FAQ
Why can't I see the bot_client.js be injected into the response page for Biometric Based Detection?
Please check from two aspects:
1) Double check if the request matches the rule or not.
2) Be aware that if the client is considered as not a bot, its good client status will be kept for 30 minutes. So FortiWeb won’t do biometric based checking to this client within 30 minutes.