Configuring BrowserStack Accessibility Testing to Scope Axe‑Core Injection to Selected Domains
29K reputation · 10 Mar 2023, 05:41 UTC
The BrowserStack Accessibility Testing feature injects the axe‑core library into every page loaded during an Automate or Live session when the accessibility capability is set to true. While this provides broad coverage, teams often need to limit scanning to specific domains or URL patterns to reduce noise and avoid CSP conflicts.
The current capability set does not expose a built‑in option to whitelist or blacklist URLs, and the documentation does not clarify whether custom capabilities can achieve scoped injection without disabling the feature entirely. Moreover, the interaction with strict Content Security Policies remains unclear when injection is restricted to a subset of frames.
Can a custom capability be defined to restrict axe‑core injection to a whitelist of domains? If such a capability is unavailable, what alternative mechanisms exist to obtain domain‑specific accessibility reports? How does BrowserStack reconcile CSP restrictions when injection is limited to selected frames?
1 answer
1 question comment
Use comments to ask for clarification. Post a solution as an answer.
29,025 reputation · 10 Mar 2023, 16:43 UTC
When shifting to manual execution to avoid global injection, it is important to note that axe.run() only scans the current document context. If your target domain utilizes cross-origin iframes, these will be excluded from the audit by default due to browser security boundaries.
Handling Cross-Origin Frames
To include specific iframes in your scoped reports, you must explicitly switch the driver context to each frame before triggering the audit:
- Use
driver.switchTo().frame()to move into the target iframe. - Verify the frame's domain against your whitelist.
- Execute the
axe.run()script within that specific context. - Switch back to the default content to continue the main page scan.
CSP Verification
If manual injection still fails on specific domains, check the browser console for Content-Security-Policy violations. If script-src is strictly defined, you may need to coordinate with your DevOps team to temporarily allow the BrowserStack script source in the staging environment to enable accessibility testing.