What version of the Codex App are you using (From “About Codex” dialog)?
Version 26.616.51431
What subscription do you have?
pro €225/month
What platform is your computer?
No response
What issue are you seeing?
Codex silently refuses to load certain sites using the Chrome plugin.
there seems to be a server-side blacklist of sites that Codex refuses to load. When you try and access one of these sites, the browser plugin throws an error:
Browser Use rejected this action due to browser security policy.
Reason: Browser Use is not permitted on https://detail.1688.com.
these sites aren't malicious or don't seem to be against TOS or anything: normal e-commerce sites such as Taobao or 1688.com.
futhermore, this isn't documented anywhere either.
Philosophically, having a web browser that decides - server side - which websites it can and can't load, without any transparency on this, it's not great. I could (grudgingly) understand if the sites are malicious/pornographic/illegal/etc, but these are genuine huge e-commerce sites - the Western equivalent of blocking Amazon or Walmart. More broadly, silently blocking sites in a non-transparent/undocumented way doesn't feel right either.
It seems like you ALSO can't even use Computer Use on Chrome if a tab is open from one of the "non-permitted" websites:
mcp__computer_use.get_app_state({
"app": "Google Chrome"
})
// returns:
[{"type":"text","text":"This session has been stopped because Computer Use is not allowed on the current browser URL. Stop your work and send a final message noting why the session has been ended. Note that Computer Use is not allowed on this URL even if the user navigates to it themselves."}]
Obviously I could monkey-patch around this by modifying the javascript plugin or computer use.... but that's not an okay workaround either. Computer use, Chrome, and the Browser plugin should just work on all (legal) sites.
What steps can reproduce the bug?
Feedback ID: 019ee97a-589a-7670-9b4c-a7eadac555ba
What is the expected behavior?
The built in plugins do not run a server-side check to see if users are permitted to look at a certain site or not.
Additional information
Codex investigated the issue further, a brief summary (before we get the clanker to attach a big slop comment of everything it found):
- On every request, the Chrome plugin will make a request to
https://chatgpt.com/backend-api/aura/site_status, if this endpoint returns something, the request will be blocked
- chrome plugin code:
/Users/<me>/.codex/plugins/cache/openai-bundled/chrome/26.616.51431/scripts/browser-client.mjs:3234
What version of the Codex App are you using (From “About Codex” dialog)?
Version 26.616.51431
What subscription do you have?
pro €225/month
What platform is your computer?
No response
What issue are you seeing?
Codex silently refuses to load certain sites using the Chrome plugin.
there seems to be a server-side blacklist of sites that Codex refuses to load. When you try and access one of these sites, the browser plugin throws an error:
these sites aren't malicious or don't seem to be against TOS or anything: normal e-commerce sites such as Taobao or 1688.com.
futhermore, this isn't documented anywhere either.
Philosophically, having a web browser that decides - server side - which websites it can and can't load, without any transparency on this, it's not great. I could (grudgingly) understand if the sites are malicious/pornographic/illegal/etc, but these are genuine huge e-commerce sites - the Western equivalent of blocking Amazon or Walmart. More broadly, silently blocking sites in a non-transparent/undocumented way doesn't feel right either.
It seems like you ALSO can't even use Computer Use on Chrome if a tab is open from one of the "non-permitted" websites:
Obviously I could monkey-patch around this by modifying the javascript plugin or computer use.... but that's not an okay workaround either. Computer use, Chrome, and the Browser plugin should just work on all (legal) sites.
What steps can reproduce the bug?
Feedback ID: 019ee97a-589a-7670-9b4c-a7eadac555ba
What is the expected behavior?
The built in plugins do not run a server-side check to see if users are permitted to look at a certain site or not.
Additional information
Codex investigated the issue further, a brief summary (before we get the clanker to attach a big slop comment of everything it found):
https://chatgpt.com/backend-api/aura/site_status, if this endpoint returns something, the request will be blocked/Users/<me>/.codex/plugins/cache/openai-bundled/chrome/26.616.51431/scripts/browser-client.mjs:3234