Skip to content

v1.9.4 — Hydration wait + retry on login rejection

Choose a tag to compare

@Gonzalez8 Gonzalez8 released this 22 May 18:17
· 38 commits to main since this release

Login was getting rejected with lite-variant bodies

After the captcha-relay work, production hit a new failure mode:

Form usable despite small body (7183 bytes) ...
Login button clicked
... 15s later ...
CheckJCLoginRejected: still at /login after submit

Diagnosis: when CheckJC serves the lite variant of /login the visible
username and password inputs become interactable before Stencil has
finished hydrating the form's hidden CSRF token. We click the
submit button right away → the POST goes with an empty token → the
server silently bounces us back to /login → we surface
CheckJCLoginRejected.

This is the same <input type="hidden" name="token"> documented in
docs/migrations/checkjc-v7.4.md; it's just that on lite bodies it
isn't there yet when our code reads the DOM.

Fix

Two layers in CheckJCClient.login():

  1. Extra wait on lite bodies before submit. If body_size < _LITE_BODY_THRESHOLD (~20KB), wait 3s after locating the form so
    Stencil can populate the hidden token. Normal-sized bodies skip
    this and behave as before.

  2. Retry once on login rejection. If we still end up on /login
    (no IP-block banner), reload the form and try a second time with
    a 6s warm-up. Only after the second rejection do we raise
    CheckJCLoginRejected. IP blocks still short-circuit immediately.

Image

ghcr.io/gonzalez8/checktime:1.9.4 / :1.9 / :latest

Upgrade

sed -i 's/^CHECK_TIME_VERSION=.*/CHECK_TIME_VERSION=1.9.4/' stack.env
docker compose pull app
docker compose up -d app

Log lines to look for

Best case:

Form usable despite small body (7183 bytes) ...
Body is small (7183 bytes); waiting 3000ms extra for Stencil to hydrate ...
Login button clicked for ... (submit attempt 1/2)
Login successful for ... landed at /portal/employee/verification

Retry path:

Login submit rejected for ... on attempt 1, reloading and retrying
Body is small (...); waiting 6000ms extra ...
Login button clicked for ... (submit attempt 2/2)
Login successful ...

If you still see CheckJCLoginRejected after 2 attempts consistently,
the credentials are likely wrong or CheckJC has put a hard block on
the account — log in manually in a browser to confirm.