Skip to content

fix(core): avoid Turnstile form bot-wall alerts - #86

Merged
k2kirov merged 3 commits into
mainfrom
fix/turnstile-form-false-positive
Oct 6, 2026
Merged

k2kirov merged 3 commits into
mainfrom
fix/turnstile-form-false-positive

Conversation

@k2kirov

@k2kirov k2kirov commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

A storefront can return HTTP 200 with readable content, but its form-scoped Turnstile loader caused the scanner to report a Cloudflare bot wall and deny content audit evidence.

Remove the shared challenges.cloudflare.com hostname from wall detection. Keep explicit challenge headers, refusal responses and interstitial markers, and recognise the managed challenge-page loader. This preserves form CAPTCHA warnings while removing the false site-wide access wall. Add a patch changeset and record the correction in the evidence dossier.

Validation:

  • Reproduced the false wall with failing script and preconnect regression tests before the fix.
  • Added coverage for non-blocking JavaScript Detections, HTTP 200 managed challenge loaders and the detector-to-scan-evidence path.
  • Regression tests use inline HTML and mock responses at shop.test; they make no live requests and require no external site's markup.
  • Focused detector, scan evidence and hostile-state contract suites: 453 tests passed.
  • Manual live storefront scan: wafProtection: null, score 60, gated mass 0; completed in 35.3 seconds without exhausting its 60-second budget.
  • All seven repository gates passed in order: build, full tests (including live-site tests), typecheck, lint, dossier agreement, declared requirements and audit map.
  • Re-ran all seven gates after making the fixtures generic, with AL_SKIP_NETWORK=1 for the test suite: 5,421 tests passed, 251 skipped. Live-site verification was deliberately disabled for this run.

@k2kirov
k2kirov merged commit 8866724 into main Oct 6, 2026
1 check passed
@k2kirov
k2kirov deleted the fix/turnstile-form-false-positive branch October 6, 2026 07:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant