Fix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flags - #691

Merged
lpcox merged 3 commits into
mainfrom
copilot/fix-browser-navigation-error
Feb 5, 2026
Merged

Fix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flags#691
lpcox merged 3 commits into
mainfrom
copilot/fix-browser-navigation-error

Conversation

CopilotAI commented Feb 5, 2026

Copy link
Copy Markdown
Contributor

Playwright MCP server was failing navigation with ERR_BLOCKED_BY_CLIENT despite container launching successfully. Chromium's sandbox requirements aren't met in Docker containers without explicit bypass flags.

Changes

Added Docker-specific Chromium launch flags to PLAYWRIGHT_LAUNCH_OPTIONS:

  • --no-sandbox - bypass Linux sandbox restrictions
  • --disable-setuid-sandbox - additional sandbox bypass
  • --disable-gpu - disable GPU acceleration (unavailable in headless containers)

Enhanced security warning to explicitly note these flags disable critical browser protections and should only be used in controlled CI environments.

PLAYWRIGHT_LAUNCH_OPTIONS: '{"args": ["--no-sandbox", "--disable-setuid-sandbox", "--disable-gpu", "--disable-blink-features=AutomationControlled", "--disable-web-security", "--disable-features=IsolateOrigins,site-per-process"]}'

Standard pattern for Playwright in Docker per official docs.

Original prompt

This section details on the original issue you should resolve

<issue_title>[mcp-stress-test] Playwright MCP server browser navigation blocked by security policy</issue_title>
<issue_description>## MCP Server Stress Test - Non-Authentication Failure

The nightly stress test detected 1 server with a non-authentication failure.

Test Summary

  • Test Session: stress-test-20260205-030515
  • Test Date: 2026-02-05T03:05:15Z
  • Total Non-Auth Failures: 1

Failed Server

1. playwright - Browser Navigation Error

Container: mcr.microsoft.com/playwright:v1.49.1-noble

Issue Type: Security Policy / Browser Configuration

Status:⚠️ Partial Success (browser launches but navigation blocked)

Error:

Error: page.goto: net::ERR_BLOCKED_BY_CLIENT at (example.com/redacted)
Call log:
- navigating to "(example.com/redacted), waiting until "domcontentloaded"

Analysis:
The Playwright MCP server and browser launch successfully, indicating the container and MCP protocol communication are working correctly. However, navigation attempts are blocked by a client-side security policy (ERR_BLOCKED_BY_CLIENT). This error typically occurs when:

  • An ad blocker or security extension is active in the browser profile
  • Content Security Policy (CSP) blocks the navigation
  • Browser launch args include restrictive security settings

The MCP server itself is functional; this is a browser configuration issue.

Suggested Investigation:

  • Review browser launch options in the Playwright server configuration
  • Disable browser extensions or security add-ons
  • Use headless mode without UI extensions
  • Check for CSP headers or security policies in the browser profile
  • Verify browser args don't include overly restrictive security flags
  • Test with different URLs to isolate the issue

Test Configuration

The test used the following setup:

  • MCP Gateway: Pre-configured via workflow infrastructure
  • Test Method: Sequential server testing with simple tool invocations
  • Playwright Browser: Containerized Playwright v1.49.1

Gateway Performance

No gateway-level issues detected:

  • MCP protocol communication working correctly
  • Container launched successfully
  • Error responses properly formatted
  • No crashes or timeouts

Next Steps

  1. Investigate browser launch configuration
  2. Apply fixes to browser settings
  3. Re-run stress test to verify

Generated by Nightly MCP Stress Test
Test Session: stress-test-20260205-030515

Full Test Results: See workflow run artifacts at /tmp/mcp-stress-results/test_report.md

AI generated by Nightly MCP Server Stress Test

<agent_instructions>Only update the .md file, not the .lock.yml file. </agent_instructions>

Comments on the Issue (you are @copilot in this section)

Custom agent used: agentic-workflows
GitHub Agentic Workflows (gh-aw) - Create, debug, and upgrade AI-powered workflows with intelligent prompt routing


✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

CopilotAIand others added 2 commits February 5, 2026 03:18
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
CopilotAI changed the title [WIP] Fix Playwright MCP server browser navigation error due to security policyFix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flagsFeb 5, 2026
CopilotAI requested a review from lpcoxFebruary 5, 2026 03:20
@lpcox
lpcox marked this pull request as ready for review February 5, 2026 03:23
CopilotAI review requested due to automatic review settings February 5, 2026 03:23
@lpcox
lpcox merged commit 7d92126 into mainFeb 5, 2026
4 checks passed
@lpcox
lpcox deleted the copilot/fix-browser-navigation-error branch February 5, 2026 03:24

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes the Playwright MCP server's browser navigation failure in Docker environments by adding required Chromium sandbox bypass flags and enhanced security documentation.

Changes:

  • Added Docker-specific Chromium launch flags (--no-sandbox, --disable-setuid-sandbox, --disable-gpu) to PLAYWRIGHT_LAUNCH_OPTIONS
  • Enhanced security warning with explicit multi-line documentation about disabled security features
  • Added reference to official Playwright Docker documentation

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[mcp-stress-test] Playwright MCP server browser navigation blocked by security policy

3 participants

@lpcox
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Fix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flags - #691

Merged
lpcox merged 3 commits into
mainfrom
copilot/fix-browser-navigation-error
Feb 5, 2026
Merged

Fix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flags#691
lpcox merged 3 commits into
mainfrom
copilot/fix-browser-navigation-error

Conversation

CopilotAI commented Feb 5, 2026

Copy link
Copy Markdown
Contributor

Playwright MCP server was failing navigation with ERR_BLOCKED_BY_CLIENT despite container launching successfully. Chromium's sandbox requirements aren't met in Docker containers without explicit bypass flags.

Changes

Added Docker-specific Chromium launch flags to PLAYWRIGHT_LAUNCH_OPTIONS:

  • --no-sandbox - bypass Linux sandbox restrictions
  • --disable-setuid-sandbox - additional sandbox bypass
  • --disable-gpu - disable GPU acceleration (unavailable in headless containers)

Enhanced security warning to explicitly note these flags disable critical browser protections and should only be used in controlled CI environments.

PLAYWRIGHT_LAUNCH_OPTIONS: '{"args": ["--no-sandbox", "--disable-setuid-sandbox", "--disable-gpu", "--disable-blink-features=AutomationControlled", "--disable-web-security", "--disable-features=IsolateOrigins,site-per-process"]}'

Standard pattern for Playwright in Docker per official docs.

Original prompt

This section details on the original issue you should resolve

<issue_title>[mcp-stress-test] Playwright MCP server browser navigation blocked by security policy</issue_title>
<issue_description>## MCP Server Stress Test - Non-Authentication Failure

The nightly stress test detected 1 server with a non-authentication failure.

Test Summary

  • Test Session: stress-test-20260205-030515
  • Test Date: 2026-02-05T03:05:15Z
  • Total Non-Auth Failures: 1

Failed Server

1. playwright - Browser Navigation Error

Container: mcr.microsoft.com/playwright:v1.49.1-noble

Issue Type: Security Policy / Browser Configuration

Status:⚠️ Partial Success (browser launches but navigation blocked)

Error:

Error: page.goto: net::ERR_BLOCKED_BY_CLIENT at (example.com/redacted)
Call log:
- navigating to "(example.com/redacted), waiting until "domcontentloaded"

Analysis:
The Playwright MCP server and browser launch successfully, indicating the container and MCP protocol communication are working correctly. However, navigation attempts are blocked by a client-side security policy (ERR_BLOCKED_BY_CLIENT). This error typically occurs when:

  • An ad blocker or security extension is active in the browser profile
  • Content Security Policy (CSP) blocks the navigation
  • Browser launch args include restrictive security settings

The MCP server itself is functional; this is a browser configuration issue.

Suggested Investigation:

  • Review browser launch options in the Playwright server configuration
  • Disable browser extensions or security add-ons
  • Use headless mode without UI extensions
  • Check for CSP headers or security policies in the browser profile
  • Verify browser args don't include overly restrictive security flags
  • Test with different URLs to isolate the issue

Test Configuration

The test used the following setup:

  • MCP Gateway: Pre-configured via workflow infrastructure
  • Test Method: Sequential server testing with simple tool invocations
  • Playwright Browser: Containerized Playwright v1.49.1

Gateway Performance

No gateway-level issues detected:

  • MCP protocol communication working correctly
  • Container launched successfully
  • Error responses properly formatted
  • No crashes or timeouts

Next Steps

  1. Investigate browser launch configuration
  2. Apply fixes to browser settings
  3. Re-run stress test to verify

Generated by Nightly MCP Stress Test
Test Session: stress-test-20260205-030515

Full Test Results: See workflow run artifacts at /tmp/mcp-stress-results/test_report.md

AI generated by Nightly MCP Server Stress Test

<agent_instructions>Only update the .md file, not the .lock.yml file. </agent_instructions>

Comments on the Issue (you are @copilot in this section)

Custom agent used: agentic-workflows
GitHub Agentic Workflows (gh-aw) - Create, debug, and upgrade AI-powered workflows with intelligent prompt routing


✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

CopilotAIand others added 2 commits February 5, 2026 03:18
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
CopilotAI changed the title [WIP] Fix Playwright MCP server browser navigation error due to security policyFix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flagsFeb 5, 2026
CopilotAI requested a review from lpcoxFebruary 5, 2026 03:20
@lpcox
lpcox marked this pull request as ready for review February 5, 2026 03:23
CopilotAI review requested due to automatic review settings February 5, 2026 03:23
@lpcox
lpcox merged commit 7d92126 into mainFeb 5, 2026
4 checks passed
@lpcox
lpcox deleted the copilot/fix-browser-navigation-error branch February 5, 2026 03:24

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes the Playwright MCP server's browser navigation failure in Docker environments by adding required Chromium sandbox bypass flags and enhanced security documentation.

Changes:

  • Added Docker-specific Chromium launch flags (--no-sandbox, --disable-setuid-sandbox, --disable-gpu) to PLAYWRIGHT_LAUNCH_OPTIONS
  • Enhanced security warning with explicit multi-line documentation about disabled security features
  • Added reference to official Playwright Docker documentation

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[mcp-stress-test] Playwright MCP server browser navigation blocked by security policy

3 participants

@lpcox
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flags - #691

Merged
lpcox merged 3 commits into
mainfrom
copilot/fix-browser-navigation-error
Feb 5, 2026
Merged

Fix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flags#691
lpcox merged 3 commits into
mainfrom
copilot/fix-browser-navigation-error

Conversation

CopilotAI commented Feb 5, 2026

Copy link
Copy Markdown
Contributor

Playwright MCP server was failing navigation with ERR_BLOCKED_BY_CLIENT despite container launching successfully. Chromium's sandbox requirements aren't met in Docker containers without explicit bypass flags.

Changes

Added Docker-specific Chromium launch flags to PLAYWRIGHT_LAUNCH_OPTIONS:

  • --no-sandbox - bypass Linux sandbox restrictions
  • --disable-setuid-sandbox - additional sandbox bypass
  • --disable-gpu - disable GPU acceleration (unavailable in headless containers)

Enhanced security warning to explicitly note these flags disable critical browser protections and should only be used in controlled CI environments.

PLAYWRIGHT_LAUNCH_OPTIONS: '{"args": ["--no-sandbox", "--disable-setuid-sandbox", "--disable-gpu", "--disable-blink-features=AutomationControlled", "--disable-web-security", "--disable-features=IsolateOrigins,site-per-process"]}'

Standard pattern for Playwright in Docker per official docs.

Original prompt

This section details on the original issue you should resolve

<issue_title>[mcp-stress-test] Playwright MCP server browser navigation blocked by security policy</issue_title>
<issue_description>## MCP Server Stress Test - Non-Authentication Failure

The nightly stress test detected 1 server with a non-authentication failure.

Test Summary

  • Test Session: stress-test-20260205-030515
  • Test Date: 2026-02-05T03:05:15Z
  • Total Non-Auth Failures: 1

Failed Server

1. playwright - Browser Navigation Error

Container: mcr.microsoft.com/playwright:v1.49.1-noble

Issue Type: Security Policy / Browser Configuration

Status:⚠️ Partial Success (browser launches but navigation blocked)

Error:

Error: page.goto: net::ERR_BLOCKED_BY_CLIENT at (example.com/redacted)
Call log:
- navigating to "(example.com/redacted), waiting until "domcontentloaded"

Analysis:
The Playwright MCP server and browser launch successfully, indicating the container and MCP protocol communication are working correctly. However, navigation attempts are blocked by a client-side security policy (ERR_BLOCKED_BY_CLIENT). This error typically occurs when:

  • An ad blocker or security extension is active in the browser profile
  • Content Security Policy (CSP) blocks the navigation
  • Browser launch args include restrictive security settings

The MCP server itself is functional; this is a browser configuration issue.

Suggested Investigation:

  • Review browser launch options in the Playwright server configuration
  • Disable browser extensions or security add-ons
  • Use headless mode without UI extensions
  • Check for CSP headers or security policies in the browser profile
  • Verify browser args don't include overly restrictive security flags
  • Test with different URLs to isolate the issue

Test Configuration

The test used the following setup:

  • MCP Gateway: Pre-configured via workflow infrastructure
  • Test Method: Sequential server testing with simple tool invocations
  • Playwright Browser: Containerized Playwright v1.49.1

Gateway Performance

No gateway-level issues detected:

  • MCP protocol communication working correctly
  • Container launched successfully
  • Error responses properly formatted
  • No crashes or timeouts

Next Steps

  1. Investigate browser launch configuration
  2. Apply fixes to browser settings
  3. Re-run stress test to verify

Generated by Nightly MCP Stress Test
Test Session: stress-test-20260205-030515

Full Test Results: See workflow run artifacts at /tmp/mcp-stress-results/test_report.md

AI generated by Nightly MCP Server Stress Test

<agent_instructions>Only update the .md file, not the .lock.yml file. </agent_instructions>

Comments on the Issue (you are @copilot in this section)

Custom agent used: agentic-workflows
GitHub Agentic Workflows (gh-aw) - Create, debug, and upgrade AI-powered workflows with intelligent prompt routing


✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

CopilotAIand others added 2 commits February 5, 2026 03:18
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
CopilotAI changed the title [WIP] Fix Playwright MCP server browser navigation error due to security policyFix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flagsFeb 5, 2026
CopilotAI requested a review from lpcoxFebruary 5, 2026 03:20
@lpcox
lpcox marked this pull request as ready for review February 5, 2026 03:23
CopilotAI review requested due to automatic review settings February 5, 2026 03:23
@lpcox
lpcox merged commit 7d92126 into mainFeb 5, 2026
4 checks passed
@lpcox
lpcox deleted the copilot/fix-browser-navigation-error branch February 5, 2026 03:24

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes the Playwright MCP server's browser navigation failure in Docker environments by adding required Chromium sandbox bypass flags and enhanced security documentation.

Changes:

  • Added Docker-specific Chromium launch flags (--no-sandbox, --disable-setuid-sandbox, --disable-gpu) to PLAYWRIGHT_LAUNCH_OPTIONS
  • Enhanced security warning with explicit multi-line documentation about disabled security features
  • Added reference to official Playwright Docker documentation

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[mcp-stress-test] Playwright MCP server browser navigation blocked by security policy

3 participants

@lpcox
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flags - #691

Merged
lpcox merged 3 commits into
mainfrom
copilot/fix-browser-navigation-error
Feb 5, 2026
Merged

Fix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flags#691
lpcox merged 3 commits into
mainfrom
copilot/fix-browser-navigation-error

Conversation

CopilotAI commented Feb 5, 2026

Copy link
Copy Markdown
Contributor

Playwright MCP server was failing navigation with ERR_BLOCKED_BY_CLIENT despite container launching successfully. Chromium's sandbox requirements aren't met in Docker containers without explicit bypass flags.

Changes

Added Docker-specific Chromium launch flags to PLAYWRIGHT_LAUNCH_OPTIONS:

  • --no-sandbox - bypass Linux sandbox restrictions
  • --disable-setuid-sandbox - additional sandbox bypass
  • --disable-gpu - disable GPU acceleration (unavailable in headless containers)

Enhanced security warning to explicitly note these flags disable critical browser protections and should only be used in controlled CI environments.

PLAYWRIGHT_LAUNCH_OPTIONS: '{"args": ["--no-sandbox", "--disable-setuid-sandbox", "--disable-gpu", "--disable-blink-features=AutomationControlled", "--disable-web-security", "--disable-features=IsolateOrigins,site-per-process"]}'

Standard pattern for Playwright in Docker per official docs.

Original prompt

This section details on the original issue you should resolve

<issue_title>[mcp-stress-test] Playwright MCP server browser navigation blocked by security policy</issue_title>
<issue_description>## MCP Server Stress Test - Non-Authentication Failure

The nightly stress test detected 1 server with a non-authentication failure.

Test Summary

  • Test Session: stress-test-20260205-030515
  • Test Date: 2026-02-05T03:05:15Z
  • Total Non-Auth Failures: 1

Failed Server

1. playwright - Browser Navigation Error

Container: mcr.microsoft.com/playwright:v1.49.1-noble

Issue Type: Security Policy / Browser Configuration

Status:⚠️ Partial Success (browser launches but navigation blocked)

Error:

Error: page.goto: net::ERR_BLOCKED_BY_CLIENT at (example.com/redacted)
Call log:
- navigating to "(example.com/redacted), waiting until "domcontentloaded"

Analysis:
The Playwright MCP server and browser launch successfully, indicating the container and MCP protocol communication are working correctly. However, navigation attempts are blocked by a client-side security policy (ERR_BLOCKED_BY_CLIENT). This error typically occurs when:

  • An ad blocker or security extension is active in the browser profile
  • Content Security Policy (CSP) blocks the navigation
  • Browser launch args include restrictive security settings

The MCP server itself is functional; this is a browser configuration issue.

Suggested Investigation:

  • Review browser launch options in the Playwright server configuration
  • Disable browser extensions or security add-ons
  • Use headless mode without UI extensions
  • Check for CSP headers or security policies in the browser profile
  • Verify browser args don't include overly restrictive security flags
  • Test with different URLs to isolate the issue

Test Configuration

The test used the following setup:

  • MCP Gateway: Pre-configured via workflow infrastructure
  • Test Method: Sequential server testing with simple tool invocations
  • Playwright Browser: Containerized Playwright v1.49.1

Gateway Performance

No gateway-level issues detected:

  • MCP protocol communication working correctly
  • Container launched successfully
  • Error responses properly formatted
  • No crashes or timeouts

Next Steps

  1. Investigate browser launch configuration
  2. Apply fixes to browser settings
  3. Re-run stress test to verify

Generated by Nightly MCP Stress Test
Test Session: stress-test-20260205-030515

Full Test Results: See workflow run artifacts at /tmp/mcp-stress-results/test_report.md

AI generated by Nightly MCP Server Stress Test

<agent_instructions>Only update the .md file, not the .lock.yml file. </agent_instructions>

Comments on the Issue (you are @copilot in this section)

Custom agent used: agentic-workflows
GitHub Agentic Workflows (gh-aw) - Create, debug, and upgrade AI-powered workflows with intelligent prompt routing


✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

CopilotAIand others added 2 commits February 5, 2026 03:18
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
CopilotAI changed the title [WIP] Fix Playwright MCP server browser navigation error due to security policyFix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flagsFeb 5, 2026
CopilotAI requested a review from lpcoxFebruary 5, 2026 03:20
@lpcox
lpcox marked this pull request as ready for review February 5, 2026 03:23
CopilotAI review requested due to automatic review settings February 5, 2026 03:23
@lpcox
lpcox merged commit 7d92126 into mainFeb 5, 2026
4 checks passed
@lpcox
lpcox deleted the copilot/fix-browser-navigation-error branch February 5, 2026 03:24

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes the Playwright MCP server's browser navigation failure in Docker environments by adding required Chromium sandbox bypass flags and enhanced security documentation.

