Earlier this week, automated login monitoring for GOM (GamersOfficialMarketing) alerted that mobile users were getting hit with a 403 Forbidden: Bot verification failed error during login, while web users authenticated cleanly.
Here is how I diagnosed and fixed the issue across our hybrid stack.
1. Diagnosing the Drop-off
I ran a quick network audit to rule out SSL or DNS issues:
- DNS & TLS: Handshakes and API resolution completed cleanly over mobile networks.
- Headers: Mobile clients sent valid headers and standard
User-Agentstrings.
Checking our Node.js auth logs revealed the real culprit: Turnstile token missing from request payload. I had recently enabled Cloudflare Turnstile on our web app to prevent credential-stuffing bots. Because the native mobile app was never wired to pass Turnstile tokens, the backend started blocking all mobile login attempts by default.
2. Building a WebView Bridge for Native Mobile
Because Turnstile relies on browser DOM execution, native React Native components cannot run the script directly.
I implemented an invisible verification bridge using react-native-webview:
- Hosted an HTML wrapper containing the Turnstile script.
- Configured Turnstile's
callbackto post the generated token string to React Native usingwindow.ReactNativeWebView.postMessage(token). - Wrapped the WebView inside the mobile login screen to generate challenge tokens before invoking the login API.
3. Fixing Domain & Origin Mismatches
Loading the WebView immediately threw Error 110200: Domain not authorized. Because mobile WebViews execute under about:blank or local file origins, Cloudflare's security policy rejected the request against our web sitekey setup.
The Fix:
- Dual Widgets: Created two separate Turnstile widgets in Cloudflare—one for Web (strict domain matching) and one for Mobile (custom hostname permissions).
- Dual Secrets on Backend: Updated the backend verification middleware to check incoming tokens against both secret keys (
WEB_SECRETandMOBILE_SECRET).
Outcome
Mobile login success rates returned to 100%, with bot protection running seamlessly across both web and native apps.
If you run React Native apps behind Cloudflare-protected endpoints, account for WebView origin requirements early. How do you handle bot verification challenges on mobile?
Source: r/BuildingGOM · by /u/gramerscial