Skip to content

Chrome plugin, browser and computer use refuse to interact with certain sites. #29343

Description

@joshp123

What version of the Codex App are you using (From “About Codex” dialog)?

Version 26.616.51431

What subscription do you have?

pro €225/month

What platform is your computer?

No response

What issue are you seeing?

Codex silently refuses to load certain sites using the Chrome plugin.

there seems to be a server-side blacklist of sites that Codex refuses to load. When you try and access one of these sites, the browser plugin throws an error:

Browser Use rejected this action due to browser security policy.
Reason: Browser Use is not permitted on https://detail.1688.com.

these sites aren't malicious or don't seem to be against TOS or anything: normal e-commerce sites such as Taobao or 1688.com.
futhermore, this isn't documented anywhere either.

Philosophically, having a web browser that decides - server side - which websites it can and can't load, without any transparency on this, it's not great. I could (grudgingly) understand if the sites are malicious/pornographic/illegal/etc, but these are genuine huge e-commerce sites - the Western equivalent of blocking Amazon or Walmart. More broadly, silently blocking sites in a non-transparent/undocumented way doesn't feel right either.

It seems like you ALSO can't even use Computer Use on Chrome if a tab is open from one of the "non-permitted" websites:

mcp__computer_use.get_app_state({
  "app": "Google Chrome"
})
// returns:
[{"type":"text","text":"This session has been stopped because Computer Use is not allowed on the current browser URL. Stop your work and send a final message noting why the session has been ended. Note that Computer Use is not allowed on this URL even if the user navigates to it themselves."}]

Obviously I could monkey-patch around this by modifying the javascript plugin or computer use.... but that's not an okay workaround either. Computer use, Chrome, and the Browser plugin should just work on all (legal) sites.

What steps can reproduce the bug?

Feedback ID: 019ee97a-589a-7670-9b4c-a7eadac555ba

What is the expected behavior?

The built in plugins do not run a server-side check to see if users are permitted to look at a certain site or not.

Additional information

Codex investigated the issue further, a brief summary (before we get the clanker to attach a big slop comment of everything it found):

  • On every request, the Chrome plugin will make a request to https://chatgpt.com/backend-api/aura/site_status, if this endpoint returns something, the request will be blocked
  • chrome plugin code: /Users/<me>/.codex/plugins/cache/openai-bundled/chrome/26.616.51431/scripts/browser-client.mjs:3234

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    appIssues related to the Codex desktop appbrowserbugSomething isn't workingcomputer-usesafety-checkIssues related to safety and abuse checks

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions