# Reported issues for Aginx Browser

Pod holds 13 of 13 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to [Aginx Browser](/mcp/aginx-browser).

## Most discussed

### Permission to add MCP Queen operational badge for net.aginx/aginxbrowser

Hi — MCP Queen’s current public probe for **net.aginx/aginxbrowser** reports an operational **A (97/100)** with **23 discovered tools**: https://mcpqueen.com/s/net.aginx/aginxbrowser

We are asking before making any repository change. One-click approval: close this issue as completed to authorize us to submit a one-line pull request in your existing badge area. You can also reply **PR welcome**. Close as not planned to decline; we will not open a PR without one of those explicit approval…

[Read the thread](https://github.com/yinnho/aginxbrowser/issues/20) · 2026-09-17 · closed · outside contributor · 4 comments

### tmall 发布页视频入口：点击无可用选择器，auctionVideos=[]（v0.5.8）

## 症状（v0.5.8 官方 release 实测，操作员报告 #119）

tmall 发布页视频区：组件展开后显示「上传视频」，点击未出现可用选择器，`auctionVideos=[]`。入口未通过；真实视频上传/转码/播放未测（被入口阻塞）。

## 待判分叉

两种可能分开验：

1. 入口点击要开原生文件选择对话框 — 引擎无此面，属引擎 gap（参考主图路径：`/files` 直写 `input[name=itemImage]` 可用，视频入口是否有同款 input 可落）
2. 点击后组件层崩溃/无响应 — 归 React 交互族（关联 #100）

## 复现入口

同 #120（tmall 新建表单，汽车贴膜类目）。

Refs #119

[Read the thread](https://github.com/yinnho/aginxbrowser/issues/122) · 2026-09-26 · closed · 3 comments

### HTTP/CDP 面零鉴权：本机任意进程（默认 bind 下连局域网）可驾驶已登录会话

## 洞

lightpanda#3452 同款，我方形状更宽：

1. `--cdp-port N` 把**整个 HTTP 面**绑上 127.0.0.1:N —— 本机任何进程都能 POST /eval /click /sessions，读已登录会话的 cookie（eval `document.cookie`）、驾驶登录态。loopback 不是访问控制。
2. 默认 bind 是 `AGINXBROWSER_BIND` 缺省 `0.0.0.0:8089` —— 局域网同理。
3. CDP 面：`/devtools/:kind/:id` 的 WS 升级对 `:id` 零校验（发现端点发的 uuid 是装饰性的），`/json/version` `/json/list` 无门。

## 危害

引擎持有实名账户 jar / persona / 登录会话（account 体系）。拿到面的进程等于拿到全部登录态。

## 修法方向（opt-in，零破坏）

`AGINXBROWSER_TOKEN`：设置时，除 `/health` 外所有 HTTP 路由 + WS 升级要求…

[Read the thread](https://github.com/yinnho/aginxbrowser/issues/162) · 2026-09-28 · closed · 1 comment

### Input.dispatchTouchEvent 裸 ack 假成功：不派发任何事件

## 现象

`Input.dispatchTouchEvent` 在 CDP 面返回成功 `{}`，但页面里什么都没发生——`touchstart`/`touchend`/`pointerdown`（pointerType:'touch'）/tap 合成 `click` 一概不派发。Playwright 的 `page.tap()` / `touchscreen.tap()` 走的正是这条命令，全部假绿。

（吸收自 obscura#1086。批241 已把 `Emulation.setTouchEmulationEnabled` 接真——`Input.dispatchTouchEvent` 是同一族剩下的另一半。）

## 验收

- `touchStart` → 每点 `pointerdown`（pointerType:'touch'、pointerId=点 id、首个活动点 isPrimary）+ `touchstart`（touches=全体活动点、changedTouches=本次列出的点、targetTouches）；
- `touchMove` →…

[Read the thread](https://github.com/yinnho/aginxbrowser/issues/156) · 2026-09-27 · closed · 1 comment

