Skip to content

fix(desktop): set the browser user agent process-wide so Cloudflare Turnstile passes - #8192

Merged
waleedlatif1 merged 2 commits into
stagingfrom
fix/desktop-browser-captcha
Sep 23, 2026
Merged

waleedlatif1 merged 2 commits into
stagingfrom
fix/desktop-browser-captcha

Conversation

@waleedlatif1

Copy link
Copy Markdown
Collaborator

Summary

  • Cloudflare Turnstile always failed in the embedded browser ("Verification failed"). The Chrome-shaped user agent was set per session and per tab, but those overrides miss some request paths: the challenge frame's own XHR/image requests still went out with Electron's native UA (Sim/<v> … Electron/<v>). Cloudflare saw two user agents inside one challenge and rejected it as a spoof
  • Set the identity once as app.userAgentFallback at startup, before any session exists, so every request path (document, subframe, worker, challenge traffic) sends the same string; removed the per-session and per-tab overrides that only patched individual paths
  • Identity is unchanged — sites still see stock Chrome, so allowlists that reject "Electron" keep working. The app's own windows now present the same string; desktop identity already travels in X-Sim-Client-Info, and nothing parses the old tokens
  • Moved the module to src/main/user-agent.ts since it now owns process identity, not just the browser's

Type of Change

  • Bug fix

Testing

  • A/B harness on the shipped Electron build (43.5.0) against a real managed Turnstile, fresh partition per run, debugger attached exactly as the browser does: current per-session override 5/5 fail (verification error within 4–10s), process-wide fallback 5/5 pass
  • Header capture confirmed the mechanism: under the per-session override the challenge requests carried the native UA; with the process-wide fallback no request did. Workers and navigator.userAgentData/Sec-CH-UA were consistent in every arm, and the CDP debugger is not a factor
  • Added a session test that fails if a tab or session overrides the user agent again; desktop suite (1669), tsc, lint, and check:audits pass

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

🤖 Generated with Claude Code

@vercel

vercel Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Sep 23, 2026 5:40am UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 5 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@greptile-apps

greptile-apps Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

The PR appears safe to merge; the process-wide user-agent is installed before session creation, narrower overrides are removed, and the previously missing startup coverage is now present.

Summary

This PR replaces per-session and per-tab user-agent overrides with an Electron process-wide fallback installed before session creation, ensuring consistent Chrome-shaped identity across document, frame, worker, and challenge request paths.

  • Moves user-agent ownership into the desktop main-process module.
  • Removes browser-agent session and WebContents overrides.
  • Adds unit coverage for transformation and idempotent installation.
  • Adds session regression coverage against local overrides.
  • Adds an end-to-end startup test covering the first document request and subsequent fetch.
Diagram
sequenceDiagram
    participant Startup as Electron startup
    participant App as Electron app
    participant Session as Browser session
    participant Window as WebContents
    participant Site as Remote site

    Startup->>App: installBrowserUserAgent()
    App->>App: Set stock Chrome userAgentFallback
    Startup->>Session: Create session
    Session->>Window: Create and load window
    Window->>Site: Document request with fallback UA
    Window->>Site: Frame, worker, and fetch requests with same UA
Loading

Reviews (2) · Last reviewed commit: "test(desktop): cover the process-wide us..."

Comment thread apps/desktop/src/main/user-agent.test.ts
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 23, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 6 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit 230e42a into staging Sep 23, 2026
37 checks passed
@waleedlatif1
waleedlatif1 deleted the fix/desktop-browser-captcha branch September 23, 2026 06:11

This branch was previously deployed

1 inactive deployment
Preview — fbb6ed9d Deployed Sep 23, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant