Skip to content

Expose native HttpOnly cookie queries and fix packaged Windows startup - #51

Merged
shannah merged 3 commits into
webliteca:masterfrom
TIMER-err:feature/cookie-api
Sep 30, 2026
Merged

shannah merged 3 commits into
webliteca:masterfrom
TIMER-err:feature/cookie-api

Conversation

@TIMER-err

@TIMER-err TIMER-err commented Aug 24, 2026 •

Copy link
Copy Markdown

Summary

  • add WebViewComponent.getCookies(String) returning a CompletableFuture<String> on the Swing EDT
  • query the platform-native cookie store so HttpOnly cookies are included
  • return only cookies applicable to the requested URL in HTTP Cookie header syntax
  • support WKHTTPCookieStore on macOS, WebKitCookieManager on Linux, and ICoreWebView2CookieManager on Windows
  • support Linux offscreen WebViews and return explicit unsupported errors for offscreen backends on macOS/Windows
  • store Windows WebView2 data under a writable per-user %LOCALAPPDATA%\SwingWebView directory so packaged applications installed in Program Files start without elevation
  • preserve WEBVIEW2_USER_DATA_FOLDER overrides and fall back to the Windows temporary directory when Local AppData is unavailable
  • document credential-handling expectations, platform behavior, and the Windows user-data location

Validation

  • mvn -DskipTests=false -Dmaven.test.skip=false test
  • Linux native build
  • runtime Linux smoke test: an HTTP server supplied an HttpOnly cookie and getCookies() retrieved it successfully
  • Windows runtime smoke test using the Action-built JAR: WebView2 initialized under %LOCALAPPDATA%\SwingWebView, created EBWebView, and JavaScript evaluation returned "qplayer-webview2-ok"
  • all six CI native targets and the combined JAR built successfully: macOS x64/arm64, Linux x64/arm64, Windows x64/arm64

Cross-platform build: https://github.com/TIMER-err/swingwebview/actions/runs/32698087328

@TIMER-err
TIMER-err marked this pull request as draft August 24, 2026 06:18
@TIMER-err TIMER-err changed the title Expose native HttpOnly cookie queries Expose native HttpOnly cookie queries and fix packaged Windows startup Aug 24, 2026
@TIMER-err
TIMER-err marked this pull request as ready for review August 24, 2026 06:39
@TIMER-err

TIMER-err commented Sep 25, 2026 •

Copy link
Copy Markdown
Author

@shannah Could you review this PR?

@TIMER-err

Copy link
Copy Markdown
Author

ok, just ignore it.

@shannah

shannah commented Sep 27, 2026

Copy link
Copy Markdown
Collaborator

ignore it because it's not an issue? or ignore it because you got impatient with me responding?

@TIMER-err

TIMER-err commented Sep 28, 2026 •

Copy link
Copy Markdown
Author

you are right, it's not a issue. i apologize if i made you feel uncomfortable. but i didnt got impatient, if you dont want to merge it, just close it.

shannah added a commit that referenced this pull request Sep 30, 2026
Native getCookies API (from #51) with review fixes and per-platform demo
@shannah
shannah merged commit 33cd4ff into webliteca:master Sep 30, 2026

shannah commented Sep 30, 2026

Copy link
Copy Markdown
Collaborator

Thanks @TIMER-err, this is a great addition! Your commits have been merged into master as part of #61, with your authorship preserved, so I'm closing this PR.

Because this PR comes from a fork, the follow-up fixes went into #61 as a separate branch, on top of your commits:

  • macOS: the NSURL is now retained across the async getAllCookies: completion. The file is non-ARC C++, so the block wasn't retaining it, which caused a use-after-free.
  • macOS: host-only cookies (domain without a leading dot) now match only that exact host, so they're no longer returned for subdomains.
  • All platforms: results are ordered longest path first (RFC 6265 §5.4). WebView2's GetCookies doesn't sort by path, so Windows sorts explicitly.
  • Windows: if posting the query to the WebView2 thread fails, the future now completes with an error instead of hanging.
  • Windows: an existing, writable <exe>.WebView2 folder beside the executable keeps being used, so upgrading doesn't discard users' cookies and storage. Otherwise your %LOCALAPPDATA%\SwingWebView default applies.
  • Older native libraries now give a failed future instead of a synchronous UnsatisfiedLinkError.
  • New demo: demos/WebViewCookieDemo with run-{linux,mac}-cookie-demo.sh / run-windows-cookie-demo.bat. It passes on macOS, Windows and Linux.

Thanks again for the contribution!


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants