mirror of
https://github.com/stablyai/orca.git
synced 2026-09-29 08:03:20 +00:00
The Android private origin's host label is the session id's prefix, but the ids were base64url. `https` is a special scheme, so Chromium ASCII-lowercases the host of every URL it loads and reports back, while `Uri.parse` keeps the mixed case the shell derived: `serveRequest`'s origin check rejected the main document and answered 403, which Android renders as `net::ERR_HTTP_RESPONSE_CODE_FAILURE`. `java.net.URI.getHost()` is also null for a label holding `_`, so the same ids dropped every bridge message. Session ids now come from a lowercase base32 alphabet, `mobileWebOriginForSession` rejects anything a URