cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
suryakasturi
New member
Status: New idea

Is your feature request related to a problem? Please describe.

Web servers currently have no reliable way to determine whether a network request originated from a genuine user interaction or from software automation.

Browsers already distinguish trusted user-generated events from script-generated events internally (for example, Event.isTrusted). However, this provenance is lost as execution flows from a trusted input event through JavaScript and eventually to a network request.

For example:

physical click → trusted browser event → event handler → fetch() → HTTP request

At the server, the resulting request is indistinguishable from a fetch() initiated entirely by automation.

This is becoming increasingly relevant as autonomous browser agents interact with websites on behalf of users. Websites may want to distinguish direct user interaction, user-authorized automation, and unrelated automated traffic without relying solely on behavioral bot detection or CAPTCHAs.

Describe the solution you'd like

I would like Firefox to expose a privacy-preserving mechanism that allows a server to verify that a network request was causally associated with a recent trusted user interaction.

Conceptually, Firefox could propagate an internal provenance marker from a trusted input event through the execution that it triggers:

trusted input → browser event → JavaScript execution → network request

For eligible requests, Firefox could provide a cryptographically verifiable attestation indicating that the request originated from, or was causally associated with, a trusted user interaction.

The attestation should ideally be origin-bound, short-lived, non-transferable between origins, and designed to avoid exposing identifying information about the user or device.

The exact API does not need to expose the underlying keyboard, mouse, touch, or accessibility event. The important property is allowing the receiving origin to verify the provenance class of the request.

Additional context

This is not intended as proof that a user is human, nor as a replacement for authentication. A trusted interaction could still occur in a session subsequently controlled by automation.

The narrower goal is preserving information Firefox already possesses about trusted user interaction across the boundary where it is currently lost.

There are several open questions that would need careful consideration:

How far should causality propagate from a trusted event?

Should one interaction authorize one request or a bounded group of requests required to fulfill the interaction?

How should accessibility tools and other legitimate software-generated input be represented?

How can the mechanism avoid becoming a fingerprinting or cross-site tracking primitive?

Should provenance distinguish direct interaction from explicitly user-delegated automation?

What cryptographic or device-attestation mechanism, if any, should make the assertion verifiable by the server?

1 Comment
Status changed to: New idea
Jon
Community Manager
Community Manager

Thanks for submitting an idea to the Mozilla Connect community! Your idea is now open to votes (aka kudos) and comments.