Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 14 additions & 4 deletions docs/captcha-method-reference.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# CAPTCHA native method reference

Companion to [CAPTCHA provider coverage](captcha-provider-coverage.md). Audited 2026-09-29. Generated from the executable catalog; 197 method variants across seven providers. Method IDs select an adapter contract, not an arbitrary upstream task type. Fixed values are added automatically. Fields use dot paths for nested objects; pass nested JSON, not literal dotted keys.
Companion to [CAPTCHA provider coverage](captcha-provider-coverage.md). Contracts rechecked 2026-10-01. Generated from the executable catalog; 198 method variants across seven providers. Method IDs select an adapter contract, not an arbitrary upstream task type. Fixed values are added automatically. Fields use dot paths for nested objects; pass nested JSON, not literal dotted keys.

Required fields below are unconditional. GeeTest v3 additionally needs `gt` and a fresh `challenge`; v4 needs its provider-specific CAPTCHA ID. AWS WAF variants, proxy authentication, alternate image inputs, and VisionEngine module-specific fields have conditional requirements described in the guide and official documentation. Every submitted value must come from the selected challenge.

Expand Down Expand Up @@ -472,15 +472,15 @@ Family: `funcaptcha_recognition`. [Official contract](https://2captcha.com/api-d
Family: `geetest`. [Official contract](https://2captcha.com/api-docs/geetest).

- Required: `websiteURL` (string).
- Optional: `gt` (string), `challenge` (string), `geetestApiServerSubdomain` (string), `userAgent` (string), `version` (integer), `initParameters` (object), `risk_type` (string).
- Optional: `gt` (string), `challenge` (string), `geetestApiServerSubdomain` (string), `userAgent` (string), `version` (integer), `initParameters` (object), `riskType` (string).
- Fixed wire values: `{"type":"GeeTestTaskProxyless"}`.

### GeeTestTask

Family: `geetest`. [Official contract](https://2captcha.com/api-docs/geetest).

- Required: `websiteURL` (string), `proxyType` (string), `proxyAddress` (string), `proxyPort` (integer).
- Optional: `gt` (string), `challenge` (string), `geetestApiServerSubdomain` (string), `userAgent` (string), `version` (integer), `initParameters` (object), `risk_type` (string), `proxyLogin` (string), `proxyPassword` (string).
- Optional: `gt` (string), `challenge` (string), `geetestApiServerSubdomain` (string), `userAgent` (string), `version` (integer), `initParameters` (object), `riskType` (string), `proxyLogin` (string), `proxyPassword` (string).
- Fixed wire values: `{"type":"GeeTestTask"}`.

### GridTask
Expand Down Expand Up @@ -805,6 +805,8 @@ Family: `aws_waf`. [Official contract](https://docs.capmonster.cloud/docs/captch
- Optional: `cookieSolution` (boolean), `proxyType` (string), `proxyAddress` (string), `proxyPort` (integer), `proxyLogin` (string), `proxyPassword` (string).
- Fixed wire values: `{"type":"AmazonTask"}`.

`context` and `iv` must be supplied as empty strings in this invisible-challenge mode (CapMonster Option 3).

### BinanceTask

Family: `binance`. [Official contract](https://docs.capmonster.cloud/docs/captchas/binance/).
Expand Down Expand Up @@ -1281,7 +1283,7 @@ Family: `recaptcha_v3_enterprise`. [Official contract](https://solvecaptcha.com/
- Optional: `domain` (string), `action` (string), `min_score` (number), `proxy` (string), `proxytype` (string), `cookies` (string), `userAgent` (string).
- Fixed wire values: `{"method":"userrecaptcha","version":"v3","enterprise":1}`.

## anti-captcha (23 variants)
## anti-captcha (24 variants)

### AltchaTask

Expand Down Expand Up @@ -1317,6 +1319,14 @@ Family: `aws_waf`. [Official contract](https://anti-captcha.com/apidoc/task-type
- Optional: `captchaScript` (string), `challengeScript` (string).
- Fixed wire values: `{"type":"AmazonTaskProxyless"}`.

### AmazonTaskProxyless:widget

Family: `aws_waf`. [Official contract — select Widget](https://anti-captcha.com/apidoc/task-types/AmazonTaskProxyless).

- Required: `websiteURL` (string), `websiteKey` (string), `jsapiScript` (string).
- Fixed wire values: `{"type":"AmazonTaskProxyless","wafType":"widget"}`.
- `websiteKey` is the observed `AwsWafCaptcha.renderCaptcha` API key; `jsapiScript` is the observed SDK URL. It is not the interstitial `gokuProps.key`.

### AntiGateTask

Family: `antigate`. [Official contract](https://anti-captcha.com/apidoc/task-types/AntiGateTask).
Expand Down
51 changes: 44 additions & 7 deletions docs/captcha-provider-coverage.md

Large diffs are not rendered by default.

4 changes: 3 additions & 1 deletion docs/slash-commands.md
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,7 @@ for its available flags.
| `/print` | Open the current page's native print dialog |
| `/screenshot [--full-page]` | Capture the visible tab, or the full scrollable page with `--full-page` (Chrome only) |
| `/record [--full-screen] [--hide-recording-indicator] [--transcribe]` | Record the current tab, or a selected screen/window with `--full-screen` (Chrome only); add `--hide-recording-indicator` to hide the banner or `--transcribe` to save a transcript after stop |
| `/export [--traces \| --config]` | Download version-stamped conversation Markdown, export the version-stamped tool chain with `--traces`, or export a Settings snapshot with `--config` |
| `/export [--traces [--full] \| --config]` | Download version-stamped conversation Markdown, export the version-stamped tool chain with `--traces`, add `--full` for the complete stored session JSON including screenshots, or export a Settings snapshot with `--config` |
| `/import <json>` | Import a Settings snapshot pasted inline |
| `/import --file` | Choose and import a Settings snapshot JSON file |
| `/profile` | Toggle profile auto-fill on/off without opening Settings |
Expand Down Expand Up @@ -154,3 +154,5 @@ version:
before download. Import normalizes it again, assigns a fresh local ID and
timestamps, and never overwrites an existing workflow, so the same file can
safely move between Chrome, Firefox, and WebBrain Cloud.

`/export --traces --full` uses the same versioned JSON format as the Traces page, without Markdown preview truncation or the 500-turn Markdown limit. It exports recorded data only: earlier recording omissions remain marked, and the panel reports when they exist. Content and screenshots follow the recording privacy setting; the command does not enable lossless recording retroactively. Essential solver outcomes remain available even when the lossless content budget fills.
4 changes: 4 additions & 0 deletions docs/trace-format-compatibility.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,10 @@ WebBrain's trace data has three independent version layers:

## Reader obligations

Tool events may include an optional `data.outcome` summary containing bounded dispatch, application, provider, error, and CAPTCHA-gate diagnostics. In lossless recordings, this summary survives the content-budget marker, while answer tokens, cookies, provider keys, and form inputs are excluded from the summary. Readers should still honor `_truncated` and `losslessBudgetOmitted`; the summary does not reconstruct discarded content.

`/export --traces --full` exports the stored conversation through the existing `webbrain-trace/1` session envelope, including stored screenshots. It adds no Markdown preview or turn-count truncation. Recording-time omissions and privacy projections remain explicit. The side panel reads the shared trace database and assembles the download locally; only the session identity crosses runtime messaging, so screenshot-heavy exports do not hit the browser message-size limit.

Treat a missing or malformed `traceFormatVersion` as the legacy baseline. Keep
missing optional fields harmless. Reject a numeric `traceFormatVersion` newer
than the latest version the reader supports instead of interpreting `seq` and
Expand Down
4 changes: 2 additions & 2 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

5 changes: 3 additions & 2 deletions package.json
Original file line number Diff line number Diff line change
@@ -1,12 +1,13 @@
{
"name": "webbrain",
"version": "38.0.1",
"version": "38.0.12",
"description": "Open-source AI browser agent \u2014 chat with pages, automate tasks, multi-provider LLM support.",
"private": true,
"type": "module",
"scripts": {
"test": "npm run test:cms && npm run test:markdown && npm run test:systemone && npm run test:systemone:fast && node --test test/browser-dialogs.mjs test/capsolver-cloud-broker.mjs test/captcha-providers.mjs test/captcha-weighted-fallback.mjs test/captcha-hcaptcha-providers.mjs test/captcha-native-providers.mjs test/captcha-runtime-policy.mjs && npm run test:firefox-bidi && npm run test:runtime-lifecycle && npm run test:provider-limits && npm run test:accessibility-tree-benchmark && npm run test:toolbar-guard && npm run test:discord && npm run test:pdf-read && npm run test:pdf-selection && npm run test:social-contract && npm run test:safesocial && npm run test:build-unpacked && npm run test:attachment-drop && npm run test:workflow-editor && node --test test/profile-sync-stats.mjs && node test/run.js && node test/selection-scope-restoration.mjs && node scripts/benchmark-offline-relevance.mjs && npm run test:security",
"test": "npm run test:cms && npm run test:markdown && npm run test:systemone && npm run test:systemone:fast && node --test test/browser-dialogs.mjs test/capsolver-cloud-broker.mjs test/captcha-providers.mjs test/captcha-weighted-fallback.mjs test/captcha-hcaptcha-providers.mjs test/captcha-native-providers.mjs test/captcha-runtime-policy.mjs test/captcha-callback-bridge.mjs test/captcha-aws-recovery.mjs test/captcha-documented-contracts.mjs test/huggingface-signup-recovery.mjs test/trace-full-export.mjs && npm run test:firefox-bidi && npm run test:runtime-lifecycle && npm run test:provider-limits && npm run test:accessibility-tree-benchmark && npm run test:toolbar-guard && npm run test:discord && npm run test:pdf-read && npm run test:pdf-selection && npm run test:social-contract && npm run test:safesocial && npm run test:build-unpacked && npm run test:attachment-drop && npm run test:workflow-editor && node --test test/profile-sync-stats.mjs && node test/run.js && node test/selection-scope-restoration.mjs && node scripts/benchmark-offline-relevance.mjs && npm run test:security",
"test:captcha:ui": "node test/captcha-settings-ui.mjs && node test/captcha-application-ui.mjs",
"test:captcha:bridge:ui": "node test/captcha-callback-bridge-ui.mjs",
"test:provider-limits": "node test/provider-model-limits.mjs",
"test:markdown": "node --test test/markdown-render.mjs",
"test:accessibility-tree-benchmark": "node --test test/llm/lib/accessibility-tree-formats.test.mjs && node test/llm/accessibility-tree-benchmark.mjs --no-exact-tokenizer --check",
Expand Down
2 changes: 1 addition & 1 deletion src/chrome/ARCHITECTURE.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# WebBrain Chrome/Edge Extension — Architecture

> Version 38.0.1 · Manifest V3 · Service Worker background
> Version 38.0.12 · Manifest V3 · Service Worker background

## High-Level Overview

Expand Down
10 changes: 9 additions & 1 deletion src/chrome/manifest.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"manifest_version": 3,
"name": "WebBrain",
"version": "38.0.1",
"version": "38.0.12",
"description": "Open-source AI browser agent — chat with pages, automate tasks, multi-provider LLM support.",
"permissions": [
"sidePanel",
Expand Down Expand Up @@ -45,6 +45,14 @@
"type": "module"
},
"content_scripts": [
{
"matches": ["<all_urls>"],
"js": ["src/content/captcha-callback-bridge.js"],
"run_at": "document_start",
"world": "MAIN",
"all_frames": true,
"match_about_blank": true
},
{
"matches": ["<all_urls>"],
"js": ["src/content/file-picker-guard-page.js"],
Expand Down
4 changes: 4 additions & 0 deletions src/chrome/src/agent/adapters.js
Original file line number Diff line number Diff line change
Expand Up @@ -15904,6 +15904,10 @@ const ADAPTERS = [
category: 'general',
matches: (url) => /^https?:\/\/(?:www\.)?huggingface\.co(?:[/?#]|$)/i.test(url),
notes: `
- Signup at /join follows the observed credentials, profile, and email-verification stages. CAPTCHA challenges are conditional; never assume one from a person's name, country, IP, or geography, and never trigger solving or reload on a challenge-free path.
- Only when an actual CAPTCHA interrupts signup, follow the runtime CAPTCHA gate. A solved widget or applied AWS cookie is not account-creation evidence. Reload only when the runtime explicitly requests it, then inspect the current root form before choosing the next action.
- If the runtime signup checkpoint reports a reset, resume the visible stage with the original user-provided values and fresh refs. Preserve populated fields; restore only missing requested profile details and the original avatar, reusing its saved download/attachment handle when available. If the form survived, continue it without restarting.
- Before repeating Create Account after an interruption, reconcile signed-in state, verification-pending notices, and already-registered messages. Continue verification or sign-in for the same account when established; stop if creation remains uncertain. Never create another identity or blindly replay a submission. Verify account creation, email verification, profile saving, and any requested access-token creation each from its own observed success evidence.
- Repository upload routes expose two file inputs. Use \`input[type="file"]:not([accept])\` for repository files; \`input[type="file"][accept*="image"]\` belongs to the extended-description editor and does not stage a repository file.
- When the repository input already exists, call \`upload_file\` directly; do not click "Upload file(s)" or the drop zone first.
- A filename chip, generated commit summary, and enabled "Commit changes" button mean the file is staged only. Click "Commit changes", wait, and verify the file under "Files and versions" before reporting upload success.
Expand Down
Loading
Loading