses, token-only answers, manual completion, and same-URL reloads could also leave the solve state stuck or permit another paid attempt.

This mirrors the recovery fixes across Chrome and Firefox:

  • Capture widget-bound closure callbacks for hCaptcha, Turnstile, and reCAPTCHA at document start, including hCaptcha async execution. Deliver the token once, keep response getters consistent, and require fresh page evidence before clearing the gate.
  • Poll recognized NopeCHA and CapSolver pending responses on the existing job. Persist paid-attempt locks before dispatch and retain them across worker restarts and same-document URL changes.
  • Save token-only answers for explicit application, invalidate stale answers after document replacement, resume after verified manual completion or reload, and allow failed/partial completion without requiring another solve.

Validation on the committed snapshot:

  • Main suite: 2,420 passed, 0 failed.
  • 545 focused CAPTCHA checks passed.
  • 60 security checks passed.
  • Eight local browser integration cases passed with the extensions loaded in Chrome and Firefox, covering token delivery, page continuation, and gate clearance.

Reload the updated extension and refresh an existing CAPTCHA page before retrying so its callbacks can be captured. Live paid-provider acceptance on Hugging Face was not exercised.

@vercel

vercel Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
webbrain Ready Ready Preview Oct 1, 2026 4:46am UTC

Request Review

Codex release-state test added 2 commits September 30, 2026 11:38
Codex release-state test added 2 commits September 30, 2026 11:48
Models routinely fill the optional callback object with schema placeholders
like `{ name: '', path: '' }`. Those bindings used to fail validation and
request the EXECUTE_JS capability, so a cookie-only AWS WAF application
was rejected after a paid solve and the answer had to be bought again.

Share isEmptyCaptchaCallback() between application and permission checks so
an unused callback is treated as omitted, and make the rejection message
point at the stored answer instead of another solve.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Use documented AWS widget and invisible-challenge fallback modes, preserve structured answers, validate provider parameters before spending, and enforce required browser identity during application.

Retain task-bound Hugging Face signup progress across observed CAPTCHA interruptions. Add mirrored regression coverage and update integration references.
@webbrain-one
webbrain-one merged commit 499d560 into main Oct 1, 2026
7 checks passed

This branch was successfully deployed

1 active deployment
Preview — 2ba230db Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants