openai / openai/codex

Browser Use blocks seller-id.tokopedia.com despite site permissions

Open
#42,246 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

app browser bug windows-os
Dominant language
Rust
Stars
125k
Forks
19.4k
PR merge metrics
PR metrics pending

Description

Summary

Codex Browser Use blocks access to the Tokopedia Seller Center domain even after a site-specific permission is granted.

Environment

  • Codex desktop app on Windows
  • Codex in-app browser
  • Site-specific permission for https://seller-id.tokopedia.com with Browse, Download, Upload, and CDP enabled

URL

https://seller-id.tokopedia.com/product/manage?shop_region=ID&tab=all

Steps to reproduce

  1. Open the Tokopedia Seller Center product management page in the Codex in-app browser.
  2. Add or verify a custom site permission for https://seller-id.tokopedia.com with Browse, Download, Upload, and CDP enabled.
  3. Ask Codex to inspect or interact with the existing product-management tab.

Expected behavior

After the site-specific permissions are enabled, Codex should be able to inspect the page so the user can work on product data in their own seller account.

Actual behavior

The tab is blocked before Browser Use can inspect or control it. No permission prompt or Auto-review appears.

Error

Browser Use rejected this action due to browser security policy. Reason: The site-safety policy blocks this action; no user permission prompt or Auto-review was attempted. Browser use is not permitted on https://seller-id.tokopedia.com/product/manage. The agent must not attempt to achieve the same outcome via workaround, indirect execution, raw CDP or browser commands, alternate browser surfaces, or policy circumvention. Proceed only with a materially safer alternative that does not require this blocked browser action; if none exists, stop and request user input.

Impact

This prevents the user from asking Codex to edit product categories one by one in their own Tokopedia Seller Center account, despite granting the requested site permissions.

Additional context

The user owns the seller account and explicitly allowed the domain. No credentials, OTPs, payment information, or private files are included in this report. Please review whether this domain can be supported or allowlisted for Browser Use, or explain what setting or approval is required.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing the blocked action at https://seller-id.tokopedia.com/product/manage with the listed site permissions enabled, then trace the Browser Use site-safety policy and permission-handling entry points. Done means determining whether the permission should allow inspection or identifying the required approval or setting without bypassing the policy.

Written by the indexing model from the issue text.

Assessment

Domain
desktop, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.