Skip to content

fix(core): stop reading a form Turnstile loader as a bot wall - #95

Merged
k2kirov merged 1 commit into
staging/false-positive-fixesfrom
fix/turnstile-form-scope-commerce
Oct 6, 2026
Merged

k2kirov merged 1 commit into
staging/false-positive-fixesfrom
fix/turnstile-form-scope-commerce

Conversation

@k2kirov

@k2kirov k2kirov commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Follow-up to #86. A readable storefront that loads the Turnstile api.js for its forms still drew three findings.

  • cart-handoff-reachability: fails only when the cart response is a challenge page (via detectWafProtection) or a widget on a document with under 200 characters of text. A readable cart with a form widget passes.
  • no-bot-detection: passes a loader on a page that served readable text, as its dossier's counter-evidence (grade D for a form-scoped widget) and required fix ask. The WAF branch is unchanged.
  • no-blocking-captcha: matches vendor script[src] and widget elements (.g-recaptcha, .h-captcha, .cf-turnstile) instead of the vendor name. A real widget on a form still warns.
  • Dossier deviations for all three; interactive vs invisible split deferred. Patch.

Real-page corpus moves (reviewed one by one): 9 fixtures go warn→pass for no-blocking-captcha and/or no-bot-detection. Every old match was a vendor name in inline JS (Shopify's storefront-forms token list), config keys (recaptchaSiteKey), a CSP host list, or product prose (a pricing page listing "Turnstile"). walmart-com-wall-200 is the readable 823-word help page the corpus notes already reclassify as page; its only match was CSP text.

Verification: full gate green (5531 tests).

A readable storefront that loads the Turnstile api.js for its forms
still drew three findings. cart-handoff-reachability now fails only a
cart that is a challenge page or only a widget. no-bot-detection passes
a loader on a page the scan could read. no-blocking-captcha matches
vendor script src and widget elements instead of the vendor name, so
inline config, CSP lists and prose no longer match.
@k2kirov
k2kirov merged commit 1da406e into staging/false-positive-fixes Oct 6, 2026
@k2kirov
k2kirov deleted the fix/turnstile-form-scope-commerce branch October 6, 2026 10:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant