feat: bypass extension_hijack_detected + Trusted Types CSP - #64
Merged
Merged
Conversation
Extension v0.5.2:
- hijack_bypass.js: capture pristine grecaptcha.enterprise.execute before
Flow's x2a trap replaces it with extension_hijack_detected action
- injected.js: 3-level bypass (pristine → Object.assign neuter → legacy)
- manifest.json: inject all MAIN world scripts via manifest content_scripts
to bypass Trusted Types CSP (require-trusted-types-for 'script')
- content.js: removed createElement('script') injection, keep message bridge
- background.js: RPC label mapping for side panel (Gen Video, Upload Image, etc)
Agent:
- flow_client.py: distinguish [HIJACK] errors (30s cooldown) from abuse blocks (120s)
- processor.py: [HIJACK] errors don't burn retry counts
- flow.py: POST /api/flow/clear-hijack endpoint for manual cooldown reset
PeerapolSelanon
added a commit
to PeerapolSelanon/flowkit
that referenced
this pull request
Sep 28, 2026
Brings in project-session leases + real Flow project creation, the generation guard that stops retrying PUBLIC_ERROR_UNUSUAL_ACTIVITY, Omni payload sync, and direct multipart image uploads. Deliberately stops before crisng95#62 (1eae10b) and crisng95#64 (083fed7): both exist to evade Flow's detection of extension-minted reCAPTCHA tokens. fk-doctor keeps our 1080p-upscale wording for UNSUPPORTED_ON_BATCH_API. CLAUDE.md updated: POST /api/projects creates Flow projects again. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes
Extension (v0.5.2)
grecaptcha.enterprise.executebefore Flow'sx2atrap replaces it withextension_hijack_detectedactioncontent_scriptsto bypass Trusted Types CSPcreateElement('script')injection, keep message bridge onlyAgent
[HIJACK]errors (30s cooldown) from abuse blocks (120s)[HIJACK]errors don't burn retry countsPOST /api/flow/clear-hijackendpoint for manual cooldown resetTested