mirror of
https://github.com/stablyai/orca.git
synced 2026-09-29 16:02:50 +00:00
Deriving the host label by slicing the session id forced the id itself into a hostname alphabet, and the previous fix changed the native stores to mint lowercase base32. But the session id is a wire token: `ShellSessionIdSchema` in `src/shared/mobile-web/bridge-contract.ts` pins it to 43 base64url characters, and the page that validates it is served by the desktop, which updates independently of the app. A 52-character base32 id therefore failed `parseMobileWebBridgeInitialMessage` inside the page, which silently dropped `init`: no bridge client, no `ready`, no `health`, and a workspace list that spun forever behind "The workspace interface has not reported healthy". Session ids go back to base64url and the origin label is now the first 32 hex characters of their SHA-256. Lowercase hex is canonical for Chromium's host canonicalisation and parseable by `java.net.URI.getHost()`, so the original 403 and dropped-bridge-message defects stay fixed without touching the wire token. `mobile-web-shell-init-contract.test.ts` parses the exact init the hybrid screen posts, which is the oracle that was missing: nothing checked that the shell's own init survives the contract the page enforces. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb