Skip to content

Gate Flow CAPTCHA generation after account-safety reports - #68

Draft
raducupreda-art wants to merge 1 commit into
crisng95:mainfrom
raducupreda-art:codex/flowkit-account-safety
Draft

raducupreda-art wants to merge 1 commit into
crisng95:mainfrom
raducupreda-art:codex/flowkit-account-safety

Conversation

@raducupreda-art

@raducupreda-art raducupreda-art commented Sep 27, 2026 •

Copy link
Copy Markdown

Issue #67 reports two Google accounts unable to generate even in the manual Flow UI after FlowKit testing. That timing is concerning, but it does not establish that FlowKit or PR #64 caused the restriction.

Before this change, FlowKit paused for only 30/120 seconds after hijack or unusual-activity signals; the worker could requeue hijack failures without counting a retry, and generic CAPTCHA failures could be retried repeatedly. The extension also auto-injected the hijack bypass and could mint more than once.

This draft makes CAPTCHA-bearing generation opt-in (FLOW_ENABLE_CAPTCHA_GENERATION=1) and serializes it. It writes a durable in-flight marker before requesting a token, then keeps a persistent safety hold after unusual-activity, hijack, CAPTCHA, or uncertain transport failures. The hold survives restart and cannot be cleared by /api/flow/clear-hijack. The extension no longer auto-loads the hijack bypass or a second reCAPTCHA runtime, uses at most one public mint attempt, and rejects tokens returned by stale tabs without a verified mint-path diagnostic. Read-only media and polling RPCs remain available. README, dashboard, extension, and troubleshooting docs warn testers and distinguish extension-only failures from a manual Flow UI block; no Google recovery time is claimed.

Offline validation: 275 Python unit tests (excluding three unrelated Windows/environment-dependent modules), 10 Node extension tests, JS syntax checks, and git diff --check passed. The full Python unit run surfaced existing setup/CLI encoding and Windows symlink failures outside the changed paths. One bounded FlowKit canary was attempted in AdsPower FLOW 1 (one still, one attempt, no references). The patched extension returned EXTENSION_HIJACK_DETECTED before token minting or a generation RPC; the server persisted an extension_hijack_detected hold and stopped further requests. Read-only page inspection showed no old FlowKit bypass object (window.__fk_hijack absent), while the page's public execute wrapper contained the extension_hijack_detected marker. No image was generated. This validates the fail-closed path, not generation success; manual Flow UI access on this account was not established by this test.

This is a temporary safety mitigation, not a root-cause fix. The opted-in mint path needs separate live verification using a disposable account before any release.

@crisng95

Copy link
Copy Markdown
Owner

wait me for testing

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants