Add --allowed-origins flag for Playwright browser navigation to localhost - #6453

Merged
pelikhan merged 3 commits into
mainfrom
copilot/fix-playwright-network-issue
Dec 15, 2025
Merged

Add --allowed-origins flag for Playwright browser navigation to localhost#6453
pelikhan merged 3 commits into
mainfrom
copilot/fix-playwright-network-issue

Conversation

CopilotAI commented Dec 14, 2025

Copy link
Copy Markdown
Contributor

Playwright browser in GitHub Actions could not navigate to localhost URLs despite localhost being in the allowed domains. The Playwright MCP server uses two separate flags: --allowed-hosts controls MCP server CORS, while --allowed-origins controls browser navigation. We were only setting the former.

Changes:

  • Added --allowed-origins flag to Playwright MCP configurations for all engines (Claude, Copilot, Codex)
  • Both flags now receive the same domain list: localhost, localhost:*, 127.0.0.1, 127.0.0.1:*
  • Updated rendering functions in pkg/workflow/mcp-config.go and pkg/workflow/mcp_renderer.go
  • Extracted domain string formatting to reduce duplication
  • Updated test assertions to verify both flags are present

Example output:

"playwright": {"command": "docker","args": ["run", "-i", "--rm", "--init","mcr.microsoft.com/playwright/mcp","--output-dir", "/tmp/gh-aw/mcp-logs/playwright","--allowed-hosts", "localhost;localhost:*;127.0.0.1;127.0.0.1:*","--allowed-origins", "localhost;localhost:*;127.0.0.1;127.0.0.1:*"]}

This enables documentation testing, local server testing, and other workflows that require Playwright to access localhost in GitHub Actions.

Warning

Firewall rules blocked me from connecting to one or more addresses (expand for details)

I tried to connect to the following addresses, but was blocked by firewall rules:

  • https://api.github.com/user
    • Triggering command: /usr/bin/gh gh api user --jq .login 08431cddfb8368fd83d5badbf9bfd GO111MODULE ache/go/1.25.0/x64/bin/go GOINSECURE GOMOD GOMODCACHE go env tags/v6 GO111MODULE ps GOINSECURE GOMOD GOMODCACHE ps (http block)
    • Triggering command: /usr/bin/gh gh api user --jq .login -json 98934cb7db3cf861b1c3912a44c25fe853f52e101adce49a243 ache/go/1.25.0/x64/pkg/tool/linux_amd64/cgo 98934cb7db3cf861git (http block)
    • Triggering command: /usr/bin/gh gh api user --jq .login /run/containerd/io.containerd.runtime.v2.task/moby/412f2133922a5790ab7dae82709d4a5952fe5abddb2578c8a19a9a4c54e16330/init.pid 412f2133922a5790ab7dae82709d4a5952fe5abddb2578c8a19a9a4c54e16330 605619/b123=> a5952fe5abddb2578c8a19a9a4c54e16330/log.json bnext/gh-aw/cmd/aw -d/gh-aw go env s -d/gh-aw /opt/hostedtoolcache/go/1.25.0/xjson GOINSECURE GOMOD GOMODCACHE 605619/b123/impo/var/run/docker/runtime-runc/moby (http block)

If you need me to access, download, or install something from one of these locations, you can either:

Original prompt

This section details on the original issue you should resolve

<issue_title>🔍 Multi-Device Docs Testing Report - Technical Limitation Discovered</issue_title>
<issue_description>## Test Summary

Triggered by:@mnkiefer
Workflow Run:#20001915806
Test Date: 2025-12-07
Documentation Site: Built successfully at /docs/dist


Results Overview

Testing Status: Unable to complete browser-based testing
🔴 Critical Issue Identified: Playwright browser sandbox prevents localhost connections


Critical Issues

🔴 Playwright Network Isolation in GitHub Actions

Issue: The Playwright MCP server running in this GitHub Actions environment operates in a sandboxed browser that blocks connections to localhost and 127.0.0.1.

Impact:

  • Cannot perform visual regression testing
  • Cannot test responsive layouts across devices
  • Cannot validate accessibility with live browser interactions
  • Cannot capture screenshots of actual rendered pages

Technical Details:

Error: page.goto: net::ERR_CONNECTION_REFUSED at (redacted)

The documentation site builds successfully and serves correctly:

  • ✅ Build completed in ~16 seconds
  • ✅ Generated 60 pages with 98 workflow examples
  • ✅ Preview server starts on port 4321
  • ✅ Server responds to curl requests
  • ❌ Playwright browser cannot connect due to sandbox restrictions

Recommendations

Option 1: Deploy to Temporary Hosting

Instead of testing against localhost, deploy the built site to a publicly accessible URL:

  • Use GitHub Pages preview deployment
  • Use Netlify/Vercel deploy previews
  • Use ngrok or similar tunneling service

Option 2: Alternative Testing Approach

Use static analysis tools that don't require browser rendering:

  • HTML validation: Use html-validate or W3C validator
  • Accessibility: Use pa11y-ci or axe-core CLI
  • Link checking: Use linkinator or broken-link-checker
  • Responsive analysis: Parse CSS and check viewport rules

Option 3: Docker-based Testing

Run Playwright in a Docker container with proper network configuration:

- name: Run Playwright testsrun: | docker run --network=host -v $PWD:/work -w /work \ mcr.microsoft.com/playwright:latest \ npm run test:e2e

Option 4: Use GitHub Actions Service Containers

Configure the workflow to use service containers that share network access:

jobs:
test:
services:
docs:
image: nginx:alpineports:
- 4321:80

What Was Tested

Build Process

  • Documentation builds successfully
  • All 98 lab workflows generated correctly
  • Mermaid diagrams processed (10 in architecture docs)
  • Pagefind search index created
  • Sitemap generated
  • All internal links validated

Server Configuration

  • Preview server starts correctly
  • Serves at /gh-aw/ base path
  • Returns valid HTML
  • Includes proper meta tags and SEO

Next Steps

To enable comprehensive multi-device testing for the documentation site, one of the following approaches should be implemented:

  1. Short-term: Use static analysis tools that don't require browser rendering
  2. Medium-term: Deploy to a preview URL before testing
  3. Long-term: Configure proper Docker/service container setup for full Playwright testing

Would you like me to implement any of these alternative testing approaches?


Build Artifacts

The documentation was successfully built to /home/runner/work/gh-aw/gh-aw/docs/dist with:

  • 60 HTML pages
  • 4,364 indexed words
  • 1 language (English)
  • All internal links validated
  • Sitemap and search index generated

AI generated by Multi-Device Docs Tester

Comments on the Issue (you are @copilot in this section)

@pelikhan /q the playwright default domain set should allow localhost 127.0.0.1

✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

CopilotAIand others added 2 commits December 14, 2025 20:31
Co-authored-by: mnkiefer <8320933+mnkiefer@users.noreply.github.com>
Co-authored-by: mnkiefer <8320933+mnkiefer@users.noreply.github.com>
CopilotAI changed the title [WIP] Fix Playwright network isolation issue in GitHub ActionsAdd --allowed-origins flag for Playwright browser navigation to localhostDec 14, 2025
CopilotAI requested a review from mnkieferDecember 14, 2025 20:50
@pelikhan
pelikhan marked this pull request as ready for review December 14, 2025 23:04
@pelikhan
pelikhan merged commit 017e1fb into mainDec 15, 2025
125 checks passed
@pelikhan
pelikhan deleted the copilot/fix-playwright-network-issue branch December 15, 2025 01:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

🔍 Multi-Device Docs Testing Report - Technical Limitation Discovered

3 participants

@pelikhan@mnkiefer
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Add --allowed-origins flag for Playwright browser navigation to localhost - #6453

Merged
pelikhan merged 3 commits into
mainfrom
copilot/fix-playwright-network-issue
Dec 15, 2025
Merged

Add --allowed-origins flag for Playwright browser navigation to localhost#6453
pelikhan merged 3 commits into
mainfrom
copilot/fix-playwright-network-issue

Conversation

CopilotAI commented Dec 14, 2025

Copy link
Copy Markdown
Contributor

Playwright browser in GitHub Actions could not navigate to localhost URLs despite localhost being in the allowed domains. The Playwright MCP server uses two separate flags: --allowed-hosts controls MCP server CORS, while --allowed-origins controls browser navigation. We were only setting the former.

Changes:

  • Added --allowed-origins flag to Playwright MCP configurations for all engines (Claude, Copilot, Codex)
  • Both flags now receive the same domain list: localhost, localhost:*, 127.0.0.1, 127.0.0.1:*
  • Updated rendering functions in pkg/workflow/mcp-config.go and pkg/workflow/mcp_renderer.go
  • Extracted domain string formatting to reduce duplication
  • Updated test assertions to verify both flags are present

Example output:

"playwright": {"command": "docker","args": ["run", "-i", "--rm", "--init","mcr.microsoft.com/playwright/mcp","--output-dir", "/tmp/gh-aw/mcp-logs/playwright","--allowed-hosts", "localhost;localhost:*;127.0.0.1;127.0.0.1:*","--allowed-origins", "localhost;localhost:*;127.0.0.1;127.0.0.1:*"]}

This enables documentation testing, local server testing, and other workflows that require Playwright to access localhost in GitHub Actions.

Warning

Firewall rules blocked me from connecting to one or more addresses (expand for details)

I tried to connect to the following addresses, but was blocked by firewall rules:

  • https://api.github.com/user
    • Triggering command: /usr/bin/gh gh api user --jq .login 08431cddfb8368fd83d5badbf9bfd GO111MODULE ache/go/1.25.0/x64/bin/go GOINSECURE GOMOD GOMODCACHE go env tags/v6 GO111MODULE ps GOINSECURE GOMOD GOMODCACHE ps (http block)
    • Triggering command: /usr/bin/gh gh api user --jq .login -json 98934cb7db3cf861b1c3912a44c25fe853f52e101adce49a243 ache/go/1.25.0/x64/pkg/tool/linux_amd64/cgo 98934cb7db3cf861git (http block)
    • Triggering command: /usr/bin/gh gh api user --jq .login /run/containerd/io.containerd.runtime.v2.task/moby/412f2133922a5790ab7dae82709d4a5952fe5abddb2578c8a19a9a4c54e16330/init.pid 412f2133922a5790ab7dae82709d4a5952fe5abddb2578c8a19a9a4c54e16330 605619/b123=&gt; a5952fe5abddb2578c8a19a9a4c54e16330/log.json bnext/gh-aw/cmd/aw -d/gh-aw go env s -d/gh-aw /opt/hostedtoolcache/go/1.25.0/xjson GOINSECURE GOMOD GOMODCACHE 605619/b123/impo/var/run/docker/runtime-runc/moby (http block)

If you need me to access, download, or install something from one of these locations, you can either:

Original prompt

This section details on the original issue you should resolve

<issue_title>🔍 Multi-Device Docs Testing Report - Technical Limitation Discovered</issue_title>
<issue_description>## Test Summary

Triggered by:@mnkiefer
Workflow Run:#20001915806
Test Date: 2025-12-07
Documentation Site: Built successfully at /docs/dist


Results Overview

Testing Status: Unable to complete browser-based testing
🔴 Critical Issue Identified: Playwright browser sandbox prevents localhost connections


Critical Issues

🔴 Playwright Network Isolation in GitHub Actions

Issue: The Playwright MCP server running in this GitHub Actions environment operates in a sandboxed browser that blocks connections to localhost and 127.0.0.1.

Impact:

  • Cannot perform visual regression testing
  • Cannot test responsive layouts across devices
  • Cannot validate accessibility with live browser interactions
  • Cannot capture screenshots of actual rendered pages

Technical Details:

Error: page.goto: net::ERR_CONNECTION_REFUSED at (redacted)

The documentation site builds successfully and serves correctly:

  • ✅ Build completed in ~16 seconds
  • ✅ Generated 60 pages with 98 workflow examples
  • ✅ Preview server starts on port 4321
  • ✅ Server responds to curl requests
  • ❌ Playwright browser cannot connect due to sandbox restrictions

Recommendations

Option 1: Deploy to Temporary Hosting

Instead of testing against localhost, deploy the built site to a publicly accessible URL:

  • Use GitHub Pages preview deployment
  • Use Netlify/Vercel deploy previews
  • Use ngrok or similar tunneling service

Option 2: Alternative Testing Approach

Use static analysis tools that don't require browser rendering:

  • HTML validation: Use html-validate or W3C validator
  • Accessibility: Use pa11y-ci or axe-core CLI
  • Link checking: Use linkinator or broken-link-checker
  • Responsive analysis: Parse CSS and check viewport rules

Option 3: Docker-based Testing

Run Playwright in a Docker container with proper network configuration:

- name: Run Playwright testsrun: | docker run --network=host -v $PWD:/work -w /work \ mcr.microsoft.com/playwright:latest \ npm run test:e2e

Option 4: Use GitHub Actions Service Containers

Configure the workflow to use service containers that share network access:

jobs:
test:
services:
docs:
image: nginx:alpineports:
- 4321:80

What Was Tested

Build Process

  • Documentation builds successfully
  • All 98 lab workflows generated correctly
  • Mermaid diagrams processed (10 in architecture docs)
  • Pagefind search index created
  • Sitemap generated
  • All internal links validated

Server Configuration

  • Preview server starts correctly
  • Serves at /gh-aw/ base path
  • Returns valid HTML
  • Includes proper meta tags and SEO

Next Steps

To enable comprehensive multi-device testing for the documentation site, one of the following approaches should be implemented:

  1. Short-term: Use static analysis tools that don't require browser rendering
  2. Medium-term: Deploy to a preview URL before testing
  3. Long-term: Configure proper Docker/service container setup for full Playwright testing

Would you like me to implement any of these alternative testing approaches?


Build Artifacts

The documentation was successfully built to /home/runner/work/gh-aw/gh-aw/docs/dist with:

  • 60 HTML pages
  • 4,364 indexed words
  • 1 language (English)
  • All internal links validated
  • Sitemap and search index generated

AI generated by Multi-Device Docs Tester

Comments on the Issue (you are @copilot in this section)

@pelikhan /q the playwright default domain set should allow localhost 127.0.0.1

✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

CopilotAIand others added 2 commits December 14, 2025 20:31
Co-authored-by: mnkiefer <8320933+mnkiefer@users.noreply.github.com>
Co-authored-by: mnkiefer <8320933+mnkiefer@users.noreply.github.com>
CopilotAI changed the title [WIP] Fix Playwright network isolation issue in GitHub ActionsAdd --allowed-origins flag for Playwright browser navigation to localhostDec 14, 2025
CopilotAI requested a review from mnkieferDecember 14, 2025 20:50
@pelikhan
pelikhan marked this pull request as ready for review December 14, 2025 23:04
@pelikhan
pelikhan merged commit 017e1fb into mainDec 15, 2025
125 checks passed
@pelikhan
pelikhan deleted the copilot/fix-playwright-network-issue branch December 15, 2025 01:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

🔍 Multi-Device Docs Testing Report - Technical Limitation Discovered

3 participants

@pelikhan@mnkiefer
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add --allowed-origins flag for Playwright browser navigation to localhost - #6453

Merged
pelikhan merged 3 commits into
mainfrom
copilot/fix-playwright-network-issue
Dec 15, 2025
Merged

Add --allowed-origins flag for Playwright browser navigation to localhost#6453
pelikhan merged 3 commits into
mainfrom
copilot/fix-playwright-network-issue

Conversation

CopilotAI commented Dec 14, 2025

Copy link
Copy Markdown
Contributor

Playwright browser in GitHub Actions could not navigate to localhost URLs despite localhost being in the allowed domains. The Playwright MCP server uses two separate flags: --allowed-hosts controls MCP server CORS, while --allowed-origins controls browser navigation. We were only setting the former.

Changes:

  • Added --allowed-origins flag to Playwright MCP configurations for all engines (Claude, Copilot, Codex)
  • Both flags now receive the same domain list: localhost, localhost:*, 127.0.0.1, 127.0.0.1:*
  • Updated rendering functions in pkg/workflow/mcp-config.go and pkg/workflow/mcp_renderer.go
  • Extracted domain string formatting to reduce duplication
  • Updated test assertions to verify both flags are present

Example output:

"playwright": {"command": "docker","args": ["run", "-i", "--rm", "--init","mcr.microsoft.com/playwright/mcp","--output-dir", "/tmp/gh-aw/mcp-logs/playwright","--allowed-hosts", "localhost;localhost:*;127.0.0.1;127.0.0.1:*","--allowed-origins", "localhost;localhost:*;127.0.0.1;127.0.0.1:*"]}

This enables documentation testing, local server testing, and other workflows that require Playwright to access localhost in GitHub Actions.

Warning

Firewall rules blocked me from connecting to one or more addresses (expand for details)

I tried to connect to the following addresses, but was blocked by firewall rules:

  • https://api.github.com/user
    • Triggering command: /usr/bin/gh gh api user --jq .login 08431cddfb8368fd83d5badbf9bfd GO111MODULE ache/go/1.25.0/x64/bin/go GOINSECURE GOMOD GOMODCACHE go env tags/v6 GO111MODULE ps GOINSECURE GOMOD GOMODCACHE ps (http block)
    • Triggering command: /usr/bin/gh gh api user --jq .login -json 98934cb7db3cf861b1c3912a44c25fe853f52e101adce49a243 ache/go/1.25.0/x64/pkg/tool/linux_amd64/cgo 98934cb7db3cf861git (http block)
    • Triggering command: /usr/bin/gh gh api user --jq .login /run/containerd/io.containerd.runtime.v2.task/moby/412f2133922a5790ab7dae82709d4a5952fe5abddb2578c8a19a9a4c54e16330/init.pid 412f2133922a5790ab7dae82709d4a5952fe5abddb2578c8a19a9a4c54e16330 605619/b123=&gt; a5952fe5abddb2578c8a19a9a4c54e16330/log.json bnext/gh-aw/cmd/aw -d/gh-aw go env s -d/gh-aw /opt/hostedtoolcache/go/1.25.0/xjson GOINSECURE GOMOD GOMODCACHE 605619/b123/impo/var/run/docker/runtime-runc/moby (http block)

If you need me to access, download, or install something from one of these locations, you can either:

Original prompt

This section details on the original issue you should resolve

<issue_title>🔍 Multi-Device Docs Testing Report - Technical Limitation Discovered</issue_title>
<issue_description>## Test Summary

Triggered by:@mnkiefer
Workflow Run:#20001915806
Test Date: 2025-12-07
Documentation Site: Built successfully at /docs/dist


Results Overview

Testing Status: Unable to complete browser-based testing
🔴 Critical Issue Identified: Playwright browser sandbox prevents localhost connections


Critical Issues

🔴 Playwright Network Isolation in GitHub Actions

Issue: The Playwright MCP server running in this GitHub Actions environment operates in a sandboxed browser that blocks connections to localhost and 127.0.0.1.

Impact:

  • Cannot perform visual regression testing
  • Cannot test responsive layouts across devices
  • Cannot validate accessibility with live browser interactions
  • Cannot capture screenshots of actual rendered pages

Technical Details:

Error: page.goto: net::ERR_CONNECTION_REFUSED at (redacted)

The documentation site builds successfully and serves correctly:

  • ✅ Build completed in ~16 seconds
  • ✅ Generated 60 pages with 98 workflow examples
  • ✅ Preview server starts on port 4321
  • ✅ Server responds to curl requests
  • ❌ Playwright browser cannot connect due to sandbox restrictions

Recommendations

Option 1: Deploy to Temporary Hosting

Instead of testing against localhost, deploy the built site to a publicly accessible URL:

  • Use GitHub Pages preview deployment
  • Use Netlify/Vercel deploy previews
  • Use ngrok or similar tunneling service

Option 2: Alternative Testing Approach

Use static analysis tools that don't require browser rendering:

  • HTML validation: Use html-validate or W3C validator
  • Accessibility: Use pa11y-ci or axe-core CLI
  • Link checking: Use linkinator or broken-link-checker
  • Responsive analysis: Parse CSS and check viewport rules

Option 3: Docker-based Testing

Run Playwright in a Docker container with proper network configuration:

- name: Run Playwright testsrun: | docker run --network=host -v $PWD:/work -w /work \ mcr.microsoft.com/playwright:latest \ npm run test:e2e

Option 4: Use GitHub Actions Service Containers

Configure the workflow to use service containers that share network access:

jobs:
test:
services:
docs:
image: nginx:alpineports:
- 4321:80

What Was Tested

Build Process

  • Documentation builds successfully
  • All 98 lab workflows generated correctly
  • Mermaid diagrams processed (10 in architecture docs)
  • Pagefind search index created
  • Sitemap generated
  • All internal links validated

Server Configuration

  • Preview server starts correctly
  • Serves at /gh-aw/ base path
  • Returns valid HTML
  • Includes proper meta tags and SEO

Next Steps

To enable comprehensive multi-device testing for the documentation site, one of the following approaches should be implemented:

  1. Short-term: Use static analysis tools that don't require browser rendering
  2. Medium-term: Deploy to a preview URL before testing
  3. Long-term: Configure proper Docker/service container setup for full Playwright testing

Would you like me to implement any of these alternative testing approaches?


Build Artifacts

The documentation was successfully built to /home/runner/work/gh-aw/gh-aw/docs/dist with:

  • 60 HTML pages
  • 4,364 indexed words
  • 1 language (English)
  • All internal links validated
  • Sitemap and search index generated

AI generated by Multi-Device Docs Tester

Comments on the Issue (you are @copilot in this section)

@pelikhan /q the playwright default domain set should allow localhost 127.0.0.1

✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

CopilotAIand others added 2 commits December 14, 2025 20:31
Co-authored-by: mnkiefer <8320933+mnkiefer@users.noreply.github.com>
Co-authored-by: mnkiefer <8320933+mnkiefer@users.noreply.github.com>
CopilotAI changed the title [WIP] Fix Playwright network isolation issue in GitHub ActionsAdd --allowed-origins flag for Playwright browser navigation to localhostDec 14, 2025
CopilotAI requested a review from mnkieferDecember 14, 2025 20:50
@pelikhan
pelikhan marked this pull request as ready for review December 14, 2025 23:04
@pelikhan
pelikhan merged commit 017e1fb into mainDec 15, 2025
125 checks passed
@pelikhan
pelikhan deleted the copilot/fix-playwright-network-issue branch December 15, 2025 01:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

🔍 Multi-Device Docs Testing Report - Technical Limitation Discovered

3 participants

@pelikhan@mnkiefer
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add --allowed-origins flag for Playwright browser navigation to localhost - #6453

Merged
pelikhan merged 3 commits into
mainfrom
copilot/fix-playwright-network-issue
Dec 15, 2025
Merged

Add --allowed-origins flag for Playwright browser navigation to localhost#6453
pelikhan merged 3 commits into
mainfrom
copilot/fix-playwright-network-issue

Conversation

CopilotAI commented Dec 14, 2025

Copy link
Copy Markdown
Contributor

Playwright browser in GitHub Actions could not navigate to localhost URLs despite localhost being in the allowed domains. The Playwright MCP server uses two separate flags: --allowed-hosts controls MCP server CORS, while --allowed-origins controls browser navigation. We were only setting the former.

Changes:

  • Added --allowed-origins flag to Playwright MCP configurations for all engines (Claude, Copilot, Codex)
  • Both flags now receive the same domain list: localhost, localhost:*, 127.0.0.1, 127.0.0.1:*
  • Updated rendering functions in pkg/workflow/mcp-config.go and pkg/workflow/mcp_renderer.go
  • Extracted domain string formatting to reduce duplication
  • Updated test assertions to verify both flags are present

Example output:

"playwright": {"command": "docker","args": ["run", "-i", "--rm", "--init","mcr.microsoft.com/playwright/mcp","--output-dir", "/tmp/gh-aw/mcp-logs/playwright","--allowed-hosts", "localhost;localhost:*;127.0.0.1;127.0.0.1:*","--allowed-origins", "localhost;localhost:*;127.0.0.1;127.0.0.1:*"]}

This enables documentation testing, local server testing, and other workflows that require Playwright to access localhost in GitHub Actions.

Warning

Firewall rules blocked me from connecting to one or more addresses (expand for details)

I tried to connect to the following addresses, but was blocked by firewall rules:

  • https://api.github.com/user
    • Triggering command: /usr/bin/gh gh api user --jq .login 08431cddfb8368fd83d5badbf9bfd GO111MODULE ache/go/1.25.0/x64/bin/go GOINSECURE GOMOD GOMODCACHE go env tags/v6 GO111MODULE ps GOINSECURE GOMOD GOMODCACHE ps (http block)
    • Triggering command: /usr/bin/gh gh api user --jq .login -json 98934cb7db3cf861b1c3912a44c25fe853f52e101adce49a243 ache/go/1.25.0/x64/pkg/tool/linux_amd64/cgo 98934cb7db3cf861git (http block)
    • Triggering command: /usr/bin/gh gh api user --jq .login /run/containerd/io.containerd.runtime.v2.task/moby/412f2133922a5790ab7dae82709d4a5952fe5abddb2578c8a19a9a4c54e16330/init.pid 412f2133922a5790ab7dae82709d4a5952fe5abddb2578c8a19a9a4c54e16330 605619/b123=&gt; a5952fe5abddb2578c8a19a9a4c54e16330/log.json bnext/gh-aw/cmd/aw -d/gh-aw go env s -d/gh-aw /opt/hostedtoolcache/go/1.25.0/xjson GOINSECURE GOMOD GOMODCACHE 605619/b123/impo/var/run/docker/runtime-runc/moby (http block)

If you need me to access, download, or install something from one of these locations, you can either:

Original prompt

This section details on the original issue you should resolve

<issue_title>🔍 Multi-Device Docs Testing Report - Technical Limitation Discovered</issue_title>
<issue_description>## Test Summary

Triggered by:@mnkiefer
Workflow Run:#20001915806
Test Date: 2025-12-07
Documentation Site: Built successfully at /docs/dist


Results Overview

Testing Status: Unable to complete browser-based testing
🔴 Critical Issue Identified: Playwright browser sandbox prevents localhost connections


Critical Issues

🔴 Playwright Network Isolation in GitHub Actions

Issue: The Playwright MCP server running in this GitHub Actions environment operates in a sandboxed browser that blocks connections to localhost and 127.0.0.1.

Impact:

  • Cannot perform visual regression testing
  • Cannot test responsive layouts across devices
  • Cannot validate accessibility with live browser interactions
  • Cannot capture screenshots of actual rendered pages

Technical Details:

Error: page.goto: net::ERR_CONNECTION_REFUSED at (redacted)

The documentation site builds successfully and serves correctly:

  • ✅ Build completed in ~16 seconds
  • ✅ Generated 60 pages with 98 workflow examples
  • ✅ Preview server starts on port 4321
  • ✅ Server responds to curl requests
  • ❌ Playwright browser cannot connect due to sandbox restrictions

Recommendations

Option 1: Deploy to Temporary Hosting

Instead of testing against localhost, deploy the built site to a publicly accessible URL:

  • Use GitHub Pages preview deployment
  • Use Netlify/Vercel deploy previews
  • Use ngrok or similar tunneling service

Option 2: Alternative Testing Approach

Use static analysis tools that don't require browser rendering:

  • HTML validation: Use html-validate or W3C validator
  • Accessibility: Use pa11y-ci or axe-core CLI
  • Link checking: Use linkinator or broken-link-checker
  • Responsive analysis: Parse CSS and check viewport rules

Option 3: Docker-based Testing

Run Playwright in a Docker container with proper network configuration:

- name: Run Playwright testsrun: | docker run --network=host -v $PWD:/work -w /work \ mcr.microsoft.com/playwright:latest \ npm run test:e2e

Option 4: Use GitHub Actions Service Containers

Configure the workflow to use service containers that share network access:

jobs:
test:
services:
docs:
image: nginx:alpineports:
- 4321:80

What Was Tested

Build Process

  • Documentation builds successfully
  • All 98 lab workflows generated correctly
  • Mermaid diagrams processed (10 in architecture docs)
  • Pagefind search index created
  • Sitemap generated
  • All internal links validated

Server Configuration

  • Preview server starts correctly
  • Serves at /gh-aw/ base path
  • Returns valid HTML
  • Includes proper meta tags and SEO

Next Steps

To enable comprehensive multi-device testing for the documentation site, one of the following approaches should be implemented:

  1. Short-term: Use static analysis tools that don't require browser rendering
  2. Medium-term: Deploy to a preview URL before testing
  3. Long-term: Configure proper Docker/service container setup for full Playwright testing

Would you like me to implement any of these alternative testing approaches?


Build Artifacts

The documentation was successfully built to /home/runner/work/gh-aw/gh-aw/docs/dist with:

  • 60 HTML pages
  • 4,364 indexed words
  • 1 language (English)
  • All internal links validated
  • Sitemap and search index generated

AI generated by Multi-Device Docs Tester

Comments on the Issue (you are @copilot in this section)

@pelikhan /q the playwright default domain set should allow localhost 127.0.0.1

✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

CopilotAIand others added 2 commits December 14, 2025 20:31
Co-authored-by: mnkiefer <8320933+mnkiefer@users.noreply.github.com>
Co-authored-by: mnkiefer <8320933+mnkiefer@users.noreply.github.com>
CopilotAI changed the title [WIP] Fix Playwright network isolation issue in GitHub ActionsAdd --allowed-origins flag for Playwright browser navigation to localhostDec 14, 2025
CopilotAI requested a review from mnkieferDecember 14, 2025 20:50
@pelikhan
pelikhan marked this pull request as ready for review December 14, 2025 23:04
@pelikhan
pelikhan merged commit 017e1fb into mainDec 15, 2025
125 checks passed
@pelikhan
pelikhan deleted the copilot/fix-playwright-network-issue branch December 15, 2025 01:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

🔍 Multi-Device Docs Testing Report - Technical Limitation Discovered

3 participants

@pelikhan@mnkiefer
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Add --allowed-origins flag for Playwright browser navigation to localhost - #6453

Merged
pelikhan merged 3 commits into
mainfrom
copilot/fix-playwright-network-issue
Dec 15, 2025
Merged

Add --allowed-origins flag for Playwright browser navigation to localhost#6453
pelikhan merged 3 commits into
mainfrom
copilot/fix-playwright-network-issue

Conversation

CopilotAI commented Dec 14, 2025

Copy link
Copy Markdown
Contributor

Playwright browser in GitHub Actions could not navigate to localhost URLs despite localhost being in the allowed domains. The Playwright MCP server uses two separate flags: --allowed-hosts controls MCP server CORS, while --allowed-origins controls browser navigation. We were only setting the former.

Changes:

  • Added --allowed-origins flag to Playwright MCP configurations for all engines (Claude, Copilot, Codex)
  • Both flags now receive the same domain list: localhost, localhost:*, 127.0.0.1, 127.0.0.1:*
  • Updated rendering functions in pkg/workflow/mcp-config.go and pkg/workflow/mcp_renderer.go
  • Extracted domain string formatting to reduce duplication
  • Updated test assertions to verify both flags are present

Example output:

"playwright": {"command": "docker","args": ["run", "-i", "--rm", "--init","mcr.microsoft.com/playwright/mcp","--output-dir", "/tmp/gh-aw/mcp-logs/playwright","--allowed-hosts", "localhost;localhost:*;127.0.0.1;127.0.0.1:*","--allowed-origins", "localhost;localhost:*;127.0.0.1;127.0.0.1:*"]}

This enables documentation testing, local server testing, and other workflows that require Playwright to access localhost in GitHub Actions.

Warning

Firewall rules blocked me from connecting to one or more addresses (expand for details)

I tried to connect to the following addresses, but was blocked by firewall rules:

  • https://api.github.com/user
    • Triggering command: /usr/bin/gh gh api user --jq .login 08431cddfb8368fd83d5badbf9bfd GO111MODULE ache/go/1.25.0/x64/bin/go GOINSECURE GOMOD GOMODCACHE go env tags/v6 GO111MODULE ps GOINSECURE GOMOD GOMODCACHE ps (http block)
    • Triggering command: /usr/bin/gh gh api user --jq .login -json 98934cb7db3cf861b1c3912a44c25fe853f52e101adce49a243 ache/go/1.25.0/x64/pkg/tool/linux_amd64/cgo 98934cb7db3cf861git (http block)
    • Triggering command: /usr/bin/gh gh api user --jq .login /run/containerd/io.containerd.runtime.v2.task/moby/412f2133922a5790ab7dae82709d4a5952fe5abddb2578c8a19a9a4c54e16330/init.pid 412f2133922a5790ab7dae82709d4a5952fe5abddb2578c8a19a9a4c54e16330 605619/b123=&gt; a5952fe5abddb2578c8a19a9a4c54e16330/log.json bnext/gh-aw/cmd/aw -d/gh-aw go env s -d/gh-aw /opt/hostedtoolcache/go/1.25.0/xjson GOINSECURE GOMOD GOMODCACHE 605619/b123/impo/var/run/docker/runtime-runc/moby (http block)

If you need me to access, download, or install something from one of these locations, you can either:

Original prompt

This section details on the original issue you should resolve

<issue_title>🔍 Multi-Device Docs Testing Report - Technical Limitation Discovered</issue_title>
<issue_description>## Test Summary

Triggered by:@mnkiefer
Workflow Run:#20001915806
Test Date: 2025-12-07
Documentation Site: Built successfully at /docs/dist


Results Overview

Testing Status: Unable to complete browser-based testing
🔴 Critical Issue Identified: Playwright browser sandbox prevents localhost connections


Critical Issues

🔴 Playwright Network Isolation in GitHub Actions

Issue: The Playwright MCP server running in this GitHub Actions environment operates in a sandboxed browser that blocks connections to localhost and 127.0.0.1.

Impact:

  • Cannot perform visual regression testing
  • Cannot test responsive layouts across devices
  • Cannot validate accessibility with live browser interactions
  • Cannot capture screenshots of actual rendered pages

Technical Details:

Error: page.goto: net::ERR_CONNECTION_REFUSED at (redacted)

The documentation site builds successfully and serves correctly:

  • ✅ Build completed in ~16 seconds
  • ✅ Generated 60 pages with 98 workflow examples
  • ✅ Preview server starts on port 4321
  • ✅ Server responds to curl requests
  • ❌ Playwright browser cannot connect due to sandbox restrictions

Recommendations

Option 1: Deploy to Temporary Hosting

Instead of testing against localhost, deploy the built site to a publicly accessible URL:

  • Use GitHub Pages preview deployment
  • Use Netlify/Vercel deploy previews
  • Use ngrok or similar tunneling service

Option 2: Alternative Testing Approach

Use static analysis tools that don't require browser rendering:

  • HTML validation: Use html-validate or W3C validator
  • Accessibility: Use pa11y-ci or axe-core CLI
  • Link checking: Use linkinator or broken-link-checker
  • Responsive analysis: Parse CSS and check viewport rules

Option 3: Docker-based Testing

Run Playwright in a Docker container with proper network configuration:

- name: Run Playwright testsrun: | docker run --network=host -v $PWD:/work -w /work \ mcr.microsoft.com/playwright:latest \ npm run test:e2e

Option 4: Use GitHub Actions Service Containers

Configure the workflow to use service containers that share network access:

jobs:
test:
services:
docs:
image: nginx:alpineports:
- 4321:80

What Was Tested

Build Process

  • Documentation builds successfully
  • All 98 lab workflows generated correctly
  • Mermaid diagrams processed (10 in architecture docs)
  • Pagefind search index created
  • Sitemap generated
  • All internal links validated

Server Configuration

  • Preview server starts correctly
  • Serves at /gh-aw/ base path
  • Returns valid HTML
  • Includes proper meta tags and SEO

Next Steps

To enable comprehensive multi-device testing for the documentation site, one of the following approaches should be implemented:

  1. Short-term: Use static analysis tools that don't require browser rendering
  2. Medium-term: Deploy to a preview URL before testing
  3. Long-term: Configure proper Docker/service container setup for full Playwright testing

Would you like me to implement any of these alternative testing approaches?


Build Artifacts

The documentation was successfully built to /home/runner/work/gh-aw/gh-aw/docs/dist with:

  • 60 HTML pages
  • 4,364 indexed words
  • 1 language (English)
  • All internal links validated
  • Sitemap and search index generated

AI generated by Multi-Device Docs Tester

Comments on the Issue (you are @copilot in this section)

@pelikhan /q the playwright default domain set should allow localhost 127.0.0.1

✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

CopilotAIand others added 2 commits December 14, 2025 20:31
Co-authored-by: mnkiefer <8320933+mnkiefer@users.noreply.github.com>
Co-authored-by: mnkiefer <8320933+mnkiefer@users.noreply.github.com>
CopilotAI changed the title [WIP] Fix Playwright network isolation issue in GitHub ActionsAdd --allowed-origins flag for Playwright browser navigation to localhostDec 14, 2025
CopilotAI requested a review from mnkieferDecember 14, 2025 20:50
@pelikhan
pelikhan marked this pull request as ready for review December 14, 2025 23:04
@pelikhan
pelikhan merged commit 017e1fb into mainDec 15, 2025
125 checks passed
@pelikhan
pelikhan deleted the copilot/fix-playwright-network-issue branch December 15, 2025 01:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

🔍 Multi-Device Docs Testing Report - Technical Limitation Discovered

3 participants

@pelikhan@mnkiefer
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add --allowed-origins flag for Playwright browser navigation to localhost - #6453

Merged
pelikhan merged 3 commits into
mainfrom
copilot/fix-playwright-network-issue
Dec 15, 2025
Merged

Add --allowed-origins flag for Playwright browser navigation to localhost#6453
pelikhan merged 3 commits into
mainfrom
copilot/fix-playwright-network-issue

Conversation

CopilotAI commented Dec 14, 2025

Copy link
Copy Markdown
Contributor

Playwright browser in GitHub Actions could not navigate to localhost URLs despite localhost being in the allowed domains. The Playwright MCP server uses two separate flags: --allowed-hosts controls MCP server CORS, while --allowed-origins controls browser navigation. We were only setting the former.

Changes:

  • Added --allowed-origins flag to Playwright MCP configurations for all engines (Claude, Copilot, Codex)
  • Both flags now receive the same domain list: localhost, localhost:*, 127.0.0.1, 127.0.0.1:*
  • Updated rendering functions in pkg/workflow/mcp-config.go and pkg/workflow/mcp_renderer.go
  • Extracted domain string formatting to reduce duplication
  • Updated test assertions to verify both flags are present

Example output:

"playwright": {"command": "docker","args": ["run", "-i", "--rm", "--init","mcr.microsoft.com/playwright/mcp","--output-dir", "/tmp/gh-aw/mcp-logs/playwright","--allowed-hosts", "localhost;localhost:*;127.0.0.1;127.0.0.1:*","--allowed-origins", "localhost;localhost:*;127.0.0.1;127.0.0.1:*"]}

This enables documentation testing, local server testing, and other workflows that require Playwright to access localhost in GitHub Actions.

Warning

Firewall rules blocked me from connecting to one or more addresses (expand for details)

I tried to connect to the following addresses, but was blocked by firewall rules:

  • https://api.github.com/user
    • Triggering command: /usr/bin/gh gh api user --jq .login 08431cddfb8368fd83d5badbf9bfd GO111MODULE ache/go/1.25.0/x64/bin/go GOINSECURE GOMOD GOMODCACHE go env tags/v6 GO111MODULE ps GOINSECURE GOMOD GOMODCACHE ps (http block)
    • Triggering command: /usr/bin/gh gh api user --jq .login -json 98934cb7db3cf861b1c3912a44c25fe853f52e101adce49a243 ache/go/1.25.0/x64/pkg/tool/linux_amd64/cgo 98934cb7db3cf861git (http block)
    • Triggering command: /usr/bin/gh gh api user --jq .login /run/containerd/io.containerd.runtime.v2.task/moby/412f2133922a5790ab7dae82709d4a5952fe5abddb2578c8a19a9a4c54e16330/init.pid 412f2133922a5790ab7dae82709d4a5952fe5abddb2578c8a19a9a4c54e16330 605619/b123=&gt; a5952fe5abddb2578c8a19a9a4c54e16330/log.json bnext/gh-aw/cmd/aw -d/gh-aw go env s -d/gh-aw /opt/hostedtoolcache/go/1.25.0/xjson GOINSECURE GOMOD GOMODCACHE 605619/b123/impo/var/run/docker/runtime-runc/moby (http block)

If you need me to access, download, or install something from one of these locations, you can either:

Original prompt

This section details on the original issue you should resolve

<issue_title>🔍 Multi-Device Docs Testing Report - Technical Limitation Discovered</issue_title>
<issue_description>## Test Summary

Triggered by:@mnkiefer
Workflow Run:#20001915806
Test Date: 2025-12-07
Documentation Site: Built successfully at /docs/dist


Results Overview

Testing Status: Unable to complete browser-based testing
🔴 Critical Issue Identified: Playwright browser sandbox prevents localhost connections


Critical Issues

🔴 Playwright Network Isolation in GitHub Actions

Issue: The Playwright MCP server running in this GitHub Actions environment operates in a sandboxed browser that blocks connections to localhost and 127.0.0.1.

Impact:

  • Cannot perform visual regression testing
  • Cannot test responsive layouts across devices
  • Cannot validate accessibility with live browser interactions
  • Cannot capture screenshots of actual rendered pages

Technical Details:

Error: page.goto: net::ERR_CONNECTION_REFUSED at (redacted)

The documentation site builds successfully and serves correctly:

  • ✅ Build completed in ~16 seconds
  • ✅ Generated 60 pages with 98 workflow examples
  • ✅ Preview server starts on port 4321
  • ✅ Server responds to curl requests
  • ❌ Playwright browser cannot connect due to sandbox restrictions

Recommendations

Option 1: Deploy to Temporary Hosting

Instead of testing against localhost, deploy the built site to a publicly accessible URL:

  • Use GitHub Pages preview deployment
  • Use Netlify/Vercel deploy previews
  • Use ngrok or similar tunneling service

Option 2: Alternative Testing Approach

Use static analysis tools that don't require browser rendering:

  • HTML validation: Use html-validate or W3C validator
  • Accessibility: Use pa11y-ci or axe-core CLI
  • Link checking: Use linkinator or broken-link-checker
  • Responsive analysis: Parse CSS and check viewport rules

Option 3: Docker-based Testing

Run Playwright in a Docker container with proper network configuration:

- name: Run Playwright testsrun: | docker run --network=host -v $PWD:/work -w /work \ mcr.microsoft.com/playwright:latest \ npm run test:e2e

Option 4: Use GitHub Actions Service Containers

Configure the workflow to use service containers that share network access:

jobs:
test:
services:
docs:
image: nginx:alpineports:
- 4321:80

What Was Tested

Build Process

  • Documentation builds successfully
  • All 98 lab workflows generated correctly
  • Mermaid diagrams processed (10 in architecture docs)
  • Pagefind search index created
  • Sitemap generated
  • All internal links validated

Server Configuration

  • Preview server starts correctly
  • Serves at /gh-aw/ base path
  • Returns valid HTML
  • Includes proper meta tags and SEO

Next Steps

To enable comprehensive multi-device testing for the documentation site, one of the following approaches should be implemented:

  1. Short-term: Use static analysis tools that don't require browser rendering
  2. Medium-term: Deploy to a preview URL before testing
  3. Long-term: Configure proper Docker/service container setup for full Playwright testing

Would you like me to implement any of these alternative testing approaches?


Build Artifacts

The documentation was successfully built to /home/runner/work/gh-aw/gh-aw/docs/dist with:

  • 60 HTML pages
  • 4,364 indexed words
  • 1 language (English)
  • All internal links validated
  • Sitemap and search index generated

AI generated by Multi-Device Docs Tester

Comments on the Issue (you are @copilot in this section)

@pelikhan /q the playwright default domain set should allow localhost 127.0.0.1

✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

CopilotAIand others added 2 commits December 14, 2025 20:31
Co-authored-by: mnkiefer <8320933+mnkiefer@users.noreply.github.com>
Co-authored-by: mnkiefer <8320933+mnkiefer@users.noreply.github.com>
CopilotAI changed the title [WIP] Fix Playwright network isolation issue in GitHub ActionsAdd --allowed-origins flag for Playwright browser navigation to localhostDec 14, 2025
CopilotAI requested a review from mnkieferDecember 14, 2025 20:50
@pelikhan
pelikhan marked this pull request as ready for review December 14, 2025 23:04
@pelikhan
pelikhan merged commit 017e1fb into mainDec 15, 2025
125 checks passed
@pelikhan
pelikhan deleted the copilot/fix-playwright-network-issue branch December 15, 2025 01:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

🔍 Multi-Device Docs Testing Report - Technical Limitation Discovered

3 participants

@pelikhan@mnkiefer
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add --allowed-origins flag for Playwright browser navigation to localhost - #6453

Merged
pelikhan merged 3 commits into
mainfrom
copilot/fix-playwright-network-issue
Dec 15, 2025
Merged

Add --allowed-origins flag for Playwright browser navigation to localhost#6453
pelikhan merged 3 commits into
mainfrom
copilot/fix-playwright-network-issue

Conversation

CopilotAI commented Dec 14, 2025

Copy link
Copy Markdown
Contributor

Playwright browser in GitHub Actions could not navigate to localhost URLs despite localhost being in the allowed domains. The Playwright MCP server uses two separate flags: --allowed-hosts controls MCP server CORS, while --allowed-origins controls browser navigation. We were only setting the former.

Changes:

  • Added --allowed-origins flag to Playwright MCP configurations for all engines (Claude, Copilot, Codex)
  • Both flags now receive the same domain list: localhost, localhost:*, 127.0.0.1, 127.0.0.1:*
  • Updated rendering functions in pkg/workflow/mcp-config.go and pkg/workflow/mcp_renderer.go
  • Extracted domain string formatting to reduce duplication
  • Updated test assertions to verify both flags are present

Example output:

"playwright": {"command": "docker","args": ["run", "-i", "--rm", "--init","mcr.microsoft.com/playwright/mcp","--output-dir", "/tmp/gh-aw/mcp-logs/playwright","--allowed-hosts", "localhost;localhost:*;127.0.0.1;127.0.0.1:*","--allowed-origins", "localhost;localhost:*;127.0.0.1;127.0.0.1:*"]}

This enables documentation testing, local server testing, and other workflows that require Playwright to access localhost in GitHub Actions.

Warning

Firewall rules blocked me from connecting to one or more addresses (expand for details)

I tried to connect to the following addresses, but was blocked by firewall rules:

  • https://api.github.com/user
    • Triggering command: /usr/bin/gh gh api user --jq .login 08431cddfb8368fd83d5badbf9bfd GO111MODULE ache/go/1.25.0/x64/bin/go GOINSECURE GOMOD GOMODCACHE go env tags/v6 GO111MODULE ps GOINSECURE GOMOD GOMODCACHE ps (http block)
    • Triggering command: /usr/bin/gh gh api user --jq .login -json 98934cb7db3cf861b1c3912a44c25fe853f52e101adce49a243 ache/go/1.25.0/x64/pkg/tool/linux_amd64/cgo 98934cb7db3cf861git (http block)
    • Triggering command: /usr/bin/gh gh api user --jq .login /run/containerd/io.containerd.runtime.v2.task/moby/412f2133922a5790ab7dae82709d4a5952fe5abddb2578c8a19a9a4c54e16330/init.pid 412f2133922a5790ab7dae82709d4a5952fe5abddb2578c8a19a9a4c54e16330 605619/b123=&gt; a5952fe5abddb2578c8a19a9a4c54e16330/log.json bnext/gh-aw/cmd/aw -d/gh-aw go env s -d/gh-aw /opt/hostedtoolcache/go/1.25.0/xjson GOINSECURE GOMOD GOMODCACHE 605619/b123/impo/var/run/docker/runtime-runc/moby (http block)

If you need me to access, download, or install something from one of these locations, you can either:

Original prompt

This section details on the original issue you should resolve

<issue_title>🔍 Multi-Device Docs Testing Report - Technical Limitation Discovered</issue_title>
<issue_description>## Test Summary

Triggered by:@mnkiefer
Workflow Run:#20001915806
Test Date: 2025-12-07
Documentation Site: Built successfully at /docs/dist


Results Overview

Testing Status: Unable to complete browser-based testing
🔴 Critical Issue Identified: Playwright browser sandbox prevents localhost connections


Critical Issues

🔴 Playwright Network Isolation in GitHub Actions

Issue: The Playwright MCP server running in this GitHub Actions environment operates in a sandboxed browser that blocks connections to localhost and 127.0.0.1.

Impact:

  • Cannot perform visual regression testing
  • Cannot test responsive layouts across devices
  • Cannot validate accessibility with live browser interactions
  • Cannot capture screenshots of actual rendered pages

Technical Details:

Error: page.goto: net::ERR_CONNECTION_REFUSED at (redacted)

The documentation site builds successfully and serves correctly:

  • ✅ Build completed in ~16 seconds
  • ✅ Generated 60 pages with 98 workflow examples
  • ✅ Preview server starts on port 4321
  • ✅ Server responds to curl requests
  • ❌ Playwright browser cannot connect due to sandbox restrictions

Recommendations

Option 1: Deploy to Temporary Hosting

Instead of testing against localhost, deploy the built site to a publicly accessible URL:

  • Use GitHub Pages preview deployment
  • Use Netlify/Vercel deploy previews
  • Use ngrok or similar tunneling service

Option 2: Alternative Testing Approach

Use static analysis tools that don't require browser rendering:

  • HTML validation: Use html-validate or W3C validator
  • Accessibility: Use pa11y-ci or axe-core CLI
  • Link checking: Use linkinator or broken-link-checker
  • Responsive analysis: Parse CSS and check viewport rules

Option 3: Docker-based Testing

Run Playwright in a Docker container with proper network configuration:

- name: Run Playwright testsrun: | docker run --network=host -v $PWD:/work -w /work \ mcr.microsoft.com/playwright:latest \ npm run test:e2e

Option 4: Use GitHub Actions Service Containers

Configure the workflow to use service containers that share network access:

jobs:
test:
services:
docs:
image: nginx:alpineports:
- 4321:80

What Was Tested

Build Process

  • Documentation builds successfully
  • All 98 lab workflows generated correctly
  • Mermaid diagrams processed (10 in architecture docs)
  • Pagefind search index created
  • Sitemap generated
  • All internal links validated

Server Configuration

  • Preview server starts correctly
  • Serves at /gh-aw/ base path
  • Returns valid HTML
  • Includes proper meta tags and SEO

Next Steps

To enable comprehensive multi-device testing for the documentation site, one of the following approaches should be implemented:

  1. Short-term: Use static analysis tools that don't require browser rendering
  2. Medium-term: Deploy to a preview URL before testing
  3. Long-term: Configure proper Docker/service container setup for full Playwright testing

Would you like me to implement any of these alternative testing approaches?


Build Artifacts

The documentation was successfully built to /home/runner/work/gh-aw/gh-aw/docs/dist with:

  • 60 HTML pages
  • 4,364 indexed words
  • 1 language (English)
  • All internal links validated
  • Sitemap and search index generated

AI generated by Multi-Device Docs Tester

Comments on the Issue (you are @copilot in this section)

@pelikhan /q the playwright default domain set should allow localhost 127.0.0.1

✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

CopilotAIand others added 2 commits December 14, 2025 20:31
Co-authored-by: mnkiefer <8320933+mnkiefer@users.noreply.github.com>
Co-authored-by: mnkiefer <8320933+mnkiefer@users.noreply.github.com>
CopilotAI changed the title [WIP] Fix Playwright network isolation issue in GitHub ActionsAdd --allowed-origins flag for Playwright browser navigation to localhostDec 14, 2025
CopilotAI requested a review from mnkieferDecember 14, 2025 20:50
@pelikhan
pelikhan marked this pull request as ready for review December 14, 2025 23:04
@pelikhan
pelikhan merged commit 017e1fb into mainDec 15, 2025
125 checks passed
@pelikhan
pelikhan deleted the copilot/fix-playwright-network-issue branch December 15, 2025 01:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

🔍 Multi-Device Docs Testing Report - Technical Limitation Discovered

3 participants

@pelikhan@mnkiefer
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Add --allowed-origins flag for Playwright browser navigation to localhost - #6453

Merged
pelikhan merged 3 commits into
mainfrom
copilot/fix-playwright-network-issue
Dec 15, 2025
Merged

Add --allowed-origins flag for Playwright browser navigation to localhost#6453
pelikhan merged 3 commits into
mainfrom
copilot/fix-playwright-network-issue

Conversation

CopilotAI commented Dec 14, 2025

Copy link
Copy Markdown
Contributor

Playwright browser in GitHub Actions could not navigate to localhost URLs despite localhost being in the allowed domains. The Playwright MCP server uses two separate flags: --allowed-hosts controls MCP server CORS, while --allowed-origins controls browser navigation. We were only setting the former.

Changes:

  • Added --allowed-origins flag to Playwright MCP configurations for all engines (Claude, Copilot, Codex)
  • Both flags now receive the same domain list: localhost, localhost:*, 127.0.0.1, 127.0.0.1:*
  • Updated rendering functions in pkg/workflow/mcp-config.go and pkg/workflow/mcp_renderer.go
  • Extracted domain string formatting to reduce duplication
  • Updated test assertions to verify both flags are present

Example output:

"playwright": {"command": "docker","args": ["run", "-i", "--rm", "--init","mcr.microsoft.com/playwright/mcp","--output-dir", "/tmp/gh-aw/mcp-logs/playwright","--allowed-hosts", "localhost;localhost:*;127.0.0.1;127.0.0.1:*","--allowed-origins", "localhost;localhost:*;127.0.0.1;127.0.0.1:*"]}

This enables documentation testing, local server testing, and other workflows that require Playwright to access localhost in GitHub Actions.

Warning

Firewall rules blocked me from connecting to one or more addresses (expand for details)

I tried to connect to the following addresses, but was blocked by firewall rules:

  • https://api.github.com/user
    • Triggering command: /usr/bin/gh gh api user --jq .login 08431cddfb8368fd83d5badbf9bfd GO111MODULE ache/go/1.25.0/x64/bin/go GOINSECURE GOMOD GOMODCACHE go env tags/v6 GO111MODULE ps GOINSECURE GOMOD GOMODCACHE ps (http block)
    • Triggering command: /usr/bin/gh gh api user --jq .login -json 98934cb7db3cf861b1c3912a44c25fe853f52e101adce49a243 ache/go/1.25.0/x64/pkg/tool/linux_amd64/cgo 98934cb7db3cf861git (http block)
    • Triggering command: /usr/bin/gh gh api user --jq .login /run/containerd/io.containerd.runtime.v2.task/moby/412f2133922a5790ab7dae82709d4a5952fe5abddb2578c8a19a9a4c54e16330/init.pid 412f2133922a5790ab7dae82709d4a5952fe5abddb2578c8a19a9a4c54e16330 605619/b123=&gt; a5952fe5abddb2578c8a19a9a4c54e16330/log.json bnext/gh-aw/cmd/aw -d/gh-aw go env s -d/gh-aw /opt/hostedtoolcache/go/1.25.0/xjson GOINSECURE GOMOD GOMODCACHE 605619/b123/impo/var/run/docker/runtime-runc/moby (http block)

If you need me to access, download, or install something from one of these locations, you can either:

Original prompt

This section details on the original issue you should resolve

<issue_title>🔍 Multi-Device Docs Testing Report - Technical Limitation Discovered</issue_title>
<issue_description>## Test Summary

Triggered by:@mnkiefer
Workflow Run:#20001915806
Test Date: 2025-12-07
Documentation Site: Built successfully at /docs/dist


Results Overview

Testing Status: Unable to complete browser-based testing
🔴 Critical Issue Identified: Playwright browser sandbox prevents localhost connections


Critical Issues

🔴 Playwright Network Isolation in GitHub Actions

Issue: The Playwright MCP server running in this GitHub Actions environment operates in a sandboxed browser that blocks connections to localhost and 127.0.0.1.

Impact:

  • Cannot perform visual regression testing
  • Cannot test responsive layouts across devices
  • Cannot validate accessibility with live browser interactions
  • Cannot capture screenshots of actual rendered pages

Technical Details:

Error: page.goto: net::ERR_CONNECTION_REFUSED at (redacted)

The documentation site builds successfully and serves correctly:

  • ✅ Build completed in ~16 seconds
  • ✅ Generated 60 pages with 98 workflow examples
  • ✅ Preview server starts on port 4321
  • ✅ Server responds to curl requests
  • ❌ Playwright browser cannot connect due to sandbox restrictions

Recommendations

Option 1: Deploy to Temporary Hosting

Instead of testing against localhost, deploy the built site to a publicly accessible URL:

  • Use GitHub Pages preview deployment
  • Use Netlify/Vercel deploy previews
  • Use ngrok or similar tunneling service

Option 2: Alternative Testing Approach

Use static analysis tools that don't require browser rendering:

  • HTML validation: Use html-validate or W3C validator
  • Accessibility: Use pa11y-ci or axe-core CLI
  • Link checking: Use linkinator or broken-link-checker
  • Responsive analysis: Parse CSS and check viewport rules

Option 3: Docker-based Testing

Run Playwright in a Docker container with proper network configuration:

- name: Run Playwright testsrun: | docker run --network=host -v $PWD:/work -w /work \ mcr.microsoft.com/playwright:latest \ npm run test:e2e

Option 4: Use GitHub Actions Service Containers

Configure the workflow to use service containers that share network access:

jobs:
test:
services:
docs:
image: nginx:alpineports:
- 4321:80

What Was Tested

Build Process

  • Documentation builds successfully
  • All 98 lab workflows generated correctly
  • Mermaid diagrams processed (10 in architecture docs)
  • Pagefind search index created
  • Sitemap generated
  • All internal links validated

Server Configuration

  • Preview server starts correctly
  • Serves at /gh-aw/ base path
  • Returns valid HTML
  • Includes proper meta tags and SEO

Next Steps

To enable comprehensive multi-device testing for the documentation site, one of the following approaches should be implemented:

  1. Short-term: Use static analysis tools that don't require browser rendering
  2. Medium-term: Deploy to a preview URL before testing
  3. Long-term: Configure proper Docker/service container setup for full Playwright testing

Would you like me to implement any of these alternative testing approaches?


Build Artifacts

The documentation was successfully built to /home/runner/work/gh-aw/gh-aw/docs/dist with:

  • 60 HTML pages
  • 4,364 indexed words
  • 1 language (English)
  • All internal links validated
  • Sitemap and search index generated

AI generated by Multi-Device Docs Tester

Comments on the Issue (you are @copilot in this section)

@pelikhan /q the playwright default domain set should allow localhost 127.0.0.1

✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

CopilotAIand others added 2 commits December 14, 2025 20:31
Co-authored-by: mnkiefer <8320933+mnkiefer@users.noreply.github.com>
Co-authored-by: mnkiefer <8320933+mnkiefer@users.noreply.github.com>
CopilotAI changed the title [WIP] Fix Playwright network isolation issue in GitHub ActionsAdd --allowed-origins flag for Playwright browser navigation to localhostDec 14, 2025
CopilotAI requested a review from mnkieferDecember 14, 2025 20:50
@pelikhan
pelikhan marked this pull request as ready for review December 14, 2025 23:04
@pelikhan
pelikhan merged commit 017e1fb into mainDec 15, 2025
125 checks passed
@pelikhan
pelikhan deleted the copilot/fix-playwright-network-issue branch December 15, 2025 01:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

🔍 Multi-Device Docs Testing Report - Technical Limitation Discovered

3 participants

@pelikhan@mnkiefer