Files
orca/docs/reference
Jinwoo-H 2772f21e50 fix(mobile): derive the Android origin label instead of slicing the session id
Deriving the host label by slicing the session id forced the id itself into a
hostname alphabet, and the previous fix changed the native stores to mint
lowercase base32. But the session id is a wire token: `ShellSessionIdSchema` in
`src/shared/mobile-web/bridge-contract.ts` pins it to 43 base64url characters,
and the page that validates it is served by the desktop, which updates
independently of the app. A 52-character base32 id therefore failed
`parseMobileWebBridgeInitialMessage` inside the page, which silently dropped
`init`: no bridge client, no `ready`, no `health`, and a workspace list that
spun forever behind "The workspace interface has not reported healthy".

Session ids go back to base64url and the origin label is now the first 32 hex
characters of their SHA-256. Lowercase hex is canonical for Chromium's host
canonicalisation and parseable by `java.net.URI.getHost()`, so the original 403
and dropped-bridge-message defects stay fixed without touching the wire token.

`mobile-web-shell-init-contract.test.ts` parses the exact init the hybrid screen
posts, which is the oracle that was missing: nothing checked that the shell's
own init survives the contract the page enforces.

Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb
2026-09-03 04:18:24 -04:00
..