Compare commits

..
Author SHA1 Message Date
renovate[bot] d2f943a3cf chore(deps): lock file maintenance 2026-09-24 13:45:24 +00:00
Jakub Orchowski 98e1668721 Add sponsor badge to README
Added a sponsor badge to the README.
2026-09-18 21:26:26 +02:00
ThePhaseless beb281267a feat(github): add GitHub Sponsors funding configuration 2026-09-18 21:06:05 +02:00
renovate[bot] b46614fb55 fix(deps): update dependency playwright to ==1.63.* (#413)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-16 02:11:38 +00:00
renovate[bot] cdfd73785a chore(deps): update dependency httpx2 to ==2.13.* (#412)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-14 21:29:44 +00:00
renovate[bot] 080b0f9141 chore(deps): update dependency httpx2 to ==2.12.* (#406)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-27 05:27:30 +00:00
renovate[bot] c611afb865 fix(deps): update dependency playwright to ==1.62.* (#369)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-27 01:34:31 +00:00
Jakub Orchowski cb2a862386 Merge pull request #400 from ThePhaseless/fix/tls-handshake-398
fix: match a real browser's TLS and solve Cloudflare challenges again
2026-08-18 12:45:53 +02:00
ThePhaseless 2852dc2527 fix: report an unreachable target as a gateway failure, not a crash
A host that will not resolve arrived as a plain PlaywrightError, which
nothing caught, so Byparr answered 500 and read as its own defect. It is
the upstream that failed, and the failure is usually transient, so 502
also lets clients retry where a 4xx would tell them not to. The timeout
branch stays ahead of it, since PlaywrightTimeoutError subclasses Error.
2026-08-18 12:29:39 +02:00
ThePhaseless 12ef77177a fix: stop waiting for the challenge widget to hold still
scroll_into_view_if_needed waits for actionability, and the Cloudflare
widget animates without pause, so the call timed out at every ancestor
depth and aborted the measurement before the box was ever read. The
container is already in the viewport; drop the scroll and read the box.
2026-08-18 12:02:20 +02:00
ThePhaselessandClaude Opus 5 11d7e59263 test: assert what the challenge tests claim to assert
Three tests checked solution.status against HTTPStatus.OK, which the
endpoint now hardcodes, so the check could never fail. Drop it everywhere
except the test that exists to pin that behaviour.

That left the self-clearing case asserting only that nothing raised, which
the click test already covers. Give it a measurable widget and assert we
never press it: a challenge that clears on its own is the one case where
touching the checkbox would be wrong, and nothing tested it. Verified by
moving the click ahead of the exit check, which the assertion now catches.

Drop the fake page.evaluate return as well, since /v1 stopped calling it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 04:00:17 +02:00
ThePhaselessandClaude Opus 5 78b3f314c3 refactor: report 200 like FlareSolverr and split the challenge out
FlareSolverr hardcodes the solution status ("todo: fix, selenium not
provides this info"), so clients built against it never see anything else.
Byparr handed back the real navigation code on the branch without a
challenge and 200 on the branch with one, which is neither honest nor
compatible. Always report 200.

Move the challenge handling into src/challenge.py and the response bodies
into src/content.py, leaving endpoints.py with the routes and navigation.
That also confines the import of playwright_captcha's private detection
module to a single file, so a patch release can only break one import
instead of the app and the test module at once.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 03:51:34 +02:00
ThePhaselessandClaude Opus 5 d0b013029c fix: load the page the challenge was hiding, and stop trusting a stray box
Nothing waited for the destination once the interstitial let go: page_html
stayed unset and the networkidle wait only ran on the branch that never saw
a challenge, so a challenge clearing on its own returned whatever had loaded
by then. Wait for it on both branches.

An exhausted budget produced timeout=0, which Playwright reads as no timeout
at all, turning every remaining wait unbounded exactly when it should fail
fast. Floor it instead.

Scroll the widget into view before measuring it, since bounding_box reports
viewport coordinates and an off-screen widget was clicked at a point that hit
nothing, and reject containers taller than a checkbox row so a full-page
wrapper cannot pass for one - both reported success while clicking blank
space.

Drop max_attempts, which nothing reads now that the solver is gone, and
refresh AGENTS.md, which still described camoufox and a solver in the
dependency.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 03:41:58 +02:00
ThePhaselessandClaude Opus 5 426aae4310 fix: address review findings on the challenge solver
nowsecure.nl carries no interstitial, so the turnstile detector only widened
the entry condition without ever being able to satisfy the exit one, leaving
a turnstile-only page reported as solved on the first poll. Detect on the
interstitial alone.

Restore the user-agent guard that went missing: an absent header made
Solution reject None and turned into an unhandled 500, where it used to
degrade to an empty string. Fall back to "" directly rather than reaching
for evaluate(), which CDP refuses.

Bound the widget measurement, which inherited Playwright's 30s default at
each of four depths and so could run far past the request budget, throttle
the probe when no click lands so the scan no longer repeats every tick, and
release the mouse button through a finally so a failed press cannot leave it
held down.

Cover the click path: the fixture pinned bounding_box to None, so nothing
exercised the code this branch exists to add.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 03:30:49 +02:00
ThePhaselessandClaude Opus 5 3dcf529609 refactor: drop the solver and prove the challenge page is gone
Nothing calls ClickSolver any more now that the checkbox is clicked through
the mouse, so take it out of the browser dependency instead of leaving it
constructed but unused.

Assert on the returned body as well: a 200 alone passed even when the
interstitial itself was handed back, which is the defect this branch fixes.
Judge on _cf_chl_opt, since Cloudflare keeps serving cdn-cgi/challenge-platform
as a beacon on pages that are already cleared.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 02:45:19 +02:00
ThePhaselessandClaude Opus 5 61db8d82ee fix: click the challenge checkbox without tripping Cloudflare's detector
Measuring the widget with page.evaluate() made Cloudflare reissue the
challenge every few seconds, so the interstitial never cleared. Locate the
container with locators instead and click it through the mouse, which leaves
its closed shadow root untouched.

Keep the solver lazy as well: ClickSolver.prepare() patches attachShadow,
which is what escalated a self-clearing challenge into a checkbox in the
first place.

A click can land while the widget is still self-verifying, so retry on a
cooldown for as long as the request budget lasts rather than stopping after
the first one, and confirm the marker is gone twice before reporting success
since it drops out between challenge rounds.

The bypass tests now pass on their own, so drop the xfail marks.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 17:45:15 +02:00
ThePhaselessandClaude Opus 5 9067ca37df test: simplify the xfail reason
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TDMac4vGGcBhoUB5V6bvFK
2026-08-17 12:38:14 +02:00
ThePhaselessandClaude Opus 5 cb8fb58fa8 refactor: use the library's detector instead of hand-rolled selectors
detect_cloudflare_challenge(page, 'interstitial') matches the challenge on
the page and stops matching once it clears, measured on ext.to (True then
False), and on yggtorrent, nowsecure.nl and google.com, none of which carry
a /cdn-cgi/challenge-platform/ script when cleared. So the custom marker set
was unnecessary.

The turnstile variant is not usable for this: nowsecure.nl embeds turnstile
scripts on its normal page, so it reports a challenge even when cleared.

Also adds PlaywrightTimeoutError to the retryable set. It is a different
class from the builtin TimeoutError -- playwright's derives from its own
Error -- so a Playwright timeout inside the solver escaped the loop and
returned 408 without retrying.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TDMac4vGGcBhoUB5V6bvFK
2026-08-17 11:35:49 +02:00
ThePhaselessandClaude Opus 5 fc64fe05d5 refactor: drop what is not part of the fix
Replaces the try/except-plus-log around the solve attempt with
contextlib.suppress, and inlines the one-use attempt cap. Type annotations
are unchanged.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TDMac4vGGcBhoUB5V6bvFK
2026-08-17 11:30:29 +02:00
ThePhaselessandClaude Opus 5 24c339b085 fix: judge the challenge by its markup, not by networkidle
solve_captcha decides it failed by waiting for networkidle, which returns
while Cloudflare is still verifying, so it reported failure on challenges
that had already passed and retried until the whole max_timeout burned into
a 408. Cap each solve attempt and let the challenge markup decide instead.

CHALLENGE_MARKERS has to match the orchestrator specifically: the bare
/cdn-cgi/challenge-platform/ path also matches the jsd beacon Cloudflare
serves on cleared pages, so detect_cloudflare_challenge never reports
success on its own.

Also switches the solver back to FrameworkType.PLAYWRIGHT, since PATCHRIGHT
injects the shadow-root unlock over CDP and Firefox has no CDP session, and
turns off COOP/COEP so the widget's iframe appears in page.frames at all.

The four sites Cloudflare refuses on this browser are xfail rather than
skip, so a regression still shows and a pass records as xpass.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TDMac4vGGcBhoUB5V6bvFK
2026-08-17 11:21:57 +02:00
ThePhaselessandClaude Opus 5 c7633b4525 revert: leave max_attempts alone
sys.maxsize was the original bug, but only because solve_captcha was called
in a retry loop. That call is gone, so MAX_ATTEMPTS now only reaches
ClickSolver at construction and never bounds anything; the solve loop is
bounded by timer.remaining(). Reverting a change that no longer does
anything.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TDMac4vGGcBhoUB5V6bvFK
2026-08-17 11:13:40 +02:00
ThePhaselessandClaude Opus 5 691aaa6f3f refactor: strip the challenge-solver changes to the minimum
Removes every explanatory comment added by this branch, inlines the browser
prefs rather than holding them in a module constant, folds _cloudflare_frame
into its only caller, and cuts the added docstrings to one line each.

No behaviour change: 13 unit tests pass, and removing the checked-box guard
still fails its test.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TDMac4vGGcBhoUB5V6bvFK
2026-08-17 11:06:09 +02:00
ThePhaselessandClaude Opus 5 e0b1efa560 style: trim the challenge-solver comments to what is load-bearing
Cuts ~100 lines of commentary that restated the diff or recorded dead
investigation, and merges _press_point back into _press_checkbox now that
the checked guard is one condition rather than the extra return that
tripped the too-many-returns lint.

Corrects the COOP/COEP note, which claimed the pair changed no outcome.
Without those prefs the widget's iframe never appears in page.frames at
all: measured on ext.to, eight presses land with them and none without.

No behaviour change.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TDMac4vGGcBhoUB5V6bvFK
2026-08-16 21:16:20 +02:00
ThePhaselessandClaude Opus 5 362b07e55a docs: correct the xfail reason with what was actually measured
The reason said Cloudflare refuses the checkbox click from datacenter IPs
and that the visitor's address was being judged rather than our code. That
is false. Measured from one datacenter IP within a single hour, byparr
v2.1.0 clears ext.to in 18s, speed.cd/login in 20s and extratorrent.st in
19s, each returning cf_clearance, while no configuration of the current
stack clears any of them.

Two candidate causes were measured and eliminated rather than assumed. The
JS-visible fingerprint is not it: camoufox is the less coherent of the two
browsers -- no WebGL at all, oscpu leaking Linux beneath a Windows UA -- and
passes regardless. The TLS handshake is not it either: re-enabling cipher
0xC009 reproduces camoufox's JA4 byte for byte
(t13d1717h2_5b57614c22b0_3cbfd9057e0d) and the challenge is still refused.

Also records that devtools.jsonview.enabled is load-bearing for #394, and
that the COOP/COEP pair changed no outcome on any site or network measured.

No behaviour change; comments and the xfail reason only.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TDMac4vGGcBhoUB5V6bvFK
2026-08-16 21:10:08 +02:00
ThePhaselessandClaude Opus 5 1a2cf32e1e fix: press the Cloudflare widget instead of its invisible checkbox
playwright-captcha's ClickSolver clicks the challenge's input element
directly. That input sits under a styled overlay, so Playwright reports a
successful click while `checked` never flips -- which is why the
interactive challenge has never been solved here. The solver also judged
its own click by waiting for networkidle, which returned 9ms later while
Cloudflare was still verifying, so it reported failure on challenges that
were about to pass.

Replace it with a poll loop that watches for the challenge markup to go
away and presses the widget's visible pixels whenever an unchecked box is
on offer. A box that is already checked is left alone: pressing over the
top of Cloudflare's verification restarts it, and ext.to and speed.cd sat
on "performing security verification" for a full 300s budget while being
pressed a dozen times.

Measured on a residential connection, driving the real /v1 handler:
nowsecure.nl passes in 3s, extratorrent.st in 116s and 1337x.to in 198s,
all three returning cf_clearance. extratorrent.st had never cleared
before, on any network or solver. ext.to and speed.cd still refuse -- the
press registers and the widget re-serves a fresh unchecked box -- so they
stay in the xfail list.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TDMac4vGGcBhoUB5V6bvFK
2026-08-16 19:11:31 +02:00
ThePhaselessandClaude Opus 5 f97e3d325d fix: restore v2's COOP/COEP handling so the checkbox is reachable
v2.1.0 launched camoufox with disable_coop=True. v3 dropped it, and without it
Cloudflare's challenge iframe -- which carries allow="cross-origin-isolated" --
lands in an isolated content process where Juggler sees no docShell:
content_frame() raises "Permission denied to access property docShell on
cross-origin object" and the solver never reaches the checkbox to click it.

Not a demonstrated win. From a datacenter IP Cloudflare rejects the click
however it is delivered -- measured across eight sites, nine consecutive
clicks, a humanized cursor, four fresh navigations, and a shadow-root patch
made undetectable (no global flag, toString reporting native code). The same
browser and IP clear nowsecure.nl and come back with a cf_clearance cookie, so
what is being judged is the address, not the client.

Restored for parity with the version users report working, because reaching the
checkbox is a precondition for ever passing an interactive challenge and Byparr
mostly runs from residential addresses that Cloudflare treats far better than a
CI runner.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-15 13:45:57 +02:00
ThePhaselessandClaude Opus 5 4e70c8b208 fix: bound the challenge solver and pin the TLS handshake
Follow-up to the earlier CI fix, after A/B-ing every change against main and
against this branch's original commit.

What measurably changed, and what did not:

- The solver's retry loop was unbounded (max_attempts = sys.maxsize). On a
  challenge it cannot clear it retried ~1300 times per request and the caller
  waited out the entire max_timeout for a 408 it was always going to get.
  _solve_challenge now clicks, waits for the challenge markup to actually
  disappear, and gives up when the budget does.

- That wait exists because the solver's own verdict is worthless here: it
  judges its click with wait_for_load_state("networkidle"), which returned 9ms
  after the click while Cloudflare was still showing "verifying you are
  human", and then reported failure.

- The "is it still up?" check cannot use detect_cloudflare_challenge alone.
  That matches any script under /cdn-cgi/challenge-platform/, and Cloudflare
  serves its jsd bot-scoring beacon from the same path on cleared pages. Nor
  can it use the widget iframe: a cleared nowsecure.nl carries two of those
  with no challenge present. CHALLENGE_MARKERS matches the challenge
  orchestrator script and the interstitial's own markup.

- test_tls_handshake_looks_like_firefox pins what this branch is actually for.
  Measured through /v1 on the same host: main offers 52 cipher suites, this
  branch 16, and real Firefox offers 16. route.fetch() was re-issuing
  navigations through Playwright's HTTP client, and that is a fingerprint no
  header spoofing hides. Unlike a Cloudflare verdict the count is
  deterministic, so it is the one assertion here that cannot flake.

- Disabling COOP/COEP does let the solver reach and click the checkbox for the
  first time (Cloudflare advances to "verifying you are human"), but it changed
  no outcome across eight sites, and real Firefox ships those policies on.
  Recorded in a comment rather than shipped.

test_bypass keeps a hard assertion against targets that clear from any network.
The four Cloudflare guards hardest move to xfail rather than skip: they still
run and still report, but Cloudflare's opinion of the runner's IP cannot turn
the build red.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-15 13:27:53 +02:00
ThePhaselessandClaude Opus 5 5130400571 fix: stop an unreachable Cloudflare widget from burning the whole timeout
The bypass tests were failing on CI with 408s after 78 minutes. Neither the
runner's speed nor this branch's TLS change was responsible.

On the sites that fail, Cloudflare serves its interactive checkbox challenge.
playwright-captcha locates the widget iframe inside the shadow root and then
calls ElementHandle.content_frame(), which this Firefox build refuses:

  Protocol error (Page.describeNode): Permission denied to access property
  "docShell" on cross-origin object

Its fallback -- matching page.frames by URL -- cannot help either, because the
challenge frame exposes an empty URL to the parent. Every attempt therefore
ends in CaptchaDetectionError: Cloudflare iframes not found.

