cf_clearance is bound to the exact UA that earns it, but three surfaces
touched one cookie with three different UAs: the curl_cffi driver
(impersonate=chrome -> macOS Chrome/146), the headless refresh
(Windows Chrome/131), and the interactive login (Playwright native,
Windows Chrome/148). The driver always replayed clearance under a UA no
browser had earned it with, so Cloudflare distrusted it and gated every
turn behind a Turnstile -- surfacing as hourly clearance-expired churn
once that gate became fatal.
Collapse all three onto one string (copilot/useragent.py):
- driver pins a stable curl_cffi TLS profile (chrome146) and overrides
the UA + client hints to Windows Chrome/148.
- both browser launches (headless and visible) advertise the same UA,
so clearance earned by either is reusable by the driver.
Standardize on 148 (Playwright's bundled Chromium) so the browser UA
override does not contradict its native Sec-CH-UA hint. Re-auth path is
unchanged -- it now refreshes without degrading clearance.