--disable-web-security regression

What is the name of the domain?

every site

What is the error number?

N/A

What is the error message?

N/A

What is the issue you’re encountering

–disable-web-security breaks Turnstile

What steps have you taken to resolve the issue?

N/A

What are the steps to reproduce the issue?

  1. Launch chrome with --disable-web-security --user-data-dir="C:\temp\unlock" (Windows)
  2. Every Cloudflare Turnstile site now rejects the browser with an infinite refresh loop.

This did not happen ~two days ago and started happening around Feb 4 or 5. I am guessing it is a recent code change.
It would be nice if Turnstile did not break this as it is required for accessibility reasons for many folks, as well as for integration tests.

I’ve tried eveything too, I’ve seen a lot of other people having this issues. Can we please get someone from this site to help us out? It’s going on 5 days now and this issue is still going on. I’ve tried eveything possible to fix this.

Does it happen in Chrome Incognito mode as well? :thinking:

I cannot reproduce this error and behaviour on my Websites using Turnstile from both local ISP and mobile provider.

Yea I’ve tried incognito mode, I’ve disabled all my ad blockers and eveything and still same issue. I’m using a unlocked version of chrome so idk if that’s the issue. My friend had me get it so I can use one of the extensions.

disable-web-security --user-data-dir=“C:\temp\unlock” this is the line that is in my startup for chrome. Or something like that, sorry I’m not very smart with pc stuff, but when I open chrome I see this message. you are using an unsupported command line flag disable web security, but I’ve had this for months and no issues before till the a few days ago.

May I ask why you’ve added this parameters at all? :thinking:

This is not by default. Why were you told to enable and use that in the first place?

Might want to remove it and then disable the option as suggested on the other forums:

If the extension you’re using is not valid nor in Google Chrome Store, I’d not advise continue using it due to the possible security issue.

Make new installation full or upgrade your Chrome, or use another Web browser.

I’ve been using it for for a year with no issue till a few days ago. The extension is fine and isn’t the problem at all. It’s whatever just rolled out not to long ago. Also I didn’t add that it just came that way when I DL. It’s a translator extension and thats the only way it works on certain websites.

Also the extension is in the Google chrome store

I’m having exactly the same issue; a fix would be appreciated.

1 Like

I don’t think infinite refreshing is appropriate UI for Turnstile issues. I believe:

  1. An error should be shown giving detailed issues on the problem and how to resolve.
  2. Or better, an alternate captcha the user can solve should be shown.
1 Like

Also thiis is not a accepted solution so i dont know why you marked it as that nothing has been solved at all

But why are you enabling that flag?

1 Like

Chrome extensions need it to access images on websites with strict CORs requirements. For example, if you have say, an extension that reads a caption of an image using AI because you’re blind, this flag is required for the extension to even have permissions to read the image.

1 Like

Also how is this topic about to close when nothing has been solved just wondering.

If this Chrome flag is breaking Turnstile functionality while Turnstile works normally, I am afraid Cloudflare cannot help here and wouldn’t adopt their code to allow such scenario, which might disable the function of the Turnstile itself allowing bad bots to bypass it, etc.

Turnstile seemed to work fine with the flag a week ago. Perhaps instead of breaking many users workflows, an alternate fallback captcha could be shown.

So curious how can you explain why it worked a week ago and now it dont? plus its been working for well over a year now

Kindly, create another topic and post in Feature Request Submitting & Feedback with brief details of the usage of that Chrome flag to see if we can get it looked and fixed by Cloudflare Developers in the meantime.

Otherwise, I’d suggest you to create a ticket about this case and provide HAR with all the needed helpful information onto it for better troubleshooting for the devs.

1 Like

Thanks will do

1 Like

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.