Okta Browser Plugin — dynamic takeover origin

Authorized security research (Bugcrowd submission) · sessions are per-visitor; the /.well-known/okta-organization response is generated for the org chosen below.

1 · Pre-populate — probe the visitor's extension for its current Okta tenant (loads a hidden /home/plugin/ classification pass and reads the markers the plugin injects).
idle
Detected tenant:
2 · Override — set the org the dynamic /.well-known/okta-organization mirrors for this session (arbitrary injection).
Session org: · well-known probes: 0
3 · Plant — visit /home/plugin/ with the Okta Browser Plugin installed (or use the button to open it).
Extension DOM markerMeaningStatus
okta-plugin-message-channel-availablecontent script present (baseline)
okta-plugin-versionpage classified as org UserHome
okta-plugin-version-from-headerscustomDomain mapping applied (trust signal)
sites-loadedorg tasks ran (tabs/sites fetched)
plugin-contextinterstitial context JSON (domain/newDomain)
okta-plugin-consent-required-from-headersaccount consent banner triggered
4 · Undo — server reset + the extension's own storage reset (/plugin/resetstorage on the planted org wipes DOMAINS, TRUSTED_OKTA_DOMAIN_LIST and the account allow-list).

Authorized testing only — run against your own orgs and your own browser profiles. Signals: