Repository navigation
Keep agents' browser from being flagged as a bot, with a bot check in Settings (GODM-34) - #34
Merged
Merged
Conversation
… Settings (GODM-34) Managed Chromium starts with AutomationControlled disabled; headless it gets the user agent the same Chrome sends with a window and a desktop screen, and browser-use no longer emulates a viewport larger than the window. Settings → Browser can turn it off and runs a bot check that shows, signal by signal, what bot detection sees in the default profile's browser.
Never let a failed user-agent probe reject; a browser started for a bot check or an import is only stopped if nobody else got it meanwhile; browser-use follows how the running browser was started; profiles report their running mode so the UI only offers a restart when the running browser differs, keeping its mode.
# Conflicts: # README.md # apps/desktop/src/lib/api.ts # packages/core/src/browser/manager.ts # packages/core/test/fixtures/runner-harness.ts # packages/shared/src/models.ts
Resolve browserMcpServer for on-demand browsers (GODM-30): browser-use's config follows the running browser, else the run's launch settings. Borrowed browsers count their borrowers and stop only if the last one hands back the same browser. The user-agent probe tries once (5 s), remembers a failure for 10 minutes and is cancelled on shutdown. A bot check window that is the browser's last page stays open as a blank spare.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes GODM-34.
Many sites block browsers that look automated, or bury them in CAPTCHAs. Godmode's browser now hides the signals they look for, so to those sites the agents' browser looks like a normal Chrome. Settings → Browser → Bot detection has a switch for this (on by default). It also has a bot check that shows, signal by signal, what bot detection sees in the agents' browser.
What changes in the browser
--disable-blink-features=AutomationControlled, sonavigator.webdriverstays false on every build. The Chrome inside a VM gets it too.HeadlessChrome/154…, and many sites block that on sight. Godmode now asks the installed Chrome once which user agent it sends with a window, and starts headless Chrome with that one (--user-agent). It learns this from a throwaway headless launch, once per executable and version. Because it's a launch flag, requests, frames, workers and service workers all agree.--user-agentis set, Chrome withholds the detailed client hints (full version). Only sites that ask for them notice, and the check reports it as a warning. A visible window passes all 10 checks.Bot check
POST /api/browser/profiles/:id/bot-checkopens a page in a background window of the profile's browser. The page is served by a throwaway server on 127.0.0.1. The check then judges ten signals the way common bot detection does, and marks each pass, warn or fail:navigator.webdriverwindow.chromeIn Settings you get a verdict, a 10-segment meter and one row per signal.
Testing
pnpm typecheckpasses for shared, core and desktop, and the desktop build passes.All core tests pass on the merged
main: 755 pass, 10 skip, 0 fail.The browser-use end-to-end test (
GODMODE_E2E=1, real browser-use against headless Chrome) passes.The new
browser-stealth.test.tscovers:Edg/part)cdp-integration.test.tsagainst real Chrome:HeadlessChromeTwo independent code reviews. The first found one high and two medium issues:
All three and most low findings are fixed. The follow-up review confirmed the fixes and the merge with GODM-28/GODM-30 (per-chat tabs, browsers started on demand).
Manually tested in an isolated dev instance, headless and visible, in light and dark mode: