#104 · Smarter, More Reliable Browser Authentication
We’ve just released a set of improvements that make browser-based authentication flows more powerful, more reliable, and easier to configure. Here’s what’s new:
1. Automatic API token extraction during authentication¶
Our browser agent authentication got even more powerful. This preset uses an AI Agent to automatically perform the actions to log you in with the provided credentials.
It is now capable of automatically extracting API tokens from API requests made during the authentication process. This means your scans can kick off with the right tokens without any extra steps.
You can learn more about Browser Agent authentication and how to set it up in Escape's documentation.
2. Smarter logged-in detection with logged_in_detector_text¶
You can now use the logged_in_detector_text field in both Browser Agent and Browser Actions presets.
This configuration option lets the scanner know to wait for a specific piece of visible text that only appears after a successful login, ensuring that your authentication is reliable before scanning begins.
Learn how to set it up
3. New wait text step in Browser Actions Authentication preset¶
We’ve added a new wait_text action to the Browser Actions Authentication preset, allowing you to explicitly wait for certain text to appear on the page before moving on to the next step.
Use it to:
- Wait for the page to finish loading
- Confirm that the form is ready before filling it
It's pratical if one page is slow and you want to wait before filling a field. All of these have configurable timeouts in seconds.
Here's an example for both wait text and logged_in_detector_text presets:
presets:
- type: browser_actions
users:
- username: piedpiper@escape.tech
actions:
- action: fill
locator: input[name='username']
value: piedpiper@escape.tech
auto_submit: true
- action: wait_text
value: Forgot password
timeout: 15
- action: fill
locator: input[name='password']
value: xxxx
auto_submit: true
login_url: https://app.staging.escape.tech
logged_in_detector_text: 'Connected Integrations'
logged_in_detector_timeout: 1
- type: browser_agent
users:
- username: piedpiper@escape.tech
password: xxxx
login_url: https://app.staging.escape.tech
logged_in_detector_text: 'Connected Integrations'
logged_in_detector_timeout: 15
4. Fewer CAPTCHAs, smoother logins¶
We’ve improved the default user-agent used during authentication to make it more stealthy and less likely to trigger bot protection systems. That means fewer CAPTCHAs and faster, more reliable logins.
These updates make it easier than ever to build robust, reliable browser-based authentication flows in Escape DAST!