### 会话面缺 document-start 注入：diting preload 机制已有，HTTP session 无接线（xhs 内联 jsvmp 抢先捕获 fetch 的根因）

## 现象

小红书笔记页（www explore）在引擎里正文/作者渲染正常，评论区永远「加载中」。根因已定位（#84 的深一层的真相）：

页面的 jsvmp 签名器是 **HTML 内联脚本**，在解析时刻立即执行并捕获 `window.fetch` / `XMLHttpRequest.prototype.*` 原生引用。之后页面发出的 `comment/page`、`user/me` 等调用全部走 VM 内部保存的引用，带着 VM 算出的（在引擎环境里无效的）x-s 头 → 406。

任何 eval-based 补丁都追不上：eval 需要会话导航释放 + HTTP 往返，落地最早 ~200-400ms，而内联脚本在 HTML 解析时刻就跑了。现有竞速装补丁（250ms 间隔 eval 循环）只对「页面普通脚本」发的调用有效，对 VM 发的调用永远看不见。

## 决定性实验（2026-09-24）

CDP 桥（`/json/version` + `/devtools` WS）+ `Page.addScriptToEvaluateOnNewDocument`…

[Read the thread](https://github.com/yinnho/aginxbrowser/issues/96) · 2026-09-24 · closed · 1 comment

### serviceWorker.register() resolve undefined — 页面读 reg.scope 即 TypeError

**复现**（8199 引擎，小红书 explore，任意会话）：

```
Service Worker registration failed: TypeError: Cannot read properties of undefined (reading 'scope')
```

**根因**：bootstrap.js:6689 `register(){ return Promise.resolve(); }` — resolve 的是 undefined。真实 Chrome 里 `navigator.serviceWorker.register()` resolve 一个 `ServiceWorkerRegistration`（有 `scope`/`active`/`update()`/`unregister()`）。页面惯例 `register('/sw.js').then(reg => reg.scope)` 直接炸。`ready: Promise.resolve()` 同洞（`ready.then(reg => reg.scope)` 也炸）。…

[Read the thread](https://github.com/yinnho/aginxbrowser/issues/83) · 2026-09-23 · closed · 1 comment

### navigator.serviceWorker is truthy but addEventListener is not a function — X bootstrap TypeError

From docs/AginxBrowser_打开X_浏览器问题_2026-09-23.md (local 0.5.3, engine diting, use_proxy:true).

Repro: open https://x.com/home with imported login cookies. Document is HTTP 200, readyState complete, cookies include auth_token + ct0, page fetch works (HomeTimeline og4a4SdSF3WiQkkwaPCdPg -> 200), /session/:id/verdict = landed, no challenge.

First console entry:

    TypeError: navigator.serviceWorker?.addEventListener is not a function

`?.` does not throw on null/undefined, so…

[Read the thread](https://github.com/yinnho/aginxbrowser/issues/81) · 2026-09-23 · closed · 1 comment

### After a failed/timed-out navigation, session_eval and session_state mask the failure (result:null / non-string)

From docs/AginxBrowser_打开X_浏览器问题_2026-09-23.md (hosted 0.5.3, engine diting).

Repro shape: on https://browser.aginx.net with a proxied session (use_proxy:true via /import/curl), navigating to https://x.com/home times out at the network layer.

What the tools return before any explicit navigate:
- session_eval {script: "location.href"} -> {"result": null} — reads as "page is broken", not "navigation never completed"
- session_state -> error "state extraction returned non-string"
- only an…

[Read the thread](https://github.com/yinnho/aginxbrowser/issues/80) · 2026-09-23 · closed · 1 comment

## Most recent

### eval 域带凭据 fetch/XHR 被误判跨域：CORS error 要求同源 ACAO（重定向链导航后）

## 现象

会话经 302 重定向链跨源导航后（login.taobao.com → sell.publish.tmall.com），eval 执行域里发**同源带凭据**请求被引擎按跨域处理，直接 TypeError：

```
Failed to fetch: CORS error: credentialed request requires
Access-Control-Allow-Origin 'https://sell.publish.tmall.com'
and Access-Control-Allow-Credentials 'true'
```

- 目标 URL 与 `location.origin` / `window.origin` 完全一致（https 同 host 同 port）
- 页面自身代码发同样的 XHR（同源默认带凭据）正常 200
- eval 域**不带** `credentials:'include'` 的同一 fetch → ok 200
- eval 域 XHR（天然带凭据）→ onerror

即：只有「eval 域 +…

[Read the thread](https://github.com/yinnho/aginxbrowser/issues/163) · 2026-09-28 · open · 0 comments

### navigator.sendBeacon 是假发送桩：返回 true 但信标从未离机

## 症状

proxydetect.live 的 pd-lib.js 检测套件在本引擎跑不结算：pdKey/elapsed 恒 null，页侧报 "Detection script loaded but no response - possible rate limit" + "Detection timeout"（真 Chrome ~10s 完成）。批144 挂账、批145 修复 Image 假 onload 后页轮询已活（pds.config.uuid/testResults/clientData 全初始化），但探测信标依然零发出。

## 根因

`js/bootstrap.js` 的 navigator.sendBeacon 是空桩：

    sendBeacon() { return true; }

返回 true（排队成功）但什么都不发。pd-lib.js 的传输原语计数：`new WebSocket: 1 | sendBeacon: 3 | .src=: 2 | fetch(: 3 | XMLHttpRequest: 1` —— 3 个探测信标全部静默蒸发。…

[Read the thread](https://github.com/yinnho/aginxbrowser/issues/43) · 2026-09-17 · closed · 1 comment

### Sync XHR to data:/blob: URL returns status 0 (Chrome: 200)

## Symptom

`XMLHttpRequest` with `open(method, 'data:...', false)` + `send()` lands in the catch-all with **status 0** and empty body. Real Chrome resolves data: URLs locally and reports **status 200** with the decoded payload. The async path is fine (it rides `fetch()`, which has resolved data:/blob: locally since the batch-46 registry work) — only the sync path, which goes straight to `op_fetch_url_sync`, misses scheme-local URLs. blob: URLs behave the same way (Chrome: 200 + blob bytes).…

[Read the thread](https://github.com/yinnho/aginxbrowser/issues/42) · 2026-09-17 · closed · 1 comment

### Image fires onload for unreachable URLs (fake-success load face)

## Symptom

`new Image()` with a `.src` that cannot possibly load fires **onload**. Real Chrome fires **onerror**. Any anti-bot probe that pins load faces to an unroutable host (proxydetect-style client suites, Booking-style preloaders gone defensive) reads fake success.

## Probe (HEAD build, about:blank session)

| face | target | our engine | real Chrome |
|---|---|---|---|
| new Image().src | https://0.0.0.0:44435/x.png | **onload** | onerror |
| new Image().src |…

[Read the thread](https://github.com/yinnho/aginxbrowser/issues/41) · 2026-09-17 · closed · 1 comment

### CDP: Browser.setContentsSize 未实现 — chrome-devtools-mcp resize_page 断在 Unknown method

## 背景

ChromeDevTools/chrome-devtools-mcp（52k⭐，npm `chrome-devtools-mcp@1.9.0`）支持 `--browser-url` 连任意 CDP 端点。拿它直连 aginxbrowser `--cdp-port 9223` 跑 interop spike（MCP stdio JSON-RPC 真驱动，非 mock）。

## Spike 结果（v0.4.4 debug 构建，example.com）

| 工具 | 结果 |
|---|---|
| initialize + tools/list | ✅ 29 tools |
| new_page / list_pages | ✅ |
| take_snapshot | ✅ — 吃 Accessibility.getFullAXTree（批 490 的 AX 三件），uid 树完整：RootWebArea → heading level=1 → StaticText |
| evaluate_script | ✅ `() => 6 * 7` → 42 |
|…

[Read the thread](https://github.com/yinnho/aginxbrowser/issues/18) · 2026-09-17 · closed · 1 comment

The remaining reports are on [the project's issue tracker](https://github.com/yinnho/aginxbrowser/issues).
