Skip to content

#104 · Smarter, More Reliable Browser Authentication

We’ve just released a set of improvements that make browser-based authentication flows more powerful, more reliable, and easier to configure. Here’s what’s new:

1. Automatic API token extraction during authentication

Our browser agent authentication got even more powerful. This preset uses an AI Agent to automatically perform the actions to log you in with the provided credentials.

It is now capable of automatically extracting API tokens from API requests made during the authentication process. This means your scans can kick off with the right tokens without any extra steps.

You can learn more about Browser Agent authentication and how to set it up in Escape's documentation.

2. Smarter logged-in detection with logged_in_detector_text

You can now use the logged_in_detector_text field in both Browser Agent and Browser Actions presets.

This configuration option lets the scanner know to wait for a specific piece of visible text that only appears after a successful login, ensuring that your authentication is reliable before scanning begins.

Learn how to set it up

3. New wait text step in Browser Actions Authentication preset

We’ve added a new wait_text action to the Browser Actions Authentication preset, allowing you to explicitly wait for certain text to appear on the page before moving on to the next step.

Use it to:

  • Wait for the page to finish loading
  • Confirm that the form is ready before filling it

It's pratical if one page is slow and you want to wait before filling a field. All of these have configurable timeouts in seconds.

Here's an example for both wait text and logged_in_detector_text presets:

presets:
  - type: browser_actions
    users:
      - username: piedpiper@escape.tech
        actions:
          - action: fill
            locator: input[name='username']
            value: piedpiper@escape.tech
            auto_submit: true
          - action: wait_text
            value: Forgot password
            timeout: 15
          - action: fill
            locator: input[name='password']
            value: xxxx
            auto_submit: true
    login_url: https://app.staging.escape.tech
    logged_in_detector_text: 'Connected Integrations'
    logged_in_detector_timeout: 1
  - type: browser_agent
    users:
      - username: piedpiper@escape.tech
        password: xxxx
    login_url: https://app.staging.escape.tech
    logged_in_detector_text: 'Connected Integrations'
    logged_in_detector_timeout: 15

4. Fewer CAPTCHAs, smoother logins

We’ve improved the default user-agent used during authentication to make it more stealthy and less likely to trigger bot protection systems. That means fewer CAPTCHAs and faster, more reliable logins.

These updates make it easier than ever to build robust, reliable browser-based authentication flows in Escape DAST!