Native getCookies API (from #51) with review fixes and per-platform demo - #61
Merged
Merged
Conversation
Canvas 6 Operations 15/16 updated and regenerated:
- macOS: retain the NSURL across the async getAllCookies: completion
(non-ARC blocks don't retain captured ids; it was a use-after-free),
treat dot-less cookie domains as host-only, and order matches longest
path first.
- Windows: complete the cookie query with an error when posting to the
WebView2 worker fails instead of hanging the future; keep using an
existing writable <exe>.WebView2 folder beside the executable so
upgrading does not discard existing browser data.
- Java: an older native library without the cookie entry points yields
a future failed with UnsupportedOperationException rather than a
synchronous UnsatisfiedLinkError.
- Add demos/WebViewCookieDemo with run-{linux,mac}-cookie-demo.sh and
run-windows-cookie-demo.bat (COOKIEDEMO_AUTO=1 runs the checks).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AM8KH9Z4xSuQfXF5jmeYnA
Canvas 6 Operation 16 updated and regenerated: - Windows: GetCookies does not order by path, so stable-sort matches by descending path length like macOS (Linux's libsoup already does). - Demo: WebView2 treats http://localhost as a secure context and sends Secure cookies over it; the Secure-over-http check now defers to what the engine exposes to the page (INFO instead of FAIL). The ordering check now requires the /private cookie to precede every Path=/ cookie. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AM8KH9Z4xSuQfXF5jmeYnA
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Builds on #51 (TIMER-err's
getCookies+ Windows WebView2 user-data folder). This branch contains that PR's commits plus review fixes. All changes went through Canvas 6 (/spdd-prompt-update→/spdd-generate, Operations 15/16).Fixes on top of #51
cocoa_get_cookiescaptured an autoreleasedNSURLin a block. This file is compiled as non-ARC C++, so the block doesn't retain it, andgetAllCookies:completes on a later run-loop pass. The URL is now retained before the call and released in the block.GetCookiesdoes not sort by path. Linux's libsoup already sorts.PostThreadMessageto the WebView2 worker fails, the query completes with an error instead of leaving the future pending forever.<exe dir>\<exe>.WebView2folder (WebView2's old default) keeps being used. Only when it's absent or not writable does the new%LOCALAPPDATA%\SwingWebView\…folder apply. The legacy folder is never created.getCookiesreturns a future failed withUnsupportedOperationExceptioninstead of throwingUnsatisfiedLinkErrorsynchronously.Test demo
demos/WebViewCookieDemoplusrun-linux-cookie-demo.sh,run-mac-cookie-demo.shandrun-windows-cookie-demo.bat.COOKIEDEMO_AUTO=1runs the checks and exits 0 on pass. A loopback HTTP server sets HttpOnly, script-visible,Path=/privateandSecurecookies. The demo then checks:getCookiesbut hidden fromdocument.cookie/privatecookie is scoped by path and listed firsthttp://localhostas a secure context)sub.localhostValidation
mvn testpasses.🤖 Generated with Claude Code
https://claude.ai/code/session_01AM8KH9Z4xSuQfXF5jmeYnA