MAX_ATTEMPTS was sys.maxsize, so that repeated until the request budget ran
out: 432 docShell errors and 1326 retry iterations in a single request on the
runner, and with max_timeout raised to 360 and --retries 3, a 1h18m job.

Three changes:

- max_attempts defaults to 5. An unreachable widget stays unreachable, so the
  retries were not buying anything; the caller now hears about it in seconds.
- _solve_challenge translates the solver's own give-up exceptions into the 408
  read_item already reports for timeouts. Without this, bounding max_attempts
  would have turned the hang into an unhandled 500.
- The solver framework goes back to PLAYWRIGHT. PATCHRIGHT skips the
  unlockShadowRoot init script and injects over CDP instead, which Firefox has
  no session for ("CDP session is only available in Chromium"). Cloudflare
  builds its widget in a closed shadow root, so on this branch the challenge
  iframe was invisible even to page.locator: 1 -> 0 against the same sites on
  the same runner.

test_bypass drops the max_timeout=360 override and skips again on 408.
Whether Cloudflare shows the interactive challenge depends on the visitor, so
the runner's luck should not decide whether a regression of ours is reported.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-15 11:09:30 +02:00
ThePhaseless 14834c23b2 increase test timeout 2026-08-15 00:41:34 +02:00
ThePhaseless aa9a331064 reformat, upgrade and fix timeout 2026-08-15 00:15:50 +02:00
ThePhaseless c4dcee3e2b log test skip reasons/websites 2026-08-14 23:01:25 +02:00
ThePhaselessandClaude Opus 5 652c234782 refactor: drop redundant navigator.userAgent evaluate
page.goto() returns None only for about:blank or a same-URL-different-hash
navigation, so page_request is always present for a real request and its
headers always carry the UA. The evaluate call was therefore unreachable
as a fallback and, once moved before navigation, silently became the
primary source instead.

Request headers are also the correct source: consumers replay them with
the clearance cookies, so the UA the server saw is the one to report.
This restores the ordering d3a828e established.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-14 22:22:53 +02:00
ThePhaselessandClaude Opus 5 1c2b2df90d style: collapse setup_routes docstring to one line
Fixes the ruff D200 the docstring edit introduced.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-14 22:09:01 +02:00
Alex Thomson c9d4cd4a4e fix: owui tests 2026-08-14 21:36:41 +02:00
Alex Thomson ecf7c03d7c fix: remove CSP stripping 2026-08-14 21:36:41 +02:00
Alex Thomson c96db89d03 fix: call evaluate before navigation
Avoids any Content Security Policies that maybe present after navigation
2026-08-14 21:36:41 +02:00
Alex Thomson 742cafc64a refactor: replace evaluate with locator 2026-08-14 21:36:41 +02:00
Jakub Orchowski 9afb3e0903 Merge pull request #395 from ThePhaseless/fix/csp-json-viewer-eval
fix: /v1 must survive CSP-blocked evaluate (incl. Firefox JSON viewer)
2026-08-11 11:57:47 +02:00
ThePhaseless d7792b8fcd fix(test): assert camelCase userAgent key in JSON response 2026-08-11 11:40:49 +02:00
ThePhaseless bb526d73b0 merge: resolve conflict with main (read_item refactor #393) 2026-08-11 11:30:23 +02:00
ThePhaseless 9b933ea70c chore: drop explanatory comments 2026-08-11 11:23:31 +02:00
ThePhaseless d3a828e814 fix(v1): source User-Agent from request headers; evaluate only as fallback
page.evaluate runs eval() in the page's main world, which fails with 'call to eval() blocked by CSP' under any CSP that disallows unsafe-eval - HTTP headers (already stripped), meta tags (not strippable), or internal viewer documents (#394).

The navigation request already carries the UA the site actually saw, so take user_agent from page_request.request.headers and keep evaluate only as a best-effort fallback whose failure can no longer 500 the request.
2026-08-11 11:14:10 +02:00
ThePhaseless 46a3c68eb0 fix: disable Firefox JSON viewer so evaluate works on JSON APIs
Firefox renders application/json documents in a built-in viewer whose own
CSP (<script-src resource:>) blocks Playwright's eval-based page.evaluate,
crashing /v1 with a 500 on JSON APIs (closes #394). Setting
devtools.jsonview.enabled=false renders JSON as plain text, which also
returns the raw JSON body instead of the viewer's syntax-highlighted HTML.
2026-08-11 11:08:04 +02:00
Jakub Orchowski f821290bac Merge pull request #393 from ThePhaseless/chore/ruff-lint-cleanup
chore: fix ruff lint findings and refactor read_item
2026-08-11 00:33:56 +02:00
Jakub Orchowski 5de9266d7e Merge pull request #392 from ThePhaseless/fix/fake-dep-locator-mock
test(fake_dep): mock Playwright locator API faithfully
2026-08-11 00:21:21 +02:00
ThePhaseless 89dcf5e16c Merge branch 'main' into chore/ruff-lint-cleanup
Resolved conflicts in src/consts.py and src/endpoints.py:
- consts.py: take theirs (CHALLENGE_TITLES removed, browser_locale added,
  CaptchaType import no longer needed — detection is now library-based)
- endpoints.py: merge both refactors — keep theirs' detect_cloudflare_challenge
  + page_html capture, reapply my helper extraction (setup_routes,
  _navigate_and_solve, _solve_challenge, _wait_for_networkidle,
  build_response_content, _fetch_pdf_content) on top
2026-08-11 00:20:55 +02:00
ThePhaseless 3c45ef9691 chore: fix ruff lint findings and refactor read_item
- Fix I001: sort imports in src/consts.py
- Fix PLC0415: move `import base64` to top of tests/main_test.py
- Fix UP037: remove quotes from LinkResponse return annotation
- Fix D213: correct multi-line docstring summary placement
- Remove unused `# noqa: BLE001` in src/owui.py
- Refactor read_item into helpers: setup_routes, load_page_and_solve,
  build_response_content, _fetch_pdf_content — resolves C901 and PLR0915
- Add CPY001, BLE001 to ruff ignore list
2026-08-11 00:15:39 +02:00
ThePhaseless bd4c62de38 test(fake_dep): drop explanatory comments 2026-08-11 00:01:29 +02:00
ThePhaseless 92043725f5 test(fake_dep): mock Playwright locator API faithfully
fake_dep's AsyncMock page made page.locator() return an un-awaited
coroutine, so detect_cloudflare_challenge swallowed an AttributeError
and reported a challenge. The networkidle-timeout test silently ran the
solver branch and never exercised its intended path, plus emitted a
'coroutine ... was never awaited' RuntimeWarning in CI.

Make page.locator() sync-returning (as in real Playwright) with an
awaitable count() that finds no elements, and assert the solver is never
invoked.
2026-08-11 00:00:10 +02:00
Jakub Orchowski f8d087bab8 Merge pull request #391 from ThePhaseless/fix/tmpfs-python-wipe
fix: keep uv Python out of tmpfs-mounted /tmp
2026-08-10 23:46:59 +02:00
ThePhaseless c38a6f4e85 fix(docker): keep uv Python out of tmpfs-mounted /tmp
HOME=/tmp put the uv-managed Python at /tmp/.local/share/uv, so a
tmpfs mount on /tmp (e.g. compose tmpfs: /tmp) wiped the interpreter at
container start, leaving the /app/.venv/bin/python symlink dangling and
startup failing with 'exec /app/.venv/bin/python failed: No such file
or directory' (#389).

Move HOME to /home/byparr and apply the OpenShift permission pattern
(owner uid 1000, group 0, group=user) so both the default user and
arbitrary-UID runtimes (docker run --user, OpenShift) can write to it.
Apply the same pattern to /cache, where invisible_playwright keeps
runtime browser/profile data and which arbitrary UIDs previously could
not write.

Fixes #389
2026-08-10 23:40:16 +02:00
Jakub Orchowski aa7bfee7bb Merge pull request #390 from ThePhaseless/lang-env
feat: add BROWSER_LOCALE env to override browser language
2026-08-10 22:57:42 +02:00
ThePhaseless 336773d7da merge: resolve conflict with main (drop CHALLENGE_TITLES removed in #385) 2026-08-10 22:56:51 +02:00
ThePhaseless 8cb5770b84 feat: add BROWSER_LOCALE env to override browser language 2026-08-10 22:53:42 +02:00
Jakub Orchowski ae28c7098f Merge pull request #388 from ThePhaseless/fix/cloudflare-localized-challenge-detection
fix: detect localized Cloudflare interstitials (#385)
2026-08-10 12:25:01 +02:00
Jakub Orchowski 1c4b377613 Merge pull request #387 from ThePhaseless/cache-test
fix(ci): fix Docker cache reuse across jobs and architectures
2026-08-10 12:24:47 +02:00
ThePhaseless 8ef4c62249 fix: detect Cloudflare challenges regardless of language (#385)
Cloudflare localizes its interstitial page title per visitor language
(e.g. Polish "Cierpliwości..." served by 1337x.to), so the hard-coded
["Just a moment..."] title check missed every non-English visitor:
Byparr returned the raw challenge page (HTTP 403, no cf_clearance
cookie, no "Challenge detected" log) and Prowlarr reported "Unable to
access 1337x.to, blocked by CloudFlare Protection." (issue #385, still
open on 3.0.1 after the compression fix).

Replace the title-based gate with the playwright-captcha library's own
language-independent DOM detection (detect_cloudflare_challenge), which
matches Cloudflare's challenge scripts directly:
  - interstitial:  script[src*="/cdn-cgi/challenge-platform/"]
  - turnstile:     input[name="cf-turnstile-response"],
                   script[src*="challenges.cloudflare.com/turnstile/v0"]
Both selectors match the live 1337x "Cierpliwości..." interstitial.

The navigation/detect/solve flow lives in _navigate_and_solve(); the
timeout-to-408 translation is inlined at the call site in read_item.
The now-unused title map is removed from src/consts.py.

Verified live (built image): "Challenge detected" now fires on 1337x
(0 -> 1 in logs) where the title check never fired; example.com negative
control returns 200 with no challenge path entered. End-to-end clearing
still depends on the requester's public IP (README caveat).
2026-08-10 12:05:51 +02:00
ThePhaseless baad431605 chore(ci): drop VERSION cache-comment from final stage 2026-08-10 01:22:09 +02:00
ThePhaseless 7e1a5d4329 ci: retrigger cache test (run 2 — verify arm64 self-reuse) 2026-08-09 21:35:14 +02:00
ThePhaseless 221f27acca fix(ci): hoist ARG VERSION to final stage to stop cache busting
Root cause of remaining cache misses: the base stage declared
ARG VERSION, and the build job passed VERSION=${{ github.sha }}.
Since VERSION changes every commit, every base/app layer cache key
changed with it — so layers rebuilt every run regardless of scope.

Additionally the test job passed no build-args while the build job
passed GITHUB_BUILD=true + VERSION, so test's cached base/app layers
had different keys from build's — cross-job reuse never hit either.

Fix:
- Dockerfile: move ARG VERSION / ENV VERSION from base to the final
  runtime stage (FROM app). VERSION is only read at runtime by
  src.consts via Pydantic settings; base/app layers don't use it.
  base/app now cache without per-commit VERSION variation.
- workflow: pass --build-arg GITHUB_BUILD=true in the test step so
  test and build share identical base/app cache keys (cross-job reuse).

VERSION is intentionally NOT passed to the test job: the test stage
(FROM app AS test) doesn't read VERSION, and omitting it keeps the
base/app cache keys identical between test and build.
2026-08-09 21:17:13 +02:00
ThePhaseless bdd59d7e60 ci: retrigger cache test (run 2) 2026-08-09 20:23:12 +02:00
ThePhaseless 1801eaa40c fix(ci): scope push trigger to main to avoid duplicate runs
push: branches: ["*"] matched feature branches, so every push to a
branch with an open PR fired both a 'push' and a 'pull_request' event.
Their concurrency groups differ (refs/heads/<branch> vs refs/pull/<n>/merge),
so cancel-in-progress could not dedup them — the full multi-arch build
ran twice on each push, doubling CI minutes.

Scope push to branches: ["main"]; pull_request remains the validator for
feature branches. Tag pushes (v*.*.*), schedule, and workflow_dispatch
are under separate filters and are unaffected.
2026-08-09 19:58:48 +02:00
ThePhaseless bc529e5915 fix(ci): use slice-free gha cache scopes for cross-job reuse
- test job: scope x64 -> amd64 to match build matrix amd64 leg
- build job: scope ${{ matrix.platform }} -> ${{ steps.vars.outputs.SURFIX }}
  (yields amd64/arm64), avoiding the gha backend's / path-separator
  bug that mangled scope=linux/arm64 and broke arm64 cache reuse

test (amd64) and build-amd64 now share scope=amd64 so build reuses
the app/base layers the test job cached earlier in the same run.
build-arm64 gets a working scope=arm64 that persists across runs.
2026-08-09 19:45:44 +02:00
ThePhaseless 1c9093f218 fix(ci): extract first image tag by line, not space
metadata-action emits tags newline-separated, so FIRST_TAG=${TAGS%% *}
kept the entire multi-line value and expanded to 4 args on tag releases,
making `imagetools inspect` fail before the manifest could be signed.
Split on the first line instead.
2026-08-09 19:25:09 +02:00
ThePhaseless 0c44ce1a4d fix: request uncompressed bodies in CSP-strip route
route.fulfill(response=...) re-serves the raw bytes fetched by
route.fetch(), so compressed (gzip/brotli/zstd) documents arrive
at the browser still compressed while the forwarded headers claim
otherwise - page.content() then returns garbled binary, breaking
indexers like uindex.org and 1337x.to (issue #385).

Fetch with accept-encoding: identity so the re-served body is plain
text, and drop content-encoding/content-length alongside the CSP
headers since they are stale after the rewrite.
2026-08-09 19:07:05 +02:00
renovate[bot] 07309c8d8e chore(deps): update dependency httpx2 to ==2.10.* (#386)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-09 16:33:10 +00:00
ThePhaseless 25194c3bca fix(ci): sign docker image by digest instead of tag 2026-08-08 02:20:35 +02:00
Jakub Orchowski 77020bec0d Merge pull request #384 from ThePhaseless/feat/owui-loader-cleanup
feat: add Open WebUI external web loader endpoint
2026-08-08 01:54:41 +02:00
ThePhaseless cb80a0f2a0 Merge remote-tracking branch 'origin/main' into feat/owui-loader-cleanup
# Conflicts:
#	uv.lock
2026-08-08 01:42:54 +02:00
ThePhaseless 23374ce58e chore: migrate tests from httpx to httpx2
Starlette's TestClient deprecates httpx; httpx2 is the maintained
successor (Pydantic stewardship) with a drop-in API.
2026-08-08 01:42:10 +02:00
ThePhaseless 941d5e7350 Revert "chore: migrate tests from httpx to httpx2"
This reverts commit ff70ffc32b.
2026-08-08 01:41:52 +02:00
ThePhaseless ff70ffc32b chore: migrate tests from httpx to httpx2
Starlette's TestClient deprecates httpx; httpx2 is the maintained
successor (Pydantic stewardship) with a drop-in API.
2026-08-08 01:40:12 +02:00
ThePhaseless 0dff659e34 feat: extract articles with trafilatura on /load
Run trafilatura server-side on the rendered DOM (page.content()), so
JS-rendered pages stay fully visible to the extractor; fall back to
innerText when trafilatura cannot score any main content.
2026-08-08 01:26:35 +02:00
Jakub Orchowski 2eafc88c18 Merge pull request #380 from ThePhaseless/renovate/fastapi-0.x
fix(deps): update dependency fastapi to ==0.141.*
2026-08-08 01:17:08 +02:00
ThePhaseless cd4359a1dc refactor: simplify OWUI loader endpoint
- Move OWUI_API_KEY into pydantic settings (src/consts.py); drop the
  Dockerfile ENV entry so the key is only ever set at runtime
- Enforce auth before the browser is launched via dependency ordering
- Compare bearer tokens in constant time (hmac.compare_digest)
- Keep extracting when networkidle times out, matching /v1 behavior
- Type page as Page, drop redundant comments and docstrings
2026-08-08 01:10:44 +02:00
marchingphoenixandClaude Opus 4.5 f76443cbda feat: add Open WebUI external web loader endpoint
Add /load endpoint for Open WebUI's WEB_LOADER_ENGINE=external integration.
Uses document.body.innerText for content extraction.

Configure in Open WebUI:
  WEB_LOADER_ENGINE=external
  EXTERNAL_WEB_LOADER_URL=http://byparr:8191/load
  EXTERNAL_WEB_LOADER_API_KEY=<OWUI_API_KEY env var>

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-08-08 00:56:46 +02:00
Jakub Orchowski f6010524d9 Merge branch 'main' into renovate/fastapi-0.x 2026-08-08 00:50:29 +02:00
Jakub Orchowski f970d5cf0f Merge pull request #383 from ThePhaseless/handle-networkidle-timeouts
Handle networkidle timeouts after DOM load
2026-08-08 00:50:22 +02:00
ThePhaseless 5c4d0393b4 chore: drop redundant comment on networkidle best-effort wait 2026-08-08 00:50:10 +02:00
Jakub Orchowski 0dc4643d03 Merge branch 'main' into handle-networkidle-timeouts 2026-08-08 00:45:16 +02:00
ThePhaseless 490e2fad97 refactor: keep networkidle timeout handling inline, mock-based tests 2026-08-08 00:37:09 +02:00
ThePhaseless e2fd2e6d42 refactor: simplify CSP stripping handler
Drop error handling and conditional branches that duplicated the
pass-through path; rely on the goto timeout as before.
2026-08-08 00:31:25 +02:00
ThePhaseless 7b904a5ffd feat: continue after networkidle timeout once domcontentloaded completes
A page whose network never goes idle (background analytics, websockets)
used to fail the whole request with a 408 once the networkidle wait
expired. Since the DOM is fully usable after domcontentloaded, treat a
networkidle timeout as non-fatal and return the loaded page instead.
Fatal timeouts during initial load or challenge solving still return 408.

Adds unit coverage for both paths using a fake page that fails
configured load-state waits.
2026-08-08 00:27:54 +02:00
ThePhaseless 6d447a0d67 fix: strip CSP headers from page responses so evaluate works
The Firefox engine evaluates JS via eval(), which pages whose CSP
lacks 'unsafe-eval' block - every page.evaluate() then fails with
"call to eval() blocked by CSP". yggtorrent's search URL redirects to
a page with such a CSP, crashing the user-agent read and 500ing /v1.

Rewrite document responses without CSP headers via route.fetch +
fulfill. Juggler only routes the first request of a redirect chain,
so follow redirects inside the fetch and record the final URL
ourselves instead of relying on page.url.
2026-08-08 00:25:46 +02:00
ThePhaseless 0b4d1a91ce feat: accept FlareSolverr maxTimeout in milliseconds
Add a maxTimeout alias to LinkRequest.max_timeout for FlareSolverr
drop-in compatibility. Values of 1000 or more are treated as
milliseconds and normalized to seconds; smaller values keep the
native seconds semantics. Closes #382.
2026-08-07 23:51:44 +02:00
ThePhaseless 52891d456a Merge pull request #381 from feder-cr/pin-released-invisible-playwright
Install invisible-playwright from PyPI rather than by git URL

Conflict resolution: keep the >=0.6.1 floor set by the follow-up
version bump; uv.lock already resolves to 0.6.1.
2026-08-07 23:50:14 +02:00
renovate[bot] 709a73a5cb fix(deps): update dependency fastapi to ==0.141.* 2026-08-07 21:49:50 +00:00
ThePhaseless e298eb8d3f chore(deps): update invisible-playwright to 0.6.1
Bump the PyPI floor to the latest release (0.6.1), which pins
invisible-core 18.13.0 and drops Windows-only deps (pywin32, tqdm).
2026-08-07 23:49:01 +02:00
Federico a0c4b1dd93 deps: install invisible-playwright from PyPI instead of git 2026-08-07 23:49:01 +02:00
renovate[bot] 10be6973da chore(deps): update dependency setuptools to v83 [security] (#378)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-07 23:39:57 +02:00
Federico 69f6467dde deps: install invisible-playwright from PyPI instead of git 2026-08-01 19:00:31 +02:00
renovate[bot] c42a353b8a chore(deps): update dependency ruff to ==0.16.* (#377)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-24 02:43:56 +00:00
ThePhaseless ecdd4c112a docs(readme): add Proxmox OCI/LXC shm_size workaround
Adds the Docker Compose options from #283 (comment) that resolve
multiprocessing/camoufox FileNotFoundError errors on Proxmox OCI/LXC.

Closes #283
2026-07-04 18:24:54 +02:00
ThePhaseless 885a24cf16 fix(docker): use IPv4 loopback in HEALTHCHECK to support IPv6-enabled networks
On IPv6-enabled Docker networks, 'localhost' resolves to ::1 first,
but uvicorn binds to 0.0.0.0 by default, so the healthcheck can fail.
Using 127.0.0.1 avoids the IPv6/IPv4 mismatch.

Fixes #346
2026-07-04 18:06:31 +02:00
ThePhaseless 8c3e7a9fe4 refactor: use pydantic-settings for environment configuration
- Add pydantic-settings as direct dependency

- Replace os.getenv calls with typed Settings class

- Add BLOCK_MEDIA and RETURN_ONLY_COOKIES env defaults
2026-07-04 17:42:53 +02:00
ThePhaseless 80a608a629 feat: add blockMedia, returnOnlyCookies, PDF handling and fix timeout/networkidle
- Catch both builtins.TimeoutError and playwright TimeoutError as 408

- Check challenge title before networkidle to avoid timeout on Cloudflare interstitial

- Add blockMedia and returnOnlyCookies request options

- Return raw PDF bytes as base64 with contentType application/pdf

- Skip tests on 408 timeouts; add PDF handling test
2026-07-04 17:34:54 +02:00
ThePhaseless 4800ef7f5f feat: migrate from camoufox to invisible_playwright
- Replace camoufox[geoip] with invisible_playwright git dependency

- Switch playwright-captcha framework from CAMOUFOX to PLAYWRIGHT

- Remove camoufox addon path from consts

- Add git to Docker base image; fetch invisible_playwright binary

- Make /cache writable for runtime USER 1000
2026-07-04 17:34:48 +02:00
ThePhaseless 10aa77fb00 fix: revert to camoufox 0.4.*, pin playwright==1.60.*
cloverlabs-camoufox 0.6.0 was a confirmed regression (3/6 tests failed
with 'Cloudflare iframes not found' vs 6/6 passing on camoufox 0.4.11).
Revert to camoufox[geoip]==0.4.* and pin playwright==1.60.* (exact pin
to avoid the 1.61 protocol error).
2026-07-04 16:14:37 +02:00
renovate[bot] 7a306ede63 chore(config): migrate config renovate.json (#371)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-04 15:53:18 +02:00
ThePhaseless b177dc6ad4 feat: migrate to cloverlabs-camoufox, pin playwright<1.61, add tini as PID 1
- Migrate from daijro/camoufox==0.4.* to cloverlabs-camoufox==0.6.*
  (drop-in API: same import path, same kwargs)
- Pin playwright>=1.58,<1.61 to prevent protocol error
  (Browser.setDefaultViewport viewport.isMobile incompatibility with
  camoufox bundled Firefox v135.0.1-beta.24; upstream daijro/camoufox#653)
- Bump fastapi 0.136->0.139, pytest 9.0->9.1, pytest-asyncio 1.3->1.4
  (absorbs Renovate PRs #360, #359, #357)
- Remove dead deptry DEP002 pyautogui ignore (cloverlabs dropped pyautogui)
- Add tini to Dockerfile base image and set as ENTRYPOINT PID 1
  (fixes zombie/defunct Firefox subprocesses: [Socket Process],
  [RDD Process], [Utility Process] — verified: 21 zombies without tini,
  0 zombies with tini after 5 POST /v1 requests)
- Remove init: true from compose.yaml (tini makes it redundant)
- Remove --init/init: true checkbox from bug report template

Closes #339, #340, #360, #359, #357, #366
2026-07-04 15:18:21 +02:00
renovate[bot] d9c56163cc chore(deps): update sigstore/cosign-installer action to v4.1.2 (#350)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-04 05:24:24 -07:00
renovate[bot] e653c23998 chore(deps): update actions/checkout action to v7 (#363)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-04 05:24:21 -07:00
renovate[bot] cf744cf090 chore(deps): update ghcr.io/devcontainers/features/docker-in-docker docker tag to v4 (#365)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-04 05:24:13 -07:00
ThePhaseless 912e722057 fix(docker): pin base to ubuntu:24.04 to fix broken build
ubuntu:latest rolled to 26.04 LTS on 2026-05-06, breaking the Docker
build for 50+ consecutive CI runs. Playwright 1.58.0 (pinned in uv.lock)
cannot install firefox deps for ubuntu26.04-x64 -- it prints 'Cannot
install dependencies for ubuntu26.04-x64 with Playwright 1.58.0!' and
installs nothing, leaving libgtk-3.so.0 absent. Camoufox's bundled
Firefox then fails to load XPCOM at runtime:

  libgtk-3.so.0: cannot open shared object file: No such file or directory
  Couldn't load XPCOM.

Pinning to 24.04 (the last-known-good base, supported by Playwright 1.58)
restores libgtk-3-0t64 and the rest of the GTK runtime. Adopted from PR #362
which independently diagnosed the same issue.

Verified locally:
- app stage: ldconfig shows libgtk-3.so.0 present (was absent)
- test target: 6/6 tests pass (was BrowserType.launch failure)
- runtime: POST /v1 returns 200 status:ok (was 500 libgtk-3 traceback)
2026-07-04 13:48:24 +02:00
renovate[bot] 132db521ec chore(deps): update actions/github-script action to v9 (#341)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-05-04 19:15:00 +02:00
renovate[bot] 7b5261b539 chore(deps): update sigstore/cosign-installer action to v4 (#344)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-05-04 19:14:41 +02:00
renovate[bot] ce6b4e84d6 chore(deps): update dependency pytest to v9.0.3 [security] (#342)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-04-17 01:17:49 +00:00
renovate[bot] 680c5cd709 fix(deps): update dependency fastapi to ==0.136.* (#343)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-04-16 23:32:34 +00:00
ThePhaseless 2934fb5571 add lockfile maintenance 2026-03-30 12:42:25 +00:00
CopilotandThePhaseless 103b5f5c83 Reduce Docker image size (#337)
* Initial plan

* reduce docker image size: clean caches, remove apt upgrade, use --no-install-recommends

Co-authored-by: ThePhaseless <33990351+ThePhaseless@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ThePhaseless <33990351+ThePhaseless@users.noreply.github.com>
2026-03-21 13:31:49 +01:00
ThePhaseless 6993294ffc Support running the container with arbitrary non-root users (#334)
Fixes #331
Co-authored-by: nathan <nathan@nzm.ca>
2026-03-19 15:05:38 +01:00
renovate[bot] 1064addf5e chore(deps): update dependency deptry to ==0.25.* (#335)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-19 04:58:07 +00:00
CopilotandThePhaseless 27040fdad9 Fix healthcheck to respect PORT environment variable (#330)
* Initial plan

* Fix healthcheck to respect PORT environment variable

Co-authored-by: ThePhaseless <33990351+ThePhaseless@users.noreply.github.com>

* Remove explanatory comment from Dockerfile HEALTHCHECK

Co-authored-by: ThePhaseless <33990351+ThePhaseless@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ThePhaseless <33990351+ThePhaseless@users.noreply.github.com>
2026-03-10 21:46:31 +01:00
renovate[bot] 353eb53280 chore(deps): update docker/login-action action to v4 (#325)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-10 20:53:19 +01:00
renovate[bot] 4c328b2c82 chore(deps): update docker/setup-qemu-action action to v4 (#326)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-10 20:53:11 +01:00
renovate[bot] 280c20136a chore(deps): update docker/setup-buildx-action action to v4 (#327)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-10 20:53:03 +01:00
renovate[bot] 4e1761644c chore(deps): update docker/metadata-action action to v6 (#328)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-10 20:52:56 +01:00
renovate[bot] 5a28a99203 chore(deps): update docker/build-push-action action to v7 (#329)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-10 20:52:45 +01:00
renovate[bot] 818b54848c fix(deps): update dependency fastapi to ==0.135.* (#324)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-02 02:15:47 +00:00
renovate[bot] 740efc573e fix(deps): update dependency fastapi to ==0.134.* (#323)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-28 01:00:34 +00:00
renovate[bot] 1a18bbfe1a fix(deps): update dependency fastapi to ==0.133.* (#321)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-24 19:11:48 +00:00
renovate[bot] 1826610937 fix(deps): update dependency fastapi to ==0.132.* (#320)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-24 02:09:13 +00:00
renovate[bot] 27ee7c2fb8 fix(deps): update dependency fastapi to ==0.131.* (#319)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-22 20:57:33 +00:00
renovate[bot] 8575316da6 fix(deps): update dependency fastapi to ==0.129.* (#317)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-12 22:24:32 +00:00
ThePhaseless dac2f60b46 [skip ci] add update info and fix md linting 2026-02-08 15:16:30 +00:00
ThePhaseless b5535fba02 [skip ci] Revise local install instructions in README
Updated installation instructions to include cloning the repository and revised the steps.
2026-02-08 15:30:50 +01:00
ThePhaseless 3e6a847cf2 force string on yes no label 2026-02-08 14:23:58 +00:00
ThePhaseless c1d478f7b2 Fix numbering in README instructions 2026-02-08 14:00:17 +01:00
renovate[bot] 1e726296a3 chore(deps): update python to ==3.14.* (#261)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-08 12:42:41 +00:00
ThePhaseless 1ba0bb3c5e add proxy per request 2026-02-08 12:17:06 +00:00
ThePhaseless a909098b43 Add Usage section to readme and add logo 2026-02-08 12:02:10 +00:00
ThePhaseless fadcef5fc2 add AGENTS.md 2026-02-08 11:52:18 +00:00
ThePhaseless 5af383ac3e add toml extension to devcontainer 2026-02-08 11:50:46 +00:00
ThePhaseless d15707c684 update packages 2026-02-08 11:50:37 +00:00
ThePhaseless 4be9674f82 ignore linter warning 2026-02-08 11:50:33 +00:00
ThePhaseless a35732596e add main tag info 2026-02-08 11:46:21 +00:00
renovate[bot] f5d4b02d64 chore(deps): update dependency ruff to ==0.15.* (#304)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-04 01:01:14 +00:00
ThePhaseless d9517de15f Add main tag troubleshooting checkbox to bug report template 2026-01-10 09:48:37 +01:00
renovate[bot] c4c924ead0 fix(deps): update dependency fastapi to ==0.128.* (#299)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-12-27 22:05:29 +00:00
ThePhaseless 8bf82a081a [skip ci] remove claude code reviews 2025-12-26 19:57:34 +00:00
renovate[bot] 98de158d00 chore(deps): update actions/github-script action to v8 (#280)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-12-26 19:37:10 +01:00
renovate[bot] e894e0bf73 chore(deps): update dependency pytest to v9 (#271)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-12-26 19:36:35 +01:00
renovate[bot] da620267b8 chore(deps): update actions/checkout action to v6 (#282)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-12-26 19:35:17 +01:00
Luís Oliveira 3a45795db3 Adds SVG logo (#290) 2025-12-26 19:34:13 +01:00
renovate[bot] f91bc1aae7 fix(deps): update dependency fastapi to ==0.127.* (#298)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-12-21 20:38:41 +00:00
renovate[bot] d223bb058a fix(deps): update dependency fastapi to ==0.126.* (#297)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-12-20 20:53:50 +00:00
renovate[bot] 463e1ae83c fix(deps): update dependency fastapi to ==0.125.* (#296)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-12-18 04:26:14 +00:00
renovate[bot] 4a21ba6906 fix(deps): update dependency fastapi to ==0.124.* (#292)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-12-06 17:47:24 +00:00
ThePhaseless fcbc782564 Fix formatting in bug report template options 2025-11-30 22:01:11 +01:00
ThePhaseless dd72488a44 Fix formatting in bug report template options 2025-11-30 22:00:59 +01:00
ThePhaseless a8f0d95488 Fix formatting in bug report template options 2025-11-30 22:00:40 +01:00
ThePhaseless 0cd4401955 Fix formatting of options in bug report template 2025-11-30 22:00:05 +01:00
ThePhaseless 3a99ff1fbb Add checklist item for Docker initialization steps 2025-11-30 21:59:46 +01:00
renovate[bot] 2db12eb329 fix(deps): update dependency fastapi to ==0.123.* (#288)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-11-30 20:30:30 +00:00
renovate[bot] 277ae38264 fix(deps): update dependency fastapi to ==0.122.* (#285)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-11-25 00:38:37 +00:00
ThePhaselessandClaude da6d90fabc renovate - Only test (#281)
* Skip build and review for Renovate PRs, only run tests

Modified CI workflows to optimize Renovate PRs:
- Skip Docker build and merge-and-push jobs for Renovate PRs
- Skip Claude code review for Renovate PRs
- Tests still run for all PRs including Renovate

This reduces CI time and resource usage for dependency update PRs.

* Remove redundant condition from merge-and-push job

The merge-and-push job depends on build job, so it won't run if build is skipped.

---------

Co-authored-by: Claude <noreply@anthropic.com>
2025-11-20 01:39:54 +01:00
ThePhaselessandClaude c45a464462 Add Building Feature (#276)
* feat: Build Docker images for PRs with branch name labels

- Remove condition preventing PR builds
- Add branch name extraction and sanitization
- Add branch labels to Docker images (org.opencontainers.image.branch and branch)
- Enable pushing of PR Docker images
- Sanitize branch names for Docker tags (replace / with -)

This allows PR images to be built and tagged with their branch names,
making it easier to test specific PR builds.

* feat: Add path filters to Docker workflow

Only build Docker images when relevant files change:
- Source code (src/**, main.py, tests/**)
- Docker configuration (Dockerfile, compose.yaml)
- Dependencies (pyproject.toml, uv.lock)
- Workflow file itself

This prevents unnecessary builds when only documentation or
other non-functional files are changed.

* feat: Add automatic cleanup of PR Docker images

Create a new workflow that automatically deletes Docker images
when a PR is closed or merged. This prevents accumulation of
old PR images in the container registry.

Features:
- Triggers on PR close/merge events
- Deletes images tagged with PR number and SHA
- Handles both architecture variants (amd64, arm64)
- Supports both organization and user repositories
- Provides detailed logging of cleanup operations

* refactor: Remove redundant branch label preparation

Remove duplicate branch name preparation step in merge-and-push job.
Branch labels are already added during the build step, so no need
to add them again when creating the manifest.

* refactor: Remove redundant label configurations

Remove custom label configurations from docker-publish workflow.
The docker/metadata-action already sets standard OCI labels by
default, so explicit label configuration is unnecessary.

Also removed unused BRANCH_TAG variable preparation.

* refactor: Use PR number for Docker image tags instead of SHA

Changed Docker image tagging strategy for pull requests:
- Use pr-{number}-{arch} for individual platform builds
- Use pr-{number} for final manifest
- Non-PR builds still use SHA-based tags

Benefits:
- Simpler, more readable tags for PRs
- Easier to identify which PR an image belongs to
- Cleanup script simplified to match only PR number tags

Updated cleanup workflow to match new tag pattern.

* docs: Add PR Docker image tags to README

Document the pr-{number} tag pattern used for pull request images.
These images are automatically built for PRs and cleaned up when
the PR is closed.

---------

Co-authored-by: Claude <noreply@anthropic.com>
2025-11-20 01:25:00 +01:00
renovate[bot] fd256a3ab6 chore(deps): update dependency pytest-asyncio to ==1.3.* (#273)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-11-16 06:13:01 +00:00
renovate[bot] f3c7153edc chore(deps): update dependency deptry to ==0.24.* (#272)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-11-15 04:02:36 +00:00
ThePhaseless f1696fe0fd Update claude-code-review.yml 2025-11-15 04:47:34 +01:00
ThePhaseless 12e5a1646b Enable full output for Claude code review action 2025-11-15 04:37:59 +01:00
Thirawyn91 a8d1157b26 Change default PORT from 8196 to 8191 (#267) 2025-11-08 23:05:22 +01:00
renovate[bot] a4d1777db0 fix(deps): update dependency fastapi to ==0.121.* (#270)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-11-03 19:43:52 +00:00
renovate[bot] b9af1e5693 fix(deps): update dependency fastapi to ==0.120.* (#265)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-10-24 05:11:43 +00:00
renovate[bot] 0977a0daf9 chore(deps): update actions/checkout action to v5 (#260)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-10-17 22:15:25 +02:00
ThePhaseless d8cd7cc571 remake dockerfile 2025-10-16 09:36:09 +00:00
ThePhaseless a5bdd2c144 use non-root user 2025-10-15 13:07:09 +00:00
ThePhaseless afd360cc95 remove pytest progress 2025-10-15 12:50:47 +00:00
oldwombatandAdam Roddick 7054136320 fix readme table (#256)
Co-authored-by: Adam Roddick <13641602+adamcybersec@users.noreply.github.com>
2025-10-15 09:29:13 +02:00
ThePhaseless 82f0e4ca01 bump deps and stay on python 3.13 2025-10-15 07:02:00 +00:00
ThePhaseless 560da0daf0 Add Claude Code GitHub Workflow (#259)
* "Claude PR Assistant workflow"

* "Claude Code Review workflow"
2025-10-15 08:20:21 +02:00
renovate[bot] 442254a0e8 chore(deps): update dependency ruff to ==0.14.* (#252)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-10-08 05:02:58 +00:00
ThePhaseless f8187deda1 install uv globally 2025-10-01 13:06:33 +00:00
ThePhaseless 39b804da55 add host and port as env 2025-10-01 12:09:53 +00:00
renovate[bot] f4daffca61 fix(deps): update dependency fastapi to ==0.118.* (#250)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-09-29 11:31:50 +00:00
renovate[bot] 1d5f35bd3e fix(deps): update dependency fastapi to ==0.117.* (#244)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-09-21 00:33:36 +00:00
renovate[bot] 2089cfe717 chore(deps): update dependency pytest-asyncio to ==1.2.* (#242)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-09-12 21:26:22 +00:00
ThePhaseless 9b5f2282db [skip ci] use init for containers for zombie processes 2025-09-12 20:08:34 +00:00
ThePhaseless 849e33dff3 use timer to timeout functions 2025-09-11 20:26:11 +00:00
ThePhaseless d25ce2ad94 add icon 2025-09-11 17:10:28 +00:00
ThePhaseless d78b1df041 change healthcheck msg 2025-09-11 16:55:05 +00:00
ThePhaseless c66d4e7084 return 200 if intersite challenge 2025-09-11 16:54:50 +00:00
ThePhaseless 9183a74fc3 use maxsize instead of power 2025-09-11 16:54:19 +00:00
ThePhaseless d29666151d dont build on pull request 2025-09-11 18:25:04 +02:00
renovate[bot] 2216d28e62 chore(deps): update dependency ruff to ==0.13.* (#239)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-09-11 01:53:53 +00:00
ThePhaseless 9ffc2bb5b3 fix exception 2025-09-10 20:47:59 +00:00
ThePhaseless 5f053ecd29 add logger for lib if debug 2025-09-10 22:46:03 +02:00
ThePhaseless 91e5279818 log loglevel 2025-09-10 22:45:55 +02:00
ThePhaseless 258f0bdbad add faster turnstile check 2025-09-10 22:45:40 +02:00
25 changed files with 2164 additions and 1317 deletions
+6 -2
View File
@@ -9,7 +9,11 @@
"runArgs": ["--security-opt", "label=disable", "--privileged"],
"customizations": {
"vscode": {
"extensions": ["charliermarsh.ruff", "ms-python.python"],
"extensions": [
"charliermarsh.ruff",
"ms-python.python",
"tamasfe.even-better-toml"
],
"settings": {
"python.venvPath": "./venv"
}
@@ -17,7 +21,7 @@
},
"postCreateCommand": "uv sync --group test",
"features": {
"ghcr.io/devcontainers/features/docker-in-docker:2": {
"ghcr.io/devcontainers/features/docker-in-docker:4": {
"moby": false
}
}
+3
View File
@@ -0,0 +1,3 @@
# Supported funding model platforms
github: [ThePhaseless]
+11 -2
View File
@@ -13,6 +13,8 @@ body:
- label: Checked if such issue already exists
- label: Checked other websites with Cloudflare Turnstile
- label: I am able to access the webpage from my browser
- label: (Docker only) Checked that the problem does also occur on main tag
- type: checkboxes
attributes:
label: "If checked other websites with Cloudflare Turnstile:"
@@ -20,11 +22,18 @@ body:
- label: Other websites do work.
- label: Other websites do not work.
- type: checkboxes
attributes:
label: "The issue is still present in the latest main tag:"
options:
- label: "Yes"
- label: "No"
- type: input
id: docker-host
attributes:
label: OS/Docker Host
placeholder: e.g. Docker, WSL2, Ubuntu, Windows
placeholder: e.g. Docker, WSL2, Ubuntu, Windows
- type: input
id: platform-model
@@ -49,7 +58,7 @@ body:
label: Describe the bug
description: A clear and concise description of what the bug is.
placeholder: "Example: The application crashes when trying to load a new file"
- type: textarea
id: config
attributes:
+107
View File
@@ -0,0 +1,107 @@
name: Cleanup PR Docker Images
on:
pull_request:
types: [closed]
env:
REGISTRY: ghcr.io
IMAGE_NAME: ${{ github.repository }}
jobs:
cleanup:
runs-on: ubuntu-latest
permissions:
packages: write
contents: read
steps:
- name: Delete PR Docker images
uses: actions/github-script@v9
with:
script: |
const owner = context.repo.owner.toLowerCase();
const repo = context.repo.repo.toLowerCase();
const prNumber = context.payload.pull_request.number;
// Get the package
const packageName = `${repo}`;
console.log(`Cleaning up images for PR #${prNumber}`);
// Check if owner is an org or user
let isOrg = false;
try {
await github.rest.orgs.get({ org: owner });
isOrg = true;
console.log(`Repository owner is an organization`);
} catch (error) {
console.log(`Repository owner is a user account`);
}
try {
// Get all versions of the package
let versions;
if (isOrg) {
versions = await github.rest.packages.getAllPackageVersionsForPackageOwnedByOrg({
package_type: 'container',
package_name: packageName,
org: owner,
per_page: 100
});
} else {
versions = await github.rest.packages.getAllPackageVersionsForPackageOwnedByUser({
package_type: 'container',
package_name: packageName,
username: owner,
per_page: 100
});
}
// Filter versions that match this PR (pr-123, pr-123-amd64, pr-123-arm64)
const prVersions = versions.data.filter(version => {
const tags = version.metadata?.container?.tags || [];
// Match tags like: pr-123, pr-123-amd64, pr-123-arm64
return tags.some(tag =>
tag === `pr-${prNumber}` ||
tag === `pr-${prNumber}-amd64` ||
tag === `pr-${prNumber}-arm64`
);
});
console.log(`Found ${prVersions.length} image version(s) to delete`);
// Delete each version
for (const version of prVersions) {
console.log(`Deleting version ${version.id} with tags: ${version.metadata?.container?.tags?.join(', ')}`);
try {
if (isOrg) {
await github.rest.packages.deletePackageVersionForOrg({
package_type: 'container',
package_name: packageName,
org: owner,
package_version_id: version.id
});
} else {
await github.rest.packages.deletePackageVersionForUser({
package_type: 'container',
package_name: packageName,
username: owner,
package_version_id: version.id
});
}
console.log(`✓ Deleted version ${version.id}`);
} catch (error) {
console.error(`Failed to delete version ${version.id}:`, error.message);
}
}
console.log('Cleanup completed');
} catch (error) {
if (error.status === 404) {
console.log('No package found - nothing to clean up');
} else {
console.error('Error during cleanup:', error.message);
throw error;
}
}
+75 -33
View File
@@ -9,11 +9,29 @@ on:
schedule:
- cron: "25 0 * * *"
push:
branches: ["*"]
branches: ["main"]
# Publish semver tags as releases.
tags: ["v*.*.*"]
paths:
- "src/**"
- "main.py"
- "tests/**"
- "Dockerfile"
- "pyproject.toml"
- "uv.lock"
- "compose.yaml"
- ".github/workflows/docker-publish.yml"
pull_request:
branches: ["main"]
paths:
- "src/**"
- "main.py"
- "tests/**"
- "Dockerfile"
- "pyproject.toml"
- "uv.lock"
- "compose.yaml"
- ".github/workflows/docker-publish.yml"
workflow_dispatch:
env:
@@ -36,24 +54,28 @@ jobs:
steps:
- name: Checkout repository
uses: actions/checkout@v5
uses: actions/checkout@v7
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@v4
- name: Test
id: test
uses: docker/build-push-action@v6
uses: docker/build-push-action@v7
with:
context: .
platforms: linux/amd64
cache-from: type=gha,scope=x64
cache-from: type=gha,scope=amd64
pull: true
cache-to: type=gha,mode=max,scope=x64
cache-to: type=gha,mode=max,scope=amd64
target: test
build-args: |
GITHUB_BUILD=true
build:
needs: test
# Skip build for Renovate PRs
if: github.event.pull_request.user.login != 'renovate[bot]'
runs-on: ubuntu-latest
permissions:
contents: read
@@ -66,26 +88,31 @@ jobs:
steps:
- name: Checkout repository
uses: actions/checkout@v5
uses: actions/checkout@v7
- name: Prepare variables
id: vars
run: |
SURFIX=$(echo ${{ matrix.platform }} | cut -d'/' -f2)
echo "SURFIX=$SURFIX" >> $GITHUB_OUTPUT
# Generate a unique local tag for the image
echo "LOCAL_TAG=${{ github.sha }}-$SURFIX" >> $GITHUB_OUTPUT
# Use PR number for PRs, SHA for everything else
if [ "${{ github.event_name }}" == "pull_request" ]; then
echo "LOCAL_TAG=pr-${{ github.event.pull_request.number }}-$SURFIX" >> $GITHUB_OUTPUT
else
echo "LOCAL_TAG=${{ github.sha }}-$SURFIX" >> $GITHUB_OUTPUT
fi
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
uses: docker/setup-qemu-action@v4
# Set up BuildKit Docker container builder
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@v4
# Log into registry
- name: Log into registry ${{ env.REGISTRY }}
uses: docker/login-action@v3
uses: docker/login-action@v4
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
@@ -94,24 +121,24 @@ jobs:
# Extract metadata (tags, labels) for Docker
- name: Extract Docker metadata
id: meta
uses: docker/metadata-action@v5
uses: docker/metadata-action@v6
with:
tags: type=raw,value=${{ steps.vars.outputs.LOCAL_TAG }}
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
# Build and export Docker image for each platform (without pushing)
# Build and push Docker image for each platform
- name: Build Docker image
id: build
uses: docker/build-push-action@v6
uses: docker/build-push-action@v7
with:
context: .
pull: true
push: ${{ github.event_name != 'pull_request' }}
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
platforms: ${{ matrix.platform }}
cache-from: type=gha,scope=${{ matrix.platform }}
cache-to: type=gha,mode=max,scope=${{ matrix.platform }}
cache-from: type=gha,scope=${{ steps.vars.outputs.SURFIX }}
cache-to: type=gha,mode=max,scope=${{ steps.vars.outputs.SURFIX }}
build-args: |
GITHUB_BUILD=true
VERSION=${{ github.ref_type == 'tag' && github.ref_name || github.sha }}
@@ -119,7 +146,6 @@ jobs:
merge-and-push:
needs: build
runs-on: ubuntu-latest
if: github.event_name != 'pull_request'
permissions:
contents: read
packages: write
@@ -127,19 +153,19 @@ jobs:
steps:
- name: Checkout repository
uses: actions/checkout@v5
uses: actions/checkout@v7
# Install the cosign tool
- name: Install cosign
uses: sigstore/cosign-installer@v3
uses: sigstore/cosign-installer@v4.1.2
# Set up Docker Buildx
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@v4
# Log into registry
- name: Log into registry ${{ env.REGISTRY }}
uses: docker/login-action@v3
uses: docker/login-action@v4
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
@@ -148,7 +174,7 @@ jobs:
# Extract Docker metadata for tagging
- name: Extract Docker metadata
id: meta
uses: docker/metadata-action@v5
uses: docker/metadata-action@v6
with:
tags: |
type=ref,event=branch
@@ -160,6 +186,7 @@ jobs:
# Create manifest lists and push
- name: Create and push manifest lists
id: manifests
run: |
TAGS="${{ steps.meta.outputs.tags }}"
args=""
@@ -178,15 +205,30 @@ jobs:
echo $args
docker buildx imagetools create $args \
${image}:${{github.sha}}-amd64 \
${image}:${{github.sha}}-arm64
# Use PR-based tags for PRs, SHA-based tags for everything else
if [ "${{ github.event_name }}" == "pull_request" ]; then
docker buildx imagetools create $args \
${image}:pr-${{ github.event.pull_request.number }}-amd64 \
${image}:pr-${{ github.event.pull_request.number }}-arm64
else
docker buildx imagetools create $args \
${image}:${{github.sha}}-amd64 \
${image}:${{github.sha}}-arm64
fi
# Sign the manifest
- name: Sign the manifests
# All tags created above alias a single manifest list; capture its digest
# so the signature is bound to the image bytes, not a mutable tag.
# Tags from metadata-action are full references (image:tag), one per line,
# so take the first line rather than splitting on spaces.
FIRST_TAG=$(printf '%s' "$TAGS" | head -n1)
DIGEST=$(docker buildx imagetools inspect --format '{{.Manifest.Digest}}' "$FIRST_TAG")
echo "DIGEST=$DIGEST" >> $GITHUB_OUTPUT
# Sign the manifest list by digest — every consumer tag aliases this digest
- name: Sign the manifest list by digest
env:
TAGS: ${{ steps.meta.outputs.tags }}
IMAGE: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
DIGEST: ${{ steps.manifests.outputs.DIGEST }}
run: |
for TAG in $TAGS; do
cosign sign --yes $TAG
done
image=${IMAGE,,}
cosign sign --yes ${image}@${DIGEST}
+37
View File
@@ -0,0 +1,37 @@
# Copilot Instructions
## Project overview
- FastAPI service that mimics FlareSolverr-style API for bypassing anti-bot pages using invisible_playwright.
- Entry point: main app in main.py; routes and request flow in src/endpoints.py, challenge handling in src/challenge.py, response bodies in src/content.py, models in src/models.py.
- Browser lifecycle is owned by get_browser() in src/utils.py, which yields a page and context for each request.
## Architecture and data flow
- Request flow: POST /v1 -> read_item() -> page.goto() -> wait for load states -> detect the interstitial -> click its checkbox until it clears -> return LinkResponse.
- Challenge detection uses detect_cloudflare_challenge() from playwright_captcha; the challenge is over when its markup goes, not when a solver says so.
- Health check hits /v1 internally with <https://google.com> and fails if status is not OK.
- Logging: LogRequest middleware logs only POST /v1 timing and outcome; other paths pass through.
## Key modules and patterns
- Models use Pydantic v2 with camelCase aliasing for responses (see src/models.py).
- LinkResponse.invalid() is the standard error response shape; keep fields consistent with FlareSolverr style.
- get_camoufox() constructs AsyncCamoufox with addons and optional proxy config from env vars.
## Config and environment
- Core env vars in src/consts.py: HOST, PORT, PROXY_SERVER, PROXY_USERNAME, PROXY_PASSWORD, LOG_LEVEL, VERSION.
- VERSION strips leading "v" for tag-style values.
## Developer workflows
- Local run: uv sync && uv run main.py
- Init mode: uv run main.py --init (pre-warms health check via browser setup)
- Tests: uv sync --group test && uv run pytest --retries 5
- Docker troubleshooting: docker build --target test .
## Tests and external dependencies
- tests/main_test.py calls real websites; tests are network-dependent and may be skipped based on upstream status.
- HTTP client tests use starlette.testclient + httpx; avoid mocking unless needed for local-only changes.
+42 -22
View File
@@ -1,42 +1,62 @@
FROM debian:stable-slim AS base
ENV HOME=/root
# Ubuntu is required by playwright.
# Pin to 24.04 LTS: ubuntu:latest floats to 26.04, which Playwright 1.58
# cannot install firefox deps for (no libgtk-3 -> camoufox fails to launch).
FROM ubuntu:24.04 AS base
ARG GITHUB_BUILD=false \
VERSION
ARG GITHUB_BUILD=false
ENV GITHUB_BUILD=${GITHUB_BUILD}\
VERSION=${VERSION}\
DEBIAN_FRONTEND=noninteractive \
PYTHONUNBUFFERED=1 \
# prevents python creating .pyc files
PYTHONDONTWRITEBYTECODE=1 \
UV_LINK_MODE=copy \
PATH="${HOME}/.local/bin:$PATH"
PORT=8191 \
XDG_CACHE_HOME=/cache \
HOME=/home/byparr
WORKDIR /app
RUN apt update && apt -y upgrade && apt install -y curl
ADD https://astral.sh/uv/install.sh install.sh
RUN sh install.sh && uv --version
RUN uvx playwright install-deps firefox && uvx camoufox fetch
RUN apt-get update &&\
apt-get install -y --no-install-recommends curl ca-certificates git tini &&\
apt-get clean &&\
rm -rf /var/lib/apt/lists/*
COPY --from=ghcr.io/astral-sh/uv:latest /uv /uvx /bin/
FROM base AS devcontainer
RUN apt install -y git
RUN apt-get update &&\
apt-get install -y --no-install-recommends git &&\
uvx playwright install-deps firefox &&\
uvx --from git+https://github.com/feder-cr/invisible_playwright.git python -m invisible_playwright fetch &&\
apt-get clean &&\
rm -rf /var/lib/apt/lists/*
ENTRYPOINT [ "sleep", "infinity" ]
FROM base AS app
WORKDIR /app
COPY pyproject.toml uv.lock ./
RUN --mount=type=cache,target=${HOME}/.cache/uv uv sync
RUN mkdir -p /cache &&\
uv sync &&\
uv run python -m invisible_playwright fetch &&\
apt-get update &&\
uv run playwright install-deps firefox &&\
uv cache clean &&\
apt-get clean &&\
rm -rf /var/lib/apt/lists/*
COPY . .
RUN mkdir -p /home/byparr &&\
chmod -R o+rX /app &&\
chmod -R a+rwX /cache /home/byparr
FROM app AS test
RUN --mount=type=cache,target=${HOME}/.cache/uv uv sync --group test
RUN uv run pytest --retries 3 -n auto
RUN \
uv sync --group test &&\
uv run pytest -rs --retries 5
FROM app
EXPOSE 8191
HEALTHCHECK --interval=15m --timeout=30s --start-period=5s --retries=3 CMD [ "curl", "http://localhost:8191/health" ]
ENTRYPOINT ["uv", "run", "main.py"]
ARG VERSION
ENV VERSION=${VERSION}
USER 1000
EXPOSE $PORT
HEALTHCHECK --interval=15m --timeout=30s --start-period=5s --retries=3 CMD curl "http://127.0.0.1:${PORT}/health"
ENTRYPOINT ["tini", "--", "/app/.venv/bin/python", "main.py"]
+88 -43
View File
@@ -1,44 +1,29 @@
# Byparr
# Byparr [![Sponsor](https://img.shields.io/badge/Sponsor-%E2%9D%A4-ea4aaa?logo=github-sponsors)](https://github.com/sponsors/ThePhaseless)
Built with [camoufox](https://camoufox.com/) and [FastAPI](https://fastapi.tiangolo.com), this project aims to mimic [FlareSolverr's](https://github.com/FlareSolverr/FlareSolverr) API and functionality of providing you with http cookies and headers for websites protected with anti-bot protections.
<p align="center">
<img src="icon/logo-byparr.svg" alt="Byparr logo" width="120" />
</p>
> [!IMPORTANT]
> This software does not **guarantee** (only greatly increases the chance) that any challenge will be bypassed. While this tool passes the initial browser check, Cloudflare and other captcha providers likely require valid network traffic originating from the user’s public IP address to mark a connection as legitimate. If any website does not pass the challenge, please run troubleshooting steps and check if other websites work before you create an GitHub issue.
> [!IMPORTANT]
> Support for NAS devices (like Synology) is minimal. Please report issues, but do not expect it to be fixed quickly. The only ARM device I have is a free Ampere Oracle VM, so I can only test ARM support on that. See [#22](https://github.com/ThePhaseless/Byparr/issues/22) and [#3](https://github.com/ThePhaseless/Byparr/issues/3)
> [!NOTE]
> Thanks to FastAPI implementation, now you can also see the API documentation at `/docs` or `/` (redirect to `/docs`) endpoints.
## Troubleshooting
### Docker
1. Clone repo to the host that has issues with Byparr.
2. Run `docker build --target test .`
3. Depending of the build success:
1. If run successfully, try updating container or if already on newest stable release create an issue for creating new release with new dependencies
2. If build fails, try troubleshooting on another host/using other method
### Local
1. Download [uv](https://docs.astral.sh/uv/getting-started/installation/)
2. Download dependencies using `uv sync --group test`
3. Run tests with `uv run pytest --retries 3` (You can add `-n auto` for parallelization)
4. If you see any `F` character in terminal, that means test failed even after retries.
5. Depending of the test success:
1. If run successfully, try updating container or if already on newest stable release create an issue for creating new release with new dependencies
2. If test fails, try troubleshooting on another host/using other method
## Options
| Environment Variable | Default | Description |
| -------------------- | --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `HOST` | `0.0.0.0` | Host address to bind the server to. Use `0.0.0.0` to bind to all IPv4 interfaces, `::` for all IPv6 interfaces, or `127.0.0.1`/`localhost` for local access only. |
| `PORT` | `8191` | Port to bind the server to. |
| `PROXY_SERVER` | None | Proxy to use in format: `protocol://host:port`. |
| `PROXY_USERNAME` | None | |
| `PROXY_PASSWORD` | None | |
| `PROXY_USERNAME` | None | Username for proxy authentication. |
| `PROXY_PASSWORD` | None | Password for proxy authentication. |
| `OWUI_API_KEY` | None | Bearer token for `/load` endpoint authentication. Must match `EXTERNAL_WEB_LOADER_API_KEY` in Open WebUI. |
| `BROWSER_LOCALE` | None | Override the browser's language with a [BCP-47](https://www.rfc-editor.org/rfc/bcp/bcp47.txt) tag, e.g. `en-US`, `de-DE`, `fr-FR`. When unset, the locale is derived from the egress country. |
#### Browser language
Set `BROWSER_LOCALE` to a [BCP-47](https://www.rfc-editor.org/rfc/bcp/bcp47.txt) language tag like `en-US`, `de-DE`, `fr-FR`, `pl-PL`, or `zh-CN` to fix the browser's language and `Accept-Language` header. When unset, Byparr derives the locale from the egress country (e.g. a French proxy → `fr-FR`), keeping the browser language consistent with the exit IP.
Valid tags are maintained in the [IANA Language Subtag Registry](https://www.iana.org/assignments/language-subtag-registry/language-subtag-registry). For a friendlier list, see [List of ISO 639-1 codes](https://en.wikipedia.org/wiki/List_of_ISO_639-1_codes) (language) combined with an [ISO 3166-1 alpha-2](https://en.wikipedia.org/wiki/ISO_3166-1_alpha-2) region code for the full tag, e.g. `pt-BR`.
## Proxy Recommendation
@@ -48,30 +33,90 @@ Recently I've partnered with a _new in town_ proxy service - ProxyBase - to offe
- `v*.*.*`/`latest` - Releases considered stable
- `main` - Latest release from main branch (untested)
- `pr-{number}` - Pull request images for testing (automatically cleaned up when PR closes)
## Usage
### Docker Compose
> [!IMPORTANT]
> Support for NAS devices (like Synology) is minimal. Please report issues, but do not expect it to be fixed quickly. The only ARM device I have is a free Ampere Oracle VM, so I can only test ARM support on that. See [#22](https://github.com/ThePhaseless/Byparr/issues/22) and [#3](https://github.com/ThePhaseless/Byparr/issues/3)
See `compose.yaml`
### Docker Compose setup
### Docker
1. Review settings in `compose.yaml`.
2. Start the service:
```bash
docker run -p 8191:8191 ghcr.io/thephaseless/byparr:latest
docker compose up -d
```
### Local
### Docker install
1. Pull and run the image:
```bash
docker run -p 8191:8191 ghcr.io/thephaseless/byparr:latest
```
2. Optional: set env vars using `-e` or `--env-file`.
### Local install
1. Install ([or update when Python version changes](https://github.com/astral-sh/uv/issues/17887)) [uv](https://docs.astral.sh/uv/getting-started/installation/).
2. Clone this repo - `git clone https://github.com/ThePhaseless/Byparr`
3. Run `uv run main.py`
4. Enjoy!
### API Docs
Once running, open:
- `http://localhost:8191/docs`
- `http://localhost:8191/` (redirects to `/docs`)
### Open WebUI Integration
Byparr can serve as an external web loader for [Open WebUI](https://github.com/open-webui/open-webui), allowing it to fetch web content through Byparr's anti-bot bypassing capabilities.
Configure Open WebUI with these environment variables:
```bash
uv sync && uv run main.py
WEB_LOADER_ENGINE=external
EXTERNAL_WEB_LOADER_URL=http://byparr:8191/load
EXTERNAL_WEB_LOADER_API_KEY=your-secret-key # Optional, must match OWUI_API_KEY
```
## Need help with / TODO
The `/load` endpoint accepts `POST` requests with `{"urls": ["https://..."]}` and returns extracted text content for RAG pipelines.
- [x] Slimming container (only ~1.11 GB now!)
- [x] Add more anti-bot challenges
- [x] Add doc strings
- [x] Implement versioning
- [x] Proxy support
- [x] Add more architectures support
## Troubleshooting
### Docker troubleshooting
1. Clone repo to the host that has issues with Byparr.
2. Run `docker build --target test .`
3. Depending of the build success:
1. If run successfully, try updating container or if already on newest stable release create an issue for creating new release with new dependencies
2. If build fails, try troubleshooting on another host/using other method
#### Proxmox OCI / LXC browser launch errors
If you are running Byparr as an OCI container in Proxmox (or another LXC-based setup) and see a `FileNotFoundError` from `multiprocessing.synchronize`/`camoufox` when processing requests, increase the service's shared memory in `compose.yaml`:
```yaml
services:
byparr:
shm_size: 512mb
stdin_open: true
tty: true
```
`shm_size: 512mb` is usually enough; `stdin_open` and `tty` are only needed if your orchestrator runs the container without a TTY.
### Local troubleshooting
1. Download [uv](https://docs.astral.sh/uv/getting-started/installation/)
2. Download dependencies using `uv sync --group test`
3. Run tests with `uv run pytest --retries 3` (You can add `-n auto` for parallelization)
4. If you see any `F` character in terminal, that means test failed even after retries.
5. Depending of the test success:
1. If run successfully, try updating container or if already on newest stable release create an issue for creating new release with new dependencies
2. If test fails, try troubleshooting on another host/using other method
+2
View File
@@ -2,6 +2,8 @@ services:
byparr:
image: ghcr.io/thephaseless/byparr:latest
restart: unless-stopped
# environment:
# LOG_LEVEL: debug
build:
context: .
dockerfile: Dockerfile
Binary file not shown.

After

Width:  |  Height:  |  Size: 45 KiB

+1
View File
@@ -0,0 +1 @@
<svg xmlns="http://www.w3.org/2000/svg" xml:space="preserve" viewBox="0 0 512 512"><path d="M243.9 511.9c-58.1-3.2-110.4-24-155-61.8-7-5.9-21.2-20.1-27.2-27.2-20-23.7-35.2-49.2-45.4-76.5-8.3-22-13-42.6-15.5-67.3-1.1-10.8-1.1-35.7 0-46.5 5.6-54.9 25.6-101.9 61-143.8 5.9-7 20.1-21.2 27.2-27.2 23.7-20 49.2-35.2 76.5-45.4 22-8.3 42.7-13 67.3-15.5 10.8-1.1 35.7-1.1 46.5 0 29.1 3 55.1 9.7 80 20.7 39.2 17.3 72.8 43.6 99.6 78 5.3 6.7 14.8 21 19.4 29.1 15.8 27.6 26.4 58.3 31.1 89.8 2 13.6 2.5 21.5 2.5 37.5s-.5 23.9-2.5 37.5c-7.1 47.8-27.1 91.6-59.2 129.5-5.9 7-20.1 21.2-27.2 27.2-16.4 13.8-34.2 25.8-51.8 34.6-28.8 14.5-59.1 23.1-91.7 26.3-7.4.8-28.9 1.3-35.6 1" style="fill:#fff"/><path d="M246.5 395.1c-1.7-.2-3.9-.3-5-.2-1 .1-3.5 0-5.5-.2-2-.3-6.1-.8-9.3-1.2s-6.7-.9-7.8-1.2c-1.2-.3-7.7-3.2-14.5-6.6s-14.3-7-16.8-8.1c-8.5-3.7-14.5-8.1-18.1-13.4-2.1-3.1-3.7-4.4-8.2-6.7-4-2-6-4.1-10.9-11-2-2.9-5-6.8-6.6-8.7-10.9-12.9-11.1-13.3-12.4-19.5-.5-2.5-1.6-5.4-2.9-7.8-4-7.4-5.4-10.8-6.4-14.9-.5-2.3-1.7-6.6-2.6-9.6-1.5-5.1-1.7-6.1-2.1-15.8-.4-9.4-.4-10.9.5-16.1.5-3.2 1.1-7.4 1.2-9.4.2-2 .6-5.4 1-7.6s.9-6.5 1.2-9.5c1-9.8 2.6-14.1 9.1-23.8 4.2-6.2 5.2-8.5 6-13.5.6-3.9 1.4-5.7 4.1-8.9 1.2-1.5 3.5-5.4 5.1-8.6 3.1-6.4 3.2-6.5 8.2-9.9 1.9-1.3 5.8-4 8.6-6s6.3-4.4 7.6-5.4c1.7-1.2 3.1-2.7 4.3-4.6 4.1-6.6 6.1-8 16.3-11.7 3.1-1.1 7.5-3.1 9.8-4.5 5.3-3.1 9-4.4 15-5 2.8-.3 6.8-1.2 9.8-2.1 4.5-1.4 5.6-1.6 10.4-1.6 5.7 0 6.4-.2 13.2-3.1 4.8-2.1 8.9-2.5 14.8-1.5 2.7.5 7.2 1.1 10.1 1.5 6.2.8 6.1.8 11.2 3.1 3.4 1.5 4.9 1.9 9.3 2.3 7 .7 7.9 1 16.1 5.1 3.9 2 9.5 4.5 12.4 5.7 9.8 3.9 14.3 7.2 22.1 15.7 3.3 3.6 8.6 9.2 11.9 12.5 14.5 14.5 14.9 15 16.5 19.4.8 2.2 2.6 6 3.9 8.3 5.2 9.2 12.2 23.8 13.4 28 .7 2.3 1.9 6.5 2.7 9.3 2.1 6.9 2.4 14.2 1 23.6-1.2 8-1.2 11.9-.3 18 .6 3.6.6 5.5.3 9.4-.7 6.7-1.6 10-4.1 14.1-1.3 2.2-2.4 4.7-2.9 6.6-1.8 7.8-5.6 16.3-10.7 24.3-1.4 2.2-3.4 5.5-4.3 7.4-2.2 4.3-4.2 6.6-8.2 9.6-3.7 2.7-14.5 14-17.7 18.4-2.2 3.1-7.1 7.4-10.6 9.4-1.1.6-4.3 1.8-7.2 2.6s-7.1 2.5-9.5 3.7c-3.6 1.8-5 3-8.6 6.6-2.3 2.4-4.9 4.7-5.7 5.1-1.6.8-5.5 1.5-10.7 2-1.7.2-4.6.8-6.4 1.5-7 2.6-7.3 2.6-16.1 2.7-6.9.1-9.3.3-12.3 1.2-4.9.9-8.8 1.2-12.7.6" style="fill:#cc7a3d"/><path d="M237.7 473.6c-42-3.8-79.9-18.3-113-43.2C56 378.7 24.1 291.7 43.1 207.6c6.6-29.2 19.8-57.8 37.7-81.9 47.7-64.1 126.8-97.1 205.8-85.9 36 5.1 70.5 19.3 99.7 41C455.7 132.5 488 220 468.9 304.4c-11.4 50.4-40.9 95.7-82.6 126.8-29.1 21.7-63.7 35.9-99.7 41-15.1 2.2-34.5 2.7-48.9 1.4m33.7-5.2c29-2.5 54.4-9.5 79-21.8 41.4-20.6 75.5-54.8 96.1-96.1 16.9-34 24.9-74.2 21.8-109.9-3.7-42.4-17.6-79.2-42.3-112-34.4-45.8-84.7-75.5-141.4-83.5-25.2-3.6-49.5-2.5-75.2 3.3-49.6 11.2-93.7 40-124.4 81.2-21.3 28.7-35 62-40.1 97.8-2.8 19.4-2.8 38 0 57.4 8.1 56.7 37.7 107 83.5 141.4 11.1 8.3 21 14.5 33 20.5 34.1 16.9 74.4 24.8 110 21.7" style="fill:#b1b1b1"/><path d="M253.9 367.3c-2.9-.7-4.3-1.4-6-2.9-2.9-2.6-3.9-4.9-3.9-8.9 0-3.9 1-6.3 3.9-8.9 6-5.4 15.8-3.1 19 4.3 1.1 2.6 1 7-.3 9.6-1.2 2.4-3.7 4.9-6 5.8-1.7.8-5.3 1.3-6.7 1m68.4-29.3c-9.2-3.4-11-15.4-3.1-21.1 8.1-5.9 20 1 18.8 11-.5 4-3 7.6-6.7 9.5-2.4 1.2-6.6 1.5-9 .6m-139.8-.2c-3.4-1.1-6.2-3.5-7.9-6.7-1.3-2.4-1.2-7.7.2-10.2 1.2-2.3 3.9-4.8 6.3-5.8 2.6-1.1 7-1 9.6.3 4.2 2.1 6.7 6 6.7 10.7 0 6.5-4.7 11.5-11 11.9-1.5.1-3.3 0-3.9-.2m43.2-22.8c-2.4-.8-4.1-1.9-5.8-3.8-5.4-6-3.1-15.8 4.3-19 2.6-1.1 7-1 9.6.3 2.5 1.2 4.9 3.7 5.9 6.2.9 2.1 1 6.3.1 8.8-.8 2.3-3.5 5.3-5.9 6.6-1.9 1-6.3 1.5-8.2.9m54.6 0c-2.4-.8-4.1-1.9-5.8-3.8-5.4-6-3.1-15.8 4.3-19 2.6-1.1 7-1 9.6.3 2.5 1.2 4.9 3.7 5.9 6.2.9 2.1 1 6.3.1 8.8-.8 2.3-3.5 5.3-5.9 6.6-1.9 1-6.3 1.5-8.2.9m-27.6-47c-2.2-.7-4-1.9-5.5-3.5-2.5-2.7-3.2-4.5-3.2-8.5 0-3.9.7-5.8 3.2-8.5s4.8-3.6 8.8-3.6 6.3.9 8.8 3.6 3.2 4.5 3.2 8.5c0 2.5-.3 4-.9 5.2-1.2 2.3-3.5 4.7-5.7 5.8-1.9 1.1-6.7 1.6-8.7 1m99.7 0c-2.4-.8-4.1-1.9-5.8-3.8-5.4-6-3.1-15.8 4.3-19 2.6-1.1 7-1 9.6.3 2.5 1.2 4.9 3.7 5.9 6.2.9 2.1 1 6.3.1 8.8-.8 2.3-3.5 5.3-5.9 6.6-1.9 1-6.3 1.5-8.2.9m-198.9-.7c-8.9-2.5-11.8-13.8-5.1-20.1 2.6-2.5 4.5-3.2 8.2-3.2 3.9 0 6.3 1 8.9 3.9 2.1 2.3 3 4.7 2.9 8.2 0 7.6-7.5 13.2-14.9 11.2m42.9-.4c-2.3-1.2-5.2-4.1-6.1-6.4-1-2.4-.9-7.1.3-9.5 1.1-2.3 4.1-5.2 6.4-6.2 2.4-1 7.1-.9 9.5.3 2.3 1.1 5.2 4.1 6.2 6.4 1 2.4.9 7.1-.3 9.5-1.1 2.3-4.1 5.2-6.4 6.2-2.5 1.1-7.2.9-9.6-.3m109-.3c-11.1-5.6-7-22.5 5.5-22.4 3.7 0 6.1 1.1 8.6 3.9 2.2 2.4 3.2 4.9 3.2 8s-1 5.6-3.2 8c-2.5 2.8-5 3.9-8.6 3.9-2.3-.1-3.5-.4-5.5-1.4m-79.7-46.3c-8.9-2.5-11.8-13.8-5.1-20.1 2.6-2.5 4.5-3.2 8.2-3.2 3.9 0 6.3 1 8.9 3.9 2.1 2.3 3 4.7 2.9 8.2-.1 7.6-7.6 13.3-14.9 11.2m54.5 0c-8-2.2-11.3-12-6.4-18.5 5.7-7.5 16.1-6.4 20.5 2 1.3 2.4 1.2 7.7-.2 10.2-2.6 5.1-8.6 7.8-13.9 6.3m43.2-22.8c-8-2.2-11.3-12-6.4-18.5 5.7-7.5 16.1-6.4 20.5 2 1.3 2.4 1.2 7.7-.2 10.2-2.6 5.2-8.6 7.8-13.9 6.3m-140.6-.5c-8.7-2.4-11.6-13-5.4-19.7 2.5-2.6 4.8-3.6 8.6-3.6 3.9 0 6.3 1.1 8.8 3.8 2.2 2.5 3 4.7 3 8 .1 8-7.3 13.6-15 11.5m70.3-28.9c-8-2.2-11.3-12-6.4-18.5 5.7-7.5 16.1-6.4 20.5 2 1.3 2.4 1.2 7.7-.2 10.2-2.6 5.1-8.5 7.8-13.9 6.3" style="fill:#884717"/></svg>

After

Width:  |  Height:  |  Size: 4.8 KiB

+7 -6
View File
@@ -2,30 +2,32 @@ from __future__ import annotations
import asyncio
import logging
import os
import sys
import uvicorn
from fastapi import FastAPI
from fastapi.middleware.gzip import GZipMiddleware
from src.consts import LOG_LEVEL, VERSION
from src.consts import HOST, LOG_LEVEL, PORT, VERSION
from src.endpoints import health_check, router
from src.middlewares import LogRequest
from src.utils import get_camoufox, logger
from src.owui import router as owui_router
from src.utils import get_browser, logger
logger.info("Using version %s", VERSION)
logger.info("Log level set to %s", logging.getLevelName(LOG_LEVEL))
app = FastAPI(debug=LOG_LEVEL == logging.DEBUG, log_level=LOG_LEVEL)
app.add_middleware(GZipMiddleware)
app.add_middleware(LogRequest)
app.include_router(router=router)
app.include_router(router=owui_router)
async def init():
"""Initialize the application."""
async for browser in get_camoufox():
async for browser in get_browser():
await health_check(browser)
@@ -38,5 +40,4 @@ if __name__ == "__main__":
loop.run_until_complete(init())
logger.info("Initialization complete.")
else:
host = os.getenv("HOST", "0.0.0.0") # noqa: S104
uvicorn.run(app, host=host, port=8191)
uvicorn.run(app, host=HOST, port=PORT)
+14 -13
View File
@@ -2,34 +2,34 @@
[project]
authors = [{ name = "ThePhaseless", email = "kukubaorch@gmail.com" }]
license = { text = "LICENSE" }
requires-python = "<4.0,>=3.12"
requires-python = "==3.14.*"
name = "Byparr"
version = "0.1.0"
description = "API for getting cookies for Cloudflare challenges"
readme = "README.md"
dependencies = [
"camoufox[geoip]==0.4.*",
"fastapi[standard]==0.116.*",
"fastapi[standard]==0.141.*",
"invisible-playwright>=0.6.1",
"playwright==1.63.*",
"playwright-captcha==0.1.*",
"pydantic==2.11.*",
"pydantic==2.*",
"pydantic-settings==2.*",
"trafilatura==2.2.*",
]
urls = { repository = "https://github.com/ThePhaseless/Byparr" }
[dependency-groups]
test = [
"httpx==0.28.*",
"pytest==8.4.*",
"pytest-asyncio==1.1.*",
"pytest-progress==1.3.*",
"httpx2==2.13.*",
"pytest==9.1.*",
"pytest-asyncio==1.4.*",
"pytest-retry==1.7.*",
"pytest-xdist==3.8.*",
"setuptools>=80.9.0",
]
dev = ["deptry==0.23.*", "ruff==0.12.*"]
dev = ["deptry==0.25.*", "ruff==0.16.*"]
[tool.deptry.per_rule_ignores]
DEP002 = ["pyautogui"]
[tool.ruff.lint]
ignore = [
"D203",
@@ -54,7 +54,8 @@ ignore = [
"G004",
"ANN001",
"ANN204",
"ANN206",
"CPY001",
"BLE001",
]
select = ["ALL"]
extend-safe-fixes = ["D415"]
+10
View File
@@ -2,6 +2,16 @@
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": ["config:recommended"],
"forkProcessing": "enabled",
"lockFileMaintenance": {
"enabled": true,
"rebaseWhen": "behind-base-branch",
"branchTopic": "lock-file-maintenance",
"commitMessageAction": "Lock file maintenance",
"schedule": ["before 4am on monday"],
"prBodyDefinitions": {
"Change": "All locks refreshed"
}
},
"packageRules": [
{
"automerge": true,
+117
View File
@@ -0,0 +1,117 @@
import time
from asyncio import sleep
from contextlib import suppress
from playwright.async_api import Error as PlaywrightError
from playwright.async_api import FloatRect, Page
from playwright.async_api import TimeoutError as PlaywrightTimeoutError
from playwright_captcha.solvers.click.cloudflare.utils.detection import (
CF_INTERSTITIAL_INDICATORS_SELECTORS,
detect_cloudflare_challenge,
)
from src.utils import TimeoutTimer, logger
__all__ = [
"CF_INTERSTITIAL_INDICATORS_SELECTORS",
"challenge_present",
"solve_challenge",
]
POLL_INTERVAL = 0.25
CLICK_SETTLE = 1.5
CLICK_COOLDOWN = 4
PROBE_INTERVAL = 0.5
TOKEN_READ_TIMEOUT = 1000
BOX_READ_TIMEOUT = 1000
CHECKBOX_INSET = 25
TURNSTILE_INPUT = 'input[name="cf-turnstile-response"]'
WIDGET_ANCESTOR_DEPTHS = (1, 2, 3, 4)
WIDGET_MIN_WIDTH = 40
WIDGET_MIN_HEIGHT = 20
WIDGET_MAX_HEIGHT = 120
async def challenge_present(page: Page) -> bool:
"""Report whether the Cloudflare interstitial is up."""
return await detect_cloudflare_challenge(page, "interstitial")
async def widget_box(page: Page) -> FloatRect | None:
"""Measure the widget container with locators; running page scripts resets the challenge."""
for depth in WIDGET_ANCESTOR_DEPTHS:
widget = page.locator(f"{TURNSTILE_INPUT} >> xpath=ancestor::div[{depth}]")
with suppress(PlaywrightError, PlaywrightTimeoutError):
if await widget.count() == 0:
continue
box = await widget.first.bounding_box(timeout=BOX_READ_TIMEOUT)
if (
box
and box["width"] > WIDGET_MIN_WIDTH
and WIDGET_MIN_HEIGHT < box["height"] < WIDGET_MAX_HEIGHT
):
return box
return None
async def click_checkbox(page: Page) -> bool:
"""Click the checkbox through its container, leaving its closed shadow root alone."""
box = await widget_box(page)
if box is None:
return False
await page.mouse.move(box["x"] + CHECKBOX_INSET, box["y"] + box["height"] / 2)
try:
await page.mouse.down()
finally:
await page.mouse.up()
return True
async def checkbox_already_answered(page: Page) -> bool:
"""Report whether Turnstile has already filled in its response token."""
token = page.locator(TURNSTILE_INPUT)
with suppress(PlaywrightError, PlaywrightTimeoutError):
if await token.count() > 0:
return bool(await token.first.input_value(timeout=TOKEN_READ_TIMEOUT))
return False
async def challenge_is_gone(page: Page) -> bool:
"""Confirm the interstitial is really gone and not just between navigations."""
if await challenge_present(page):
return False
await sleep(POLL_INTERVAL)
return not await challenge_present(page)
async def solve_challenge(page: Page, timer: TimeoutTimer) -> None:
"""Wait out the interstitial, clicking its checkbox whenever one is offered."""
logger.info("Challenge detected, waiting for it to clear...")
clicks = 0
next_click = 0.0
while True:
if await challenge_is_gone(page):
logger.debug("Challenge cleared.")
if clicks:
await sleep(min(CLICK_SETTLE, timer.remaining()))
return
if time.perf_counter() >= next_click:
landed = False
with suppress(PlaywrightError, PlaywrightTimeoutError):
landed = not await checkbox_already_answered(
page
) and await click_checkbox(page)
if landed:
clicks += 1
logger.info("Clicked the challenge checkbox (attempt %d).", clicks)
next_click = time.perf_counter() + (
CLICK_COOLDOWN if landed else PROBE_INTERVAL
)
if timer.remaining() <= 0:
break
await sleep(POLL_INTERVAL)
message = "Challenge still present when the request budget ran out"
raise TimeoutError(message)
+35 -23
View File
@@ -1,29 +1,41 @@
import logging
import os
from pathlib import Path
from playwright_captcha import CaptchaType
from playwright_captcha.utils.camoufox_add_init_script.add_init_script import (
get_addon_path,
)
LOG_LEVEL = logging.getLevelNamesMapping()[os.getenv("LOG_LEVEL", "INFO").upper()]
VERSION = os.getenv("VERSION", "unknown").removeprefix("v")
ADDON_PATH = str(Path(get_addon_path()).absolute())
MAX_ATTEMPTS = 2**10
from pydantic_settings import BaseSettings, SettingsConfigDict
PROXY_SERVER = os.getenv("PROXY_SERVER")
PROXY_USERNAME = os.getenv("PROXY_USERNAME")
PROXY_PASSWORD = os.getenv("PROXY_PASSWORD")
class Settings(BaseSettings):
model_config = SettingsConfigDict(env_file=".env", extra="ignore")
CHALLENGE_TITLES_MAP: dict[CaptchaType, list[str]] = {
# Cloudflare
CaptchaType.CLOUDFLARE_INTERSTITIAL: ["Just a moment..."],
}
log_level: str = "INFO"
version: str = "unknown"
CHALLENGE_TITLES = [
title for titles in CHALLENGE_TITLES_MAP.values() for title in titles
]
proxy_server: str | None = None
proxy_username: str | None = None
proxy_password: str | None = None
host: str = "0.0.0.0" # noqa: S104
port: int = 8191
block_media: bool = False
return_only_cookies: bool = False
owui_api_key: str | None = None
browser_locale: str | None = None
settings = Settings()
LOG_LEVEL = logging.getLevelNamesMapping()[settings.log_level.upper()]
VERSION = settings.version.removeprefix("v")
PROXY_SERVER = settings.proxy_server
PROXY_USERNAME = settings.proxy_username
PROXY_PASSWORD = settings.proxy_password
HOST = settings.host
PORT = settings.port
BLOCK_MEDIA = settings.block_media
RETURN_ONLY_COOKIES = settings.return_only_cookies
OWUI_API_KEY = settings.owui_api_key
BROWSER_LOCALE = settings.browser_locale
+42
View File
@@ -0,0 +1,42 @@
import base64
from playwright.async_api import Page
from src.models import LinkRequest
from src.utils import logger
async def build_response_content(
page: Page,
request: LinkRequest,
page_request: object,
*,
challenge_detected: bool,
page_html: str | None,
) -> tuple[str, str]:
"""Build (content_type, response_content) from the settled page."""
if request.return_only_cookies:
return "text/html", ""
if page_request and page_request.headers.get("content-type", "").startswith(
"application/pdf"
):
return await fetch_pdf_content(page)
response_content = (
page_html
if page_html is not None and not challenge_detected
else await page.content()
)
return "text/html", response_content
async def fetch_pdf_content(page: Page) -> tuple[str, str]:
"""Fetch raw PDF bytes as base64, falling back to viewer HTML on failure."""
try:
fetch_response = await page.request.fetch(page.url)
response_content = base64.b64encode(await fetch_response.body()).decode("ascii")
except Exception:
logger.exception("Failed to fetch PDF bytes, falling back to viewer HTML")
return "text/html", await page.content()
return "application/pdf", response_content
+92 -35
View File
@@ -1,29 +1,35 @@
import time
import warnings
from asyncio import wait_for
from http import HTTPStatus
from typing import Annotated
from fastapi import APIRouter, Depends, HTTPException
from fastapi.responses import RedirectResponse
from httpx import TimeoutException
from playwright_captcha import CaptchaType
from playwright.async_api import Error as PlaywrightError
from playwright.async_api import TimeoutError as PlaywrightTimeoutError
from src.consts import CHALLENGE_TITLES
from src.challenge import challenge_present, solve_challenge
from src.content import build_response_content
from src.models import (
HealthcheckResponse,
LinkRequest,
LinkResponse,
Solution,
)
from src.utils import CamoufoxDepType, get_camoufox, logger
from src.utils import (
BrowserDepClass,
TimeoutTimer,
get_browser,
logger,
remaining_ms,
)
warnings.filterwarnings("ignore", category=SyntaxWarning)
router = APIRouter()
CamoufoxDep = Annotated[CamoufoxDepType, Depends(get_camoufox)]
BrowserDep = Annotated[BrowserDepClass, Depends(get_browser)]
@router.get("/", include_in_schema=False)
@@ -34,7 +40,7 @@ def read_root():
@router.get("/health")
async def health_check(sb: CamoufoxDep):
async def health_check(sb: BrowserDep):
"""Health check endpoint."""
health_check_request = await read_item(
LinkRequest.model_construct(url="https://google.com"),
@@ -51,48 +57,99 @@ async def health_check(sb: CamoufoxDep):
@router.post("/v1")
async def read_item(request: LinkRequest, dep: CamoufoxDep) -> LinkResponse:
async def read_item(request: LinkRequest, dep: BrowserDep) -> LinkResponse:
"""Handle POST requests."""
start_time = int(time.time() * 1000)
timer = TimeoutTimer(duration=request.max_timeout)
request.url = request.url.replace('"', "").strip()
page_request = await dep.page.goto(request.url)
await dep.page.wait_for_load_state(state="domcontentloaded")
await dep.page.wait_for_load_state("networkidle")
if await dep.page.title() in CHALLENGE_TITLES:
logger.info("Challenge detected, attempting to solve...")
# Solve the captcha
remaining_timeout = (
request.max_timeout - (int(time.time()) * 1000 - start_time) / 1000
await setup_routes(request, dep)
try:
challenge_detected, page_html, page_request = await _navigate_and_solve(
dep, request, timer
)
logger.debug(
"Remaining timeout for solving the challenge: %d ms", remaining_timeout
)
try:
await wait_for(
dep.solver.solve_captcha( # pyright: ignore[reportUnknownMemberType,reportUnknownArgumentType]
captcha_container=dep.page,
captcha_type=CaptchaType.CLOUDFLARE_INTERSTITIAL,
),
timeout=remaining_timeout,
)
except TimeoutException as e:
logger.error("Failed to solve challenge: %s", e)
return LinkResponse.invalid(url=request.url)
logger.debug("Challenge solved successfully.")
except (TimeoutError, PlaywrightTimeoutError) as e:
logger.error("Timed out while loading the page or solving the challenge")
raise HTTPException(
status_code=408,
detail="Timed out while loading the page or solving the challenge",
) from e
except PlaywrightError as e:
logger.error("Could not reach the target: %s", e)
raise HTTPException(
status_code=502,
detail=f"Could not reach the target: {e}",
) from e
cookies = await dep.context.cookies()
content_type, response_content = await build_response_content(
dep.page,
request,
page_request,
challenge_detected=challenge_detected,
page_html=page_html,
)
user_agent = (
page_request.request.headers.get("user-agent") or "" if page_request else ""
)
return LinkResponse(
message="Success",
solution=Solution(
user_agent=await dep.page.evaluate("navigator.userAgent"),
user_agent=user_agent,
url=dep.page.url,
status=page_request.status if page_request else HTTPStatus.OK,
status=HTTPStatus.OK,
cookies=cookies,
headers=page_request.headers if page_request else {},
response=await dep.page.content(),
response=response_content,
content_type=content_type,
),
start_timestamp=start_time,
)
async def setup_routes(request: LinkRequest, dep: BrowserDep) -> None:
"""Install request routes for media blocking."""
if request.block_media:
async def block_media_route(route) -> None:
if route.request.resource_type in ("image", "media", "font"):
await route.abort()
else:
await route.continue_()
await dep.page.route("**/*", block_media_route)
async def _navigate_and_solve(
dep: BrowserDep,
request: LinkRequest,
timer: TimeoutTimer,
) -> tuple[bool, str | None, object]:
"""Navigate to the URL, then solve a challenge or wait for network idle."""
page_html: str | None = None
page_request = await dep.page.goto(request.url, timeout=remaining_ms(timer))
await dep.page.wait_for_load_state(
state="domcontentloaded", timeout=remaining_ms(timer)
)
if not await challenge_present(dep.page):
page_html = await dep.page.content()
await _wait_for_networkidle(dep, timer)
return False, page_html, page_request
await solve_challenge(dep.page, timer)
await _wait_for_networkidle(dep, timer)
return True, page_html, page_request
async def _wait_for_networkidle(dep: BrowserDep, timer: TimeoutTimer) -> None:
"""Wait for network idle, tolerating post-DOM-load stalls."""
try:
await dep.page.wait_for_load_state("networkidle", timeout=remaining_ms(timer))
except PlaywrightTimeoutError:
logger.info(
"networkidle timed out after domcontentloaded; continuing with loaded page"
)
+1 -1
View File
@@ -25,6 +25,6 @@ class LogRequest(BaseHTTPMiddleware):
if response.status_code == HTTPStatus.OK:
logger.info(f"Done {request_body.url} in {process_time:.2f}s")
else:
logger.info(f"Failed {request_body.url} in {process_time:.2f}s")
logger.warning(f"Failed {request_body.url} in {process_time:.2f}s")
return response
+32 -4
View File
@@ -5,13 +5,17 @@ from http.client import INTERNAL_SERVER_ERROR
from typing import Any
from playwright.sync_api import Cookie
from pydantic import BaseModel, Field
from pydantic import BaseModel, Field, field_validator
from pydantic.alias_generators import to_camel
from src import consts
MS_PER_SECOND = 1000
class LinkRequest(BaseModel):
model_config = {"populate_by_name": True}
cmd: str = Field(
default="request.get",
description="Type of request, currently only supports GET requests. This string is purely for compatibility with FlareSolverr.",
@@ -19,13 +23,36 @@ class LinkRequest(BaseModel):
url: str = Field(pattern=r"^https?://", default="https://")
max_timeout: int = Field(
default=60,
description="Maximum timeout in seconds for resolving the anti-bot challenge.",
alias="maxTimeout",
description=(
"Maximum timeout for resolving the anti-bot challenge. Values below 1000 "
"are treated as seconds; values of 1000 or more as milliseconds, matching "
"FlareSolverr's maxTimeout parameter."
),
)
block_media: bool = Field(
default=consts.BLOCK_MEDIA,
alias="blockMedia",
description="Block image, media, and font resources from loading.",
)
return_only_cookies: bool = Field(
default=consts.RETURN_ONLY_COOKIES,
alias="returnOnlyCookies",
description="Return only cookies, skip the page HTML content in the response.",
)
@field_validator("max_timeout")
@classmethod
def normalize_max_timeout(cls, value: int) -> int:
"""Normalize FlareSolverr-style millisecond values to seconds."""
if value >= MS_PER_SECOND:
return value // MS_PER_SECOND
return value
class HealthcheckResponse(BaseModel):
model_config = {"alias_generator": to_camel, "populate_by_name": True}
msg: str = "Byparr is ready!"
msg: str = "Byparr is working!"
version: str = consts.VERSION
user_agent: str
@@ -38,6 +65,7 @@ class Solution(BaseModel):
user_agent: str = ""
headers: dict[str, Any] = {}
response: str = ""
content_type: str = Field(default="text/html", alias="contentType")
class LinkResponse(BaseModel):
@@ -50,7 +78,7 @@ class LinkResponse(BaseModel):
version: str = consts.VERSION
@classmethod
def invalid(cls, url: str):
def invalid(cls, url: str) -> LinkResponse:
"""
Return an invalid LinkResponse with default error values.
+76
View File
@@ -0,0 +1,76 @@
"""Open WebUI external web loader endpoint: POST /load."""
from __future__ import annotations
from hmac import compare_digest
from typing import Annotated
import trafilatura
from fastapi import APIRouter, Depends, Header, HTTPException
from playwright.async_api import Page
from playwright.async_api import TimeoutError as PlaywrightTimeoutError
from pydantic import BaseModel
from src.consts import OWUI_API_KEY
from src.utils import BrowserDepClass, get_browser, logger
router = APIRouter(tags=["Open WebUI"])
BrowserDep = Annotated[BrowserDepClass, Depends(get_browser)]
class LoadRequest(BaseModel):
urls: list[str]
class LoadResult(BaseModel):
page_content: str
metadata: dict[str, str]
def require_auth(authorization: Annotated[str | None, Header()] = None) -> None:
"""Enforce a bearer token on /load when OWUI_API_KEY is set."""
if not OWUI_API_KEY:
return
if authorization is None or not compare_digest(
authorization.encode(), f"Bearer {OWUI_API_KEY}".encode()
):
raise HTTPException(status_code=401, detail="Unauthorized")
async def _extract_content(page: Page) -> str:
"""Return the page's main article text, falling back to visible text."""
article = trafilatura.extract(await page.content())
if article:
return article
result = await page.locator("body").inner_text()
return "\n".join(line.strip() for line in result.splitlines() if line.strip())
@router.post("/load", response_model=list[LoadResult])
async def load_urls(
request: LoadRequest,
_auth: Annotated[None, Depends(require_auth)],
dep: BrowserDep,
) -> list[LoadResult]:
"""
Fetch URLs through the anti-bot browser and return their text content.
Each URL is fetched sequentially; a failing URL yields empty
page_content so Open WebUI's RAG pipeline degrades gracefully.
"""
results: list[LoadResult] = []
for url in request.urls:
try:
await dep.page.goto(url, timeout=60_000)
await dep.page.wait_for_load_state("domcontentloaded", timeout=30_000)
try:
await dep.page.wait_for_load_state("networkidle", timeout=15_000)
except PlaywrightTimeoutError:
logger.debug("networkidle timed out for %s; extracting anyway", url)
content = await _extract_content(dep.page)
except Exception as exc:
logger.warning("Failed to load %s: %s", url, exc)
content = ""
results.append(LoadResult(page_content=content, metadata={"source": url}))
return results
+76 -36
View File
@@ -1,26 +1,28 @@
import logging
import time
from collections.abc import AsyncGenerator
from typing import NamedTuple, cast
from typing import Annotated, NamedTuple, cast
from camoufox import AsyncCamoufox
from fastapi import Header
from invisible_playwright.async_api import InvisiblePlaywright
from playwright.async_api import Browser, BrowserContext, Page
from playwright_captcha import (
ClickSolver,
FrameworkType,
)
from pydantic import BaseModel, Field
from src.consts import (
ADDON_PATH,
BROWSER_LOCALE,
LOG_LEVEL,
MAX_ATTEMPTS,
PROXY_PASSWORD,
PROXY_SERVER,
PROXY_USERNAME,
)
solver_logger = logging.getLogger("playwright_captcha.solvers")
solver_logger = logging.getLogger("playwright_captcha")
solver_logger.handlers.clear()
solver_logger.handlers.append(logging.NullHandler())
if LOG_LEVEL == logging.DEBUG:
solver_logger.addHandler(logging.StreamHandler())
solver_logger.setLevel(LOG_LEVEL)
else:
solver_logger.handlers.append(logging.NullHandler())
logger = logging.getLogger("uvicorn.error")
logger.setLevel(LOG_LEVEL)
@@ -28,44 +30,82 @@ if len(logger.handlers) == 0:
logger.addHandler(logging.StreamHandler())
class CamoufoxDepType(NamedTuple):
class TimeoutTimer(BaseModel):
duration: int # in seconds
start_time: float = Field(default_factory=time.perf_counter)
def remaining(self) -> float:
"""Get remaining time in seconds."""
return max(0, self.duration - (time.perf_counter() - self.start_time))
MIN_WAIT_MS = 1.0
def remaining_ms(timer: TimeoutTimer) -> float:
"""Milliseconds left, never 0 - Playwright reads that as no timeout at all."""
return max(MIN_WAIT_MS, timer.remaining() * 1000)
class BrowserDepClass(NamedTuple):
page: Page
solver: ClickSolver
context: BrowserContext
async def get_camoufox() -> AsyncGenerator[CamoufoxDepType, None]:
"""Get Camoufox instance."""
proxy_config = (
{
async def get_browser(
x_proxy_server: Annotated[
str | None,
Header(
alias="X-Proxy-Server",
description="Override proxy server for this request in protocol://host:port format.",
),
] = None,
x_proxy_username: Annotated[
str | None,
Header(
alias="X-Proxy-Username",
),
] = None,
x_proxy_password: Annotated[
str | None,
Header(
alias="X-Proxy-Password",
),
] = None,
) -> AsyncGenerator[BrowserDepClass]:
"""Get InvisiblePlaywright browser instance."""
header_server = x_proxy_server
header_username = x_proxy_username
header_password = x_proxy_password
proxy_config = None
if header_server:
proxy_config = {
"server": header_server,
"username": header_username,
"password": header_password,
}
elif PROXY_SERVER:
proxy_config = {
"server": PROXY_SERVER,
"username": PROXY_USERNAME,
"password": PROXY_PASSWORD,
}
if PROXY_SERVER
else None
)
async with AsyncCamoufox(
main_world_eval=True,
addons=[ADDON_PATH],
geoip=True,
proxy=proxy_config,
locale="en-US",
async with InvisiblePlaywright(
headless=True,
proxy=proxy_config,
humanize=True,
i_know_what_im_doing=True,
config={"forceScopeAccess": True}, # add this when creating Camoufox instance
disable_coop=True, # add this when creating Camoufox instance
locale=BROWSER_LOCALE or "auto",
extra_prefs={
"devtools.jsonview.enabled": False,
"browser.tabs.remote.useCrossOriginOpenerPolicy": False,
"browser.tabs.remote.useCrossOriginEmbedderPolicy": False,
},
) as browser_raw:
# Cast to Browser since AsyncCamoufox always returns a Browser, not BrowserContext
# InvisiblePlaywright yields a Browser instance
browser = cast("Browser", browser_raw)
context = await browser.new_context()
page = await context.new_page()
async with ClickSolver(
framework=FrameworkType.CAMOUFOX,
page=page,
max_attempts=MAX_ATTEMPTS,
attempt_delay=1,
) as solver:
yield CamoufoxDepType(page, solver, context)
yield BrowserDepClass(page, context)
+265 -3
View File
@@ -1,12 +1,20 @@
import base64
from http import HTTPStatus
from json import JSONDecodeError
from unittest.mock import AsyncMock, MagicMock
import httpx
import httpx2
import pytest
from fastapi import HTTPException
from playwright.async_api import Error as PlaywrightError
from playwright.async_api import TimeoutError as PlaywrightTimeoutError
from starlette.testclient import TestClient
from main import app
from src.challenge import CF_INTERSTITIAL_INDICATORS_SELECTORS
from src.endpoints import read_item
from src.models import LinkRequest
from src.utils import BrowserDepClass, TimeoutTimer, remaining_ms
client = TestClient(app)
@@ -27,7 +35,7 @@ def test_bypass(website: str):
This test is skipped if the website is not reachable or does not have cloudflare/DDOS-GUARD.
"""
test_request = httpx.get(
test_request = httpx2.get(
website,
)
if (
@@ -44,10 +52,44 @@ def test_bypass(website: str):
response = client.post(
"/v1",
json=LinkRequest.model_construct(url=website, cmd="request.get").model_dump(),
json=LinkRequest.model_construct(
url=website, cmd="request.get", max_timeout=60
).model_dump(),
)
assert response.status_code == HTTPStatus.OK
solution = response.json()["solution"]
assert "_cf_chl_opt" not in solution["response"]
assert "__cf_chl" not in solution["url"]
def test_json_api():
"""
JSON APIs must return 200, not crash on the UA evaluate.
Firefox renders application/json in a built-in viewer whose CSP blocks
Playwright's eval-based evaluate() (issue #394). The browser must be
launched with the viewer disabled so /v1 works and returns the raw JSON.
"""
url = "https://api.ipify.org?format=json"
test_request = httpx2.get(url)
if test_request.status_code >= HTTPStatus.INTERNAL_SERVER_ERROR:
pytest.skip(
f"Skipping JSON API test - upstream error ({test_request.status_code})"
)
response = client.post(
"/v1",
json=LinkRequest.model_construct(url=url, cmd="request.get").model_dump(),
)
if response.status_code == HTTPStatus.REQUEST_TIMEOUT:
pytest.skip("Skipping JSON API test - timed out (upstream issue)")
assert response.status_code == HTTPStatus.OK
solution = response.json()["solution"]
assert solution["userAgent"]
assert '"ip"' in solution["response"]
def test_health_check():
@@ -59,3 +101,223 @@ def test_health_check():
"""
response = client.get("/health")
assert response.status_code == HTTPStatus.OK
def test_pdf_handling():
"""Tests that PDF URLs return the raw PDF bytes, not the Firefox viewer HTML."""
pdf_url = "https://mondaymandala.com/wp-content/uploads/Mickey-And-Minnie-Mouse-Holding-An-Easter-Egg-Basket-Coloring-Page-For-Kids.pdf"
response = client.post(
"/v1",
json=LinkRequest.model_construct(url=pdf_url, cmd="request.get").model_dump(),
)
if response.status_code == HTTPStatus.REQUEST_TIMEOUT:
pytest.skip("Skipping PDF test - timed out (upstream issue)")
assert response.status_code == HTTPStatus.OK
solution = response.json()["solution"]
if solution.get("contentType") != "application/pdf":
pytest.skip(
"Skipping PDF test - PDF bytes could not be fetched (upstream issue)"
)
assert solution["response"] # non-empty base64
decoded = base64.b64decode(solution["response"])
assert decoded[:5] == b"%PDF-"
@pytest.mark.parametrize(
("payload", "expected"),
[
({"max_timeout": 60}, 60), # native API: seconds
({"maxTimeout": 60}, 60), # FlareSolverr alias, seconds-range value
({"maxTimeout": 60000}, 60), # FlareSolverr alias: milliseconds
({"maxTimeout": 55000}, 55),
({"maxTimeout": 1000}, 1),
({}, 60), # default
],
)
def test_max_timeout_normalization(payload: dict, expected: int):
"""MaxTimeout must accept FlareSolverr's milliseconds while keeping seconds."""
request = LinkRequest(url="https://example.com", **payload)
assert request.max_timeout == expected
def fake_dep(
*,
fail_states: set[str] | None = None,
challenged: bool = False,
marker_counts: list[int] | None = None,
widget_box: dict[str, float] | None = None,
user_agent: str | None = "UnitTestBrowser/1.0",
) -> BrowserDepClass:
"""Build a browser dependency pair backed by mocks."""
page = AsyncMock()
page.url = "https://example.test/login"
page.goto.return_value = MagicMock(
status=HTTPStatus.OK,
headers={"content-type": "text/html"},
request=MagicMock(headers={"user-agent": user_agent} if user_agent else {}),
)
page.title.return_value = "Login"
page.content.return_value = "<html><title>Login</title></html>"
remaining = list(marker_counts or [])
def count_for(selector: str) -> int:
"""Answer the marker check from the script, else from `challenged`."""
if selector not in CF_INTERSTITIAL_INDICATORS_SELECTORS or not remaining:
return 1 if challenged else 0
return remaining.pop(0) if len(remaining) > 1 else remaining[0]
def locator(selector: str) -> MagicMock:
handle = MagicMock()
handle.count = AsyncMock(side_effect=lambda: count_for(selector))
handle.first.bounding_box = AsyncMock(return_value=widget_box)
handle.first.input_value = AsyncMock(return_value="")
return handle
page.locator = MagicMock(side_effect=locator)
def wait_for_load_state(state: str, **_kwargs: object) -> None:
"""Fail the wait when asked for a configured state."""
if state in (fail_states or set()):
message = "load state wait timed out"
raise PlaywrightTimeoutError(message)
page.wait_for_load_state.side_effect = wait_for_load_state
context = AsyncMock()
context.cookies.return_value = []
return BrowserDepClass(page=page, context=context)
@pytest.mark.asyncio
async def test_networkidle_timeout_after_domcontentloaded_returns_content():
"""Pages that never go idle after DOM load must still return their content."""
dep = fake_dep(fail_states={"networkidle"})
response = await read_item(
LinkRequest(url="https://example.test/login"),
dep,
)
assert response.status == "ok"
assert response.solution.response == "<html><title>Login</title></html>"
@pytest.mark.asyncio
async def test_domcontentloaded_timeout_returns_408():
"""Fatal timeouts during initial page load still return a controlled 408."""
with pytest.raises(HTTPException) as exc:
await read_item(
LinkRequest(url="https://example.test/login"),
fake_dep(fail_states={"domcontentloaded"}),
)
assert exc.value.status_code == HTTPStatus.REQUEST_TIMEOUT
@pytest.mark.asyncio
async def test_unreachable_host_is_a_502_not_a_500():
"""An upstream we cannot reach is a gateway failure, never a Byparr crash."""
dep = fake_dep()
dep.page.goto.side_effect = PlaywrightError("Page.goto: NS_ERROR_UNKNOWN_HOST")
with pytest.raises(HTTPException) as exc:
await read_item(LinkRequest(url="https://nope.invalid/"), dep)
assert exc.value.status_code == HTTPStatus.BAD_GATEWAY
@pytest.mark.asyncio
async def test_status_is_always_ok_like_flaresolverr():
"""FlareSolverr hardcodes 200 because Selenium cannot report the real code."""
dep = fake_dep()
dep.page.goto.return_value = MagicMock(
status=HTTPStatus.FORBIDDEN,
headers={"content-type": "text/html"},
request=MagicMock(headers={"user-agent": "UnitTestBrowser/1.0"}),
)
response = await read_item(LinkRequest(url="https://example.test/login"), dep)
assert response.solution.status == HTTPStatus.OK
def test_exhausted_budget_never_disables_playwright_timeouts():
"""Playwright reads timeout=0 as no timeout at all, so the floor must hold."""
spent = TimeoutTimer(duration=0)
assert spent.remaining() == 0
assert remaining_ms(spent) > 0
@pytest.mark.asyncio
async def test_missing_user_agent_header_is_not_a_500():
"""A request without a user-agent header degrades to empty, never a 500 (#394)."""
response = await read_item(
LinkRequest(url="https://example.test/login"),
fake_dep(user_agent=None),
)
assert response.status == "ok"
assert response.solution.user_agent == ""
@pytest.mark.asyncio
async def test_checkbox_is_clicked_while_the_challenge_is_up():
"""A measurable widget gets a humanised press, not a raw synthetic click."""
dep = fake_dep(
challenged=True,
marker_counts=[1, 1, 0],
widget_box={"x": 100.0, "y": 200.0, "width": 300.0, "height": 60.0},
)
response = await read_item(
LinkRequest(url="https://example.test/login", max_timeout=5), dep
)
assert response.status == "ok"
dep.page.mouse.move.assert_awaited_once_with(125.0, 230.0)
dep.page.mouse.down.assert_awaited_once()
dep.page.mouse.up.assert_awaited_once()
@pytest.mark.asyncio
async def test_challenge_that_clears_on_its_own_is_never_clicked():
"""A challenge is over when its markup goes, and until then we keep our hands off."""
dep = fake_dep(
challenged=True,
marker_counts=[1, 0],
widget_box={"x": 100.0, "y": 200.0, "width": 300.0, "height": 60.0},
)
response = await read_item(
LinkRequest(url="https://example.test/login", max_timeout=5), dep
)
assert response.status == "ok"
dep.page.mouse.down.assert_not_awaited()
@pytest.mark.asyncio
async def test_challenge_that_never_clears_returns_408():
"""A challenge still up when the budget runs out is a timeout, not a 500."""
dep = fake_dep(challenged=True, marker_counts=[1])
with pytest.raises(HTTPException) as exc:
await read_item(
LinkRequest(url="https://example.test/login", max_timeout=2), dep
)
assert exc.value.status_code == HTTPStatus.REQUEST_TIMEOUT
@pytest.mark.asyncio
async def test_marker_vanishing_mid_navigation_is_not_a_solved_challenge():
"""The marker drops out between challenge rounds; one clear read proves nothing."""
dep = fake_dep(challenged=True, marker_counts=[1, 0, 1])
with pytest.raises(HTTPException) as exc:
await read_item(
LinkRequest(url="https://example.test/login", max_timeout=2), dep
)
assert exc.value.status_code == HTTPStatus.REQUEST_TIMEOUT
+115
View File
@@ -0,0 +1,115 @@
from http import HTTPStatus
from unittest.mock import AsyncMock, MagicMock, patch
import pytest
from playwright.async_api import TimeoutError as PlaywrightTimeoutError
from starlette.testclient import TestClient
from main import app
from src.owui import LoadRequest, load_urls
from src.utils import BrowserDepClass
client = TestClient(app)
def test_owui_load_basic():
"""/load returns one result per URL with the expected shape."""
response = client.post("/load", json={"urls": ["https://example.com"]})
assert response.status_code == HTTPStatus.OK
results = response.json()
assert len(results) == 1
assert results[0]["page_content"]
assert results[0]["metadata"] == {"source": "https://example.com"}
def test_owui_load_multiple_urls():
"""/load returns one result per URL, in order."""
urls = ["https://example.com", "https://example.org"]
response = client.post("/load", json={"urls": urls})
assert response.status_code == HTTPStatus.OK
results = response.json()
assert [r["metadata"]["source"] for r in results] == urls
def test_owui_load_invalid_url_graceful():
"""Unreachable URLs yield empty page_content instead of an error."""
response = client.post(
"/load", json={"urls": ["https://this-domain-does-not-exist-12345.invalid"]}
)
assert response.status_code == HTTPStatus.OK
results = response.json()
assert len(results) == 1
assert results[0]["page_content"] == ""
@pytest.mark.parametrize(
"headers",
[None, {"Authorization": "Bearer wrong-key"}],
)
def test_owui_load_rejects_missing_or_wrong_key(headers):
"""/load returns 401 without a valid bearer token when a key is set."""
with patch("src.owui.OWUI_API_KEY", "test-secret-key"):
response = client.post(
"/load", json={"urls": ["https://example.com"]}, headers=headers
)
assert response.status_code == HTTPStatus.UNAUTHORIZED
def test_owui_load_accepts_valid_key():
"""/load succeeds with the configured bearer token."""
with patch("src.owui.OWUI_API_KEY", "test-secret-key"):
response = client.post(
"/load",
json={"urls": ["https://example.com"]},
headers={"Authorization": "Bearer test-secret-key"},
)
assert response.status_code == HTTPStatus.OK
ARTICLE_HTML = """<html><head><title>Test</title></head><body>
<article><h1>Example Title</h1><p>This is the main article body with enough words for
trafilatura to consider it real content rather than boilerplate.</p></article>
<nav><a href="/x">nav link</a></nav>
</body></html>"""
def fake_dep(*, html: str = ARTICLE_HTML) -> BrowserDepClass:
"""Browser dependency whose page loads HTML but never reaches networkidle."""
page = AsyncMock()
page.goto.return_value = MagicMock()
page.content.return_value = html
page.locator = MagicMock()
page.locator.return_value.inner_text = AsyncMock(
return_value="line one\n\nline two"
)
def wait_for_load_state(state: str, **_kwargs: object) -> None:
if state == "networkidle":
message = "load state wait timed out"
raise PlaywrightTimeoutError(message)
page.wait_for_load_state.side_effect = wait_for_load_state
return BrowserDepClass(page=page, context=AsyncMock())
@pytest.mark.asyncio
async def test_networkidle_timeout_still_extracts_content():
"""A page that never reaches networkidle still yields its article text."""
results = await load_urls(
LoadRequest(urls=["https://example.test"]), None, fake_dep()
)
assert results[0].page_content == (
"Example TitleThis is the main article body with enough words for "
"trafilatura to consider it real content rather than boilerplate."
)
@pytest.mark.asyncio
async def test_extraction_falls_back_to_innertext():
"""Pages trafilatura cannot score fall back to the rendered innerText."""
results = await load_urls(
LoadRequest(urls=["https://example.test"]),
None,
fake_dep(html="<html><body></body></html>"),
)
assert results[0].page_content == "line one\nline two"
Generated
+910 -1094
View File
File diff suppressed because it is too large Load Diff