Changes:

  • Added Docker-specific Chromium launch flags (--no-sandbox, --disable-setuid-sandbox, --disable-gpu) to PLAYWRIGHT_LAUNCH_OPTIONS
  • Enhanced security warning with explicit multi-line documentation about disabled security features
  • Added reference to official Playwright Docker documentation

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[mcp-stress-test] Playwright MCP server browser navigation blocked by security policy

3 participants

@lpcox
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Fix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flags - #691

Merged
lpcox merged 3 commits into
mainfrom
copilot/fix-browser-navigation-error
Feb 5, 2026
Merged

Fix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flags#691
lpcox merged 3 commits into
mainfrom
copilot/fix-browser-navigation-error

Conversation

CopilotAI commented Feb 5, 2026

Copy link
Copy Markdown
Contributor

Playwright MCP server was failing navigation with ERR_BLOCKED_BY_CLIENT despite container launching successfully. Chromium's sandbox requirements aren't met in Docker containers without explicit bypass flags.

Changes

Added Docker-specific Chromium launch flags to PLAYWRIGHT_LAUNCH_OPTIONS:

  • --no-sandbox - bypass Linux sandbox restrictions
  • --disable-setuid-sandbox - additional sandbox bypass
  • --disable-gpu - disable GPU acceleration (unavailable in headless containers)

Enhanced security warning to explicitly note these flags disable critical browser protections and should only be used in controlled CI environments.

PLAYWRIGHT_LAUNCH_OPTIONS: '{"args": ["--no-sandbox", "--disable-setuid-sandbox", "--disable-gpu", "--disable-blink-features=AutomationControlled", "--disable-web-security", "--disable-features=IsolateOrigins,site-per-process"]}'

Standard pattern for Playwright in Docker per official docs.

Original prompt

This section details on the original issue you should resolve

<issue_title>[mcp-stress-test] Playwright MCP server browser navigation blocked by security policy</issue_title>
<issue_description>## MCP Server Stress Test - Non-Authentication Failure

The nightly stress test detected 1 server with a non-authentication failure.

Test Summary

  • Test Session: stress-test-20260205-030515
  • Test Date: 2026-02-05T03:05:15Z
  • Total Non-Auth Failures: 1

Failed Server

1. playwright - Browser Navigation Error

Container: mcr.microsoft.com/playwright:v1.49.1-noble

Issue Type: Security Policy / Browser Configuration

Status:⚠️ Partial Success (browser launches but navigation blocked)

Error:

Error: page.goto: net::ERR_BLOCKED_BY_CLIENT at (example.com/redacted)
Call log:
- navigating to "(example.com/redacted), waiting until "domcontentloaded"

Analysis:
The Playwright MCP server and browser launch successfully, indicating the container and MCP protocol communication are working correctly. However, navigation attempts are blocked by a client-side security policy (ERR_BLOCKED_BY_CLIENT). This error typically occurs when:

  • An ad blocker or security extension is active in the browser profile
  • Content Security Policy (CSP) blocks the navigation
  • Browser launch args include restrictive security settings

The MCP server itself is functional; this is a browser configuration issue.

Suggested Investigation:

  • Review browser launch options in the Playwright server configuration
  • Disable browser extensions or security add-ons
  • Use headless mode without UI extensions
  • Check for CSP headers or security policies in the browser profile
  • Verify browser args don't include overly restrictive security flags
  • Test with different URLs to isolate the issue

Test Configuration

The test used the following setup:

  • MCP Gateway: Pre-configured via workflow infrastructure
  • Test Method: Sequential server testing with simple tool invocations
  • Playwright Browser: Containerized Playwright v1.49.1

Gateway Performance

No gateway-level issues detected:

  • MCP protocol communication working correctly
  • Container launched successfully
  • Error responses properly formatted
  • No crashes or timeouts

Next Steps

  1. Investigate browser launch configuration
  2. Apply fixes to browser settings
  3. Re-run stress test to verify

Generated by Nightly MCP Stress Test
Test Session: stress-test-20260205-030515

Full Test Results: See workflow run artifacts at /tmp/mcp-stress-results/test_report.md

AI generated by Nightly MCP Server Stress Test

<agent_instructions>Only update the .md file, not the .lock.yml file. </agent_instructions>

Comments on the Issue (you are @copilot in this section)

Custom agent used: agentic-workflows
GitHub Agentic Workflows (gh-aw) - Create, debug, and upgrade AI-powered workflows with intelligent prompt routing


✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

CopilotAIand others added 2 commits February 5, 2026 03:18
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
CopilotAI changed the title [WIP] Fix Playwright MCP server browser navigation error due to security policyFix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flagsFeb 5, 2026
CopilotAI requested a review from lpcoxFebruary 5, 2026 03:20
@lpcox
lpcox marked this pull request as ready for review February 5, 2026 03:23
CopilotAI review requested due to automatic review settings February 5, 2026 03:23
@lpcox
lpcox merged commit 7d92126 into mainFeb 5, 2026
4 checks passed
@lpcox
lpcox deleted the copilot/fix-browser-navigation-error branch February 5, 2026 03:24

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes the Playwright MCP server's browser navigation failure in Docker environments by adding required Chromium sandbox bypass flags and enhanced security documentation.

Changes:

  • Added Docker-specific Chromium launch flags (--no-sandbox, --disable-setuid-sandbox, --disable-gpu) to PLAYWRIGHT_LAUNCH_OPTIONS
  • Enhanced security warning with explicit multi-line documentation about disabled security features
  • Added reference to official Playwright Docker documentation

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[mcp-stress-test] Playwright MCP server browser navigation blocked by security policy

3 participants

@lpcox
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flags - #691

Merged
lpcox merged 3 commits into
mainfrom
copilot/fix-browser-navigation-error
Feb 5, 2026
Merged

Fix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flags#691
lpcox merged 3 commits into
mainfrom
copilot/fix-browser-navigation-error

Conversation

CopilotAI commented Feb 5, 2026

Copy link
Copy Markdown
Contributor

Playwright MCP server was failing navigation with ERR_BLOCKED_BY_CLIENT despite container launching successfully. Chromium's sandbox requirements aren't met in Docker containers without explicit bypass flags.

Changes

Added Docker-specific Chromium launch flags to PLAYWRIGHT_LAUNCH_OPTIONS:

  • --no-sandbox - bypass Linux sandbox restrictions
  • --disable-setuid-sandbox - additional sandbox bypass
  • --disable-gpu - disable GPU acceleration (unavailable in headless containers)

Enhanced security warning to explicitly note these flags disable critical browser protections and should only be used in controlled CI environments.

PLAYWRIGHT_LAUNCH_OPTIONS: '{"args": ["--no-sandbox", "--disable-setuid-sandbox", "--disable-gpu", "--disable-blink-features=AutomationControlled", "--disable-web-security", "--disable-features=IsolateOrigins,site-per-process"]}'

Standard pattern for Playwright in Docker per official docs.

Original prompt

This section details on the original issue you should resolve

<issue_title>[mcp-stress-test] Playwright MCP server browser navigation blocked by security policy</issue_title>
<issue_description>## MCP Server Stress Test - Non-Authentication Failure

The nightly stress test detected 1 server with a non-authentication failure.

Test Summary

  • Test Session: stress-test-20260205-030515
  • Test Date: 2026-02-05T03:05:15Z
  • Total Non-Auth Failures: 1

Failed Server

1. playwright - Browser Navigation Error

Container: mcr.microsoft.com/playwright:v1.49.1-noble

Issue Type: Security Policy / Browser Configuration

Status:⚠️ Partial Success (browser launches but navigation blocked)

Error:

Error: page.goto: net::ERR_BLOCKED_BY_CLIENT at (example.com/redacted)
Call log:
- navigating to "(example.com/redacted), waiting until "domcontentloaded"

Analysis:
The Playwright MCP server and browser launch successfully, indicating the container and MCP protocol communication are working correctly. However, navigation attempts are blocked by a client-side security policy (ERR_BLOCKED_BY_CLIENT). This error typically occurs when:

  • An ad blocker or security extension is active in the browser profile
  • Content Security Policy (CSP) blocks the navigation
  • Browser launch args include restrictive security settings

The MCP server itself is functional; this is a browser configuration issue.

Suggested Investigation:

  • Review browser launch options in the Playwright server configuration
  • Disable browser extensions or security add-ons
  • Use headless mode without UI extensions
  • Check for CSP headers or security policies in the browser profile
  • Verify browser args don't include overly restrictive security flags
  • Test with different URLs to isolate the issue

Test Configuration

The test used the following setup:

  • MCP Gateway: Pre-configured via workflow infrastructure
  • Test Method: Sequential server testing with simple tool invocations
  • Playwright Browser: Containerized Playwright v1.49.1

Gateway Performance

No gateway-level issues detected:

  • MCP protocol communication working correctly
  • Container launched successfully
  • Error responses properly formatted
  • No crashes or timeouts

Next Steps

  1. Investigate browser launch configuration
  2. Apply fixes to browser settings
  3. Re-run stress test to verify

Generated by Nightly MCP Stress Test
Test Session: stress-test-20260205-030515

Full Test Results: See workflow run artifacts at /tmp/mcp-stress-results/test_report.md

AI generated by Nightly MCP Server Stress Test

<agent_instructions>Only update the .md file, not the .lock.yml file. </agent_instructions>

Comments on the Issue (you are @copilot in this section)

Custom agent used: agentic-workflows
GitHub Agentic Workflows (gh-aw) - Create, debug, and upgrade AI-powered workflows with intelligent prompt routing


✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

CopilotAIand others added 2 commits February 5, 2026 03:18
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
CopilotAI changed the title [WIP] Fix Playwright MCP server browser navigation error due to security policyFix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flagsFeb 5, 2026
CopilotAI requested a review from lpcoxFebruary 5, 2026 03:20
@lpcox
lpcox marked this pull request as ready for review February 5, 2026 03:23
CopilotAI review requested due to automatic review settings February 5, 2026 03:23
@lpcox
lpcox merged commit 7d92126 into mainFeb 5, 2026
4 checks passed
@lpcox
lpcox deleted the copilot/fix-browser-navigation-error branch February 5, 2026 03:24

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes the Playwright MCP server's browser navigation failure in Docker environments by adding required Chromium sandbox bypass flags and enhanced security documentation.

Changes:

  • Added Docker-specific Chromium launch flags (--no-sandbox, --disable-setuid-sandbox, --disable-gpu) to PLAYWRIGHT_LAUNCH_OPTIONS
  • Enhanced security warning with explicit multi-line documentation about disabled security features
  • Added reference to official Playwright Docker documentation

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[mcp-stress-test] Playwright MCP server browser navigation blocked by security policy

3 participants

@lpcox
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flags - #691

Merged
lpcox merged 3 commits into
mainfrom
copilot/fix-browser-navigation-error
Feb 5, 2026
Merged

Fix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flags#691
lpcox merged 3 commits into
mainfrom
copilot/fix-browser-navigation-error

Conversation

CopilotAI commented Feb 5, 2026

Copy link
Copy Markdown
Contributor

Playwright MCP server was failing navigation with ERR_BLOCKED_BY_CLIENT despite container launching successfully. Chromium's sandbox requirements aren't met in Docker containers without explicit bypass flags.

Changes

Added Docker-specific Chromium launch flags to PLAYWRIGHT_LAUNCH_OPTIONS:

  • --no-sandbox - bypass Linux sandbox restrictions
  • --disable-setuid-sandbox - additional sandbox bypass
  • --disable-gpu - disable GPU acceleration (unavailable in headless containers)

Enhanced security warning to explicitly note these flags disable critical browser protections and should only be used in controlled CI environments.

PLAYWRIGHT_LAUNCH_OPTIONS: '{"args": ["--no-sandbox", "--disable-setuid-sandbox", "--disable-gpu", "--disable-blink-features=AutomationControlled", "--disable-web-security", "--disable-features=IsolateOrigins,site-per-process"]}'

Standard pattern for Playwright in Docker per official docs.

Original prompt

This section details on the original issue you should resolve

<issue_title>[mcp-stress-test] Playwright MCP server browser navigation blocked by security policy</issue_title>
<issue_description>## MCP Server Stress Test - Non-Authentication Failure

The nightly stress test detected 1 server with a non-authentication failure.

Test Summary

  • Test Session: stress-test-20260205-030515
  • Test Date: 2026-02-05T03:05:15Z
  • Total Non-Auth Failures: 1

Failed Server

1. playwright - Browser Navigation Error

Container: mcr.microsoft.com/playwright:v1.49.1-noble

Issue Type: Security Policy / Browser Configuration

Status:⚠️ Partial Success (browser launches but navigation blocked)

Error:

Error: page.goto: net::ERR_BLOCKED_BY_CLIENT at (example.com/redacted)
Call log:
- navigating to "(example.com/redacted), waiting until "domcontentloaded"

Analysis:
The Playwright MCP server and browser launch successfully, indicating the container and MCP protocol communication are working correctly. However, navigation attempts are blocked by a client-side security policy (ERR_BLOCKED_BY_CLIENT). This error typically occurs when:

  • An ad blocker or security extension is active in the browser profile
  • Content Security Policy (CSP) blocks the navigation
  • Browser launch args include restrictive security settings

The MCP server itself is functional; this is a browser configuration issue.

Suggested Investigation:

  • Review browser launch options in the Playwright server configuration
  • Disable browser extensions or security add-ons
  • Use headless mode without UI extensions
  • Check for CSP headers or security policies in the browser profile
  • Verify browser args don't include overly restrictive security flags
  • Test with different URLs to isolate the issue

Test Configuration

The test used the following setup:

  • MCP Gateway: Pre-configured via workflow infrastructure
  • Test Method: Sequential server testing with simple tool invocations
  • Playwright Browser: Containerized Playwright v1.49.1

Gateway Performance

No gateway-level issues detected:

  • MCP protocol communication working correctly
  • Container launched successfully
  • Error responses properly formatted
  • No crashes or timeouts

Next Steps

  1. Investigate browser launch configuration
  2. Apply fixes to browser settings
  3. Re-run stress test to verify

Generated by Nightly MCP Stress Test
Test Session: stress-test-20260205-030515

Full Test Results: See workflow run artifacts at /tmp/mcp-stress-results/test_report.md

AI generated by Nightly MCP Server Stress Test

<agent_instructions>Only update the .md file, not the .lock.yml file. </agent_instructions>

Comments on the Issue (you are @copilot in this section)

Custom agent used: agentic-workflows
GitHub Agentic Workflows (gh-aw) - Create, debug, and upgrade AI-powered workflows with intelligent prompt routing


✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

CopilotAIand others added 2 commits February 5, 2026 03:18
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
CopilotAI changed the title [WIP] Fix Playwright MCP server browser navigation error due to security policyFix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flagsFeb 5, 2026
CopilotAI requested a review from lpcoxFebruary 5, 2026 03:20
@lpcox
lpcox marked this pull request as ready for review February 5, 2026 03:23
CopilotAI review requested due to automatic review settings February 5, 2026 03:23
@lpcox
lpcox merged commit 7d92126 into mainFeb 5, 2026
4 checks passed
@lpcox
lpcox deleted the copilot/fix-browser-navigation-error branch February 5, 2026 03:24

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes the Playwright MCP server's browser navigation failure in Docker environments by adding required Chromium sandbox bypass flags and enhanced security documentation.

Changes:

  • Added Docker-specific Chromium launch flags (--no-sandbox, --disable-setuid-sandbox, --disable-gpu) to PLAYWRIGHT_LAUNCH_OPTIONS
  • Enhanced security warning with explicit multi-line documentation about disabled security features
  • Added reference to official Playwright Docker documentation

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[mcp-stress-test] Playwright MCP server browser navigation blocked by security policy

3 participants

@lpcox
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Fix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flags - #691

Merged
lpcox merged 3 commits into
mainfrom
copilot/fix-browser-navigation-error
Feb 5, 2026
Merged

Fix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flags#691
lpcox merged 3 commits into
mainfrom
copilot/fix-browser-navigation-error

Conversation

CopilotAI commented Feb 5, 2026

Copy link
Copy Markdown
Contributor

Playwright MCP server was failing navigation with ERR_BLOCKED_BY_CLIENT despite container launching successfully. Chromium's sandbox requirements aren't met in Docker containers without explicit bypass flags.

