Tweak comments for MDPI challenge workaround

This commit is contained in:
Dan Stillman 2026-10-06 10:49:49 -04:00
parent 09c3c8cd3d
commit 1e2cc6820a
2 changed files with 3 additions and 3 deletions

View file

@ -2217,8 +2217,8 @@ Zotero.Attachments = new function () {
let refreshURL = Zotero.HTTP.getHTMLMetaRefreshURL(doc, responseURL);
if (refreshURL) {
// If the refresh points at a known bot-challenge host, the
// interstitial runs JS that a plain request can't satisfy. Run
// it once in a hidden browser to bank the resulting cookies,
// interstitial runs JS that a plain request can handle. Run
// it once in a hidden browser to store the resulting cookies,
// then retry the page over the normal path.
let challengeEntry = Zotero.BrowserRequest.getEntryForURL(refreshURL);
if (challengeEntry && !clearedChallenges.has(responseURL)) {

View file

@ -61,7 +61,7 @@ Zotero.BrowserRequest = {
// that computes a proof-of-work and POSTs it to /_sec/verify before
// reloading the page without the token. There's no CAPTCHA to show a
// user -- it's a fully automatic JS handshake -- so a hidden browser
// runs it to completion and banks the resulting cookies, with no
// runs it to completion and stores the resulting cookies, with no
// success cookie or viewer escalation.
match: '://www.mdpi.com',
captchaLocator: null,