Scoped Injection Capabilities
There is currently no custom capability in BrowserStack that allows you to define a domain whitelist or blacklist to restrict the automatic injection of the axe-core library. When the accessibility capability is set to true, the platform attempts to inject the engine into every page loaded during the session.
Alternative Mechanisms for Domain-Specific Reports
To avoid noise from third-party domains or to prevent CSP conflicts on non-target pages, you should move from automatic injection to manual execution. By disabling the global accessibility capability, you can control exactly when and where the audit runs.
Implementation Strategy
- Disable Global Injection: Set the accessibility capability to
false in your configuration to prevent the platform from forcing axe-core into every frame.
- Manual Script Injection: Use your automation framework (Selenium, Playwright, Cypress) to inject the axe-core library only when the browser is on a target domain.
- Conditional Execution: Wrap your accessibility audit call in a conditional check to verify the current hostname before triggering the scan.
// Example logic for scoped execution
const currentDomain = await driver.executeScript("return window.location.hostname;");
const allowedDomains = ['myapp.com', 'staging.myapp.com'];
if (allowedDomains.includes(currentDomain)) {
// Trigger the axe-core audit here
const results = await driver.executeScript("return axe.run();");
console.log(results);
}
CSP Restrictions and Frame Injection
BrowserStack's automatic injection often attempts to bypass certain restrictions, but strict Content-Security-Policy (CSP) headers—specifically script-src—can still block the injection of the axe-core library.
When injection is limited to selected frames via manual scripts, the following behaviors occur:
- Same-Origin Frames: If the frame shares the same origin as the parent, the script can be injected and executed normally.
- Cross-Origin Frames: If the frame is on a different domain, browser security models (Same-Origin Policy) will prevent the parent session from injecting scripts into that frame unless the frame's own CSP explicitly allows it.
Verification Steps
To verify that your scoping is working and CSPs are being respected:
- Navigate to a non-target domain and check the browser console; the
axe object should be undefined.
- Navigate to a target domain and verify the
axe object is initialized.
- Check the browser console for
Refused to execute inline script errors, which indicate that the CSP is successfully blocking injection on restricted pages.
Diagnostic Detail Needed: Are you utilizing the BrowserStack SDK or a standalone WebDriver implementation? The method for injecting the manual script differs slightly between the two.