Changes

Added Docker-specific Chromium launch flags to PLAYWRIGHT_LAUNCH_OPTIONS:

  • --no-sandbox - bypass Linux sandbox restrictions
  • --disable-setuid-sandbox - additional sandbox bypass
  • --disable-gpu - disable GPU acceleration (unavailable in headless containers)

Enhanced security warning to explicitly note these flags disable critical browser protections and should only be used in controlled CI environments.

PLAYWRIGHT_LAUNCH_OPTIONS: '{"args": ["--no-sandbox", "--disable-setuid-sandbox", "--disable-gpu", "--disable-blink-features=AutomationControlled", "--disable-web-security", "--disable-features=IsolateOrigins,site-per-process"]}'

Standard pattern for Playwright in Docker per official docs.

Original prompt

This section details on the original issue you should resolve

<issue_title>[mcp-stress-test] Playwright MCP server browser navigation blocked by security policy</issue_title>
<issue_description>## MCP Server Stress Test - Non-Authentication Failure

The nightly stress test detected 1 server with a non-authentication failure.

Test Summary

  • Test Session: stress-test-20260205-030515
  • Test Date: 2026-02-05T03:05:15Z
  • Total Non-Auth Failures: 1

Failed Server

1. playwright - Browser Navigation Error

Container: mcr.microsoft.com/playwright:v1.49.1-noble

Issue Type: Security Policy / Browser Configuration

Status:⚠️ Partial Success (browser launches but navigation blocked)

Error:

Error: page.goto: net::ERR_BLOCKED_BY_CLIENT at (example.com/redacted)
Call log:
- navigating to "(example.com/redacted), waiting until "domcontentloaded"

Analysis:
The Playwright MCP server and browser launch successfully, indicating the container and MCP protocol communication are working correctly. However, navigation attempts are blocked by a client-side security policy (ERR_BLOCKED_BY_CLIENT). This error typically occurs when:

  • An ad blocker or security extension is active in the browser profile
  • Content Security Policy (CSP) blocks the navigation
  • Browser launch args include restrictive security settings

The MCP server itself is functional; this is a browser configuration issue.

Suggested Investigation:

  • Review browser launch options in the Playwright server configuration
  • Disable browser extensions or security add-ons
  • Use headless mode without UI extensions
  • Check for CSP headers or security policies in the browser profile
  • Verify browser args don't include overly restrictive security flags
  • Test with different URLs to isolate the issue

Test Configuration

The test used the following setup:

  • MCP Gateway: Pre-configured via workflow infrastructure
  • Test Method: Sequential server testing with simple tool invocations
  • Playwright Browser: Containerized Playwright v1.49.1

Gateway Performance

No gateway-level issues detected:

  • MCP protocol communication working correctly
  • Container launched successfully
  • Error responses properly formatted
  • No crashes or timeouts

Next Steps

  1. Investigate browser launch configuration
  2. Apply fixes to browser settings
  3. Re-run stress test to verify

Generated by Nightly MCP Stress Test
Test Session: stress-test-20260205-030515

Full Test Results: See workflow run artifacts at /tmp/mcp-stress-results/test_report.md

AI generated by Nightly MCP Server Stress Test

<agent_instructions>Only update the .md file, not the .lock.yml file. </agent_instructions>

Comments on the Issue (you are @copilot in this section)

Custom agent used: agentic-workflows
GitHub Agentic Workflows (gh-aw) - Create, debug, and upgrade AI-powered workflows with intelligent prompt routing


✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

CopilotAIand others added 2 commits February 5, 2026 03:18
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
CopilotAI changed the title [WIP] Fix Playwright MCP server browser navigation error due to security policyFix Playwright ERR_BLOCKED_BY_CLIENT in Docker by adding sandbox bypass flagsFeb 5, 2026
CopilotAI requested a review from lpcoxFebruary 5, 2026 03:20
@lpcox
lpcox marked this pull request as ready for review February 5, 2026 03:23
CopilotAI review requested due to automatic review settings February 5, 2026 03:23
@lpcox
lpcox merged commit 7d92126 into mainFeb 5, 2026
4 checks passed
@lpcox
lpcox deleted the copilot/fix-browser-navigation-error branch February 5, 2026 03:24

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes the Playwright MCP server's browser navigation failure in Docker environments by adding required Chromium sandbox bypass flags and enhanced security documentation.

Changes:

  • Added Docker-specific Chromium launch flags (--no-sandbox, --disable-setuid-sandbox, --disable-gpu) to PLAYWRIGHT_LAUNCH_OPTIONS
  • Enhanced security warning with explicit multi-line documentation about disabled security features
  • Added reference to official Playwright Docker documentation

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[mcp-stress-test] Playwright MCP server browser navigation blocked by security policy

3 participants

@lpcox