Skip to content

Native getCookies API (from #51) with review fixes and per-platform demo - #61

Merged
shannah merged 5 commits into
masterfrom
claude/busy-lamport-flrtod
Sep 30, 2026
Merged

shannah merged 5 commits into
masterfrom
claude/busy-lamport-flrtod

Conversation

@shannah

@shannah shannah commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Builds on #51 (TIMER-err's getCookies + Windows WebView2 user-data folder). This branch contains that PR's commits plus review fixes. All changes went through Canvas 6 (/spdd-prompt-update → /spdd-generate, Operations 15/16).

Fixes on top of #51

  • macOS use-after-free: cocoa_get_cookies captured an autoreleased NSURL in a block. This file is compiled as non-ARC C++, so the block doesn't retain it, and getAllCookies: completes on a later run-loop pass. The URL is now retained before the call and released in the block.
  • macOS host-only cookies: a cookie domain without a leading dot now matches only that exact host, so it is no longer returned for subdomains.
  • Consistent ordering: results are longest path first (RFC 6265 §5.4) on every platform. macOS and Windows now sort explicitly; WebView2's GetCookies does not sort by path. Linux's libsoup already sorts.
  • Windows hang: if PostThreadMessage to the WebView2 worker fails, the query completes with an error instead of leaving the future pending forever.
  • Windows upgrade data loss: an existing, writable <exe dir>\<exe>.WebView2 folder (WebView2's old default) keeps being used. Only when it's absent or not writable does the new %LOCALAPPDATA%\SwingWebView\… folder apply. The legacy folder is never created.
  • Older native library: getCookies returns a future failed with UnsupportedOperationException instead of throwing UnsatisfiedLinkError synchronously.

Test demo

demos/WebViewCookieDemo plus run-linux-cookie-demo.sh, run-mac-cookie-demo.sh and run-windows-cookie-demo.bat. COOKIEDEMO_AUTO=1 runs the checks and exits 0 on pass. A loopback HTTP server sets HttpOnly, script-visible, Path=/private and Secure cookies. The demo then checks:

  • HttpOnly is returned by getCookies but hidden from document.cookie
  • the /private cookie is scoped by path and listed first
  • Secure-over-http matches what the engine exposes to the page (WebView2 treats http://localhost as a secure context)
  • host-only cookies are excluded for sub.localhost
  • an unrelated host returns an empty string
  • the future completes on the EDT

Validation

  • The cookie demo passes in auto mode on macOS, Windows and Linux (Linux uses the lightweight component).
  • CI native builds pass on macOS x64/arm64, Windows x64/arm64 and linux_arm64; linux_64 was still running when this was written.
  • mvn test passes.

🤖 Generated with Claude Code

https://claude.ai/code/session_01AM8KH9Z4xSuQfXF5jmeYnA

TIMER-err and others added 5 commits August 24, 2026 12:05
Canvas 6 Operations 15/16 updated and regenerated:
- macOS: retain the NSURL across the async getAllCookies: completion
  (non-ARC blocks don't retain captured ids; it was a use-after-free),
  treat dot-less cookie domains as host-only, and order matches longest
  path first.
- Windows: complete the cookie query with an error when posting to the
  WebView2 worker fails instead of hanging the future; keep using an
  existing writable <exe>.WebView2 folder beside the executable so
  upgrading does not discard existing browser data.
- Java: an older native library without the cookie entry points yields
  a future failed with UnsupportedOperationException rather than a
  synchronous UnsatisfiedLinkError.
- Add demos/WebViewCookieDemo with run-{linux,mac}-cookie-demo.sh and
  run-windows-cookie-demo.bat (COOKIEDEMO_AUTO=1 runs the checks).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AM8KH9Z4xSuQfXF5jmeYnA
Canvas 6 Operation 16 updated and regenerated:
- Windows: GetCookies does not order by path, so stable-sort matches by
  descending path length like macOS (Linux's libsoup already does).
- Demo: WebView2 treats http://localhost as a secure context and sends
  Secure cookies over it; the Secure-over-http check now defers to what
  the engine exposes to the page (INFO instead of FAIL). The ordering
  check now requires the /private cookie to precede every Path=/ cookie.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AM8KH9Z4xSuQfXF5jmeYnA
@shannah
shannah marked this pull request as ready for review September 30, 2026 15:09
@shannah
shannah merged commit c1518df into master Sep 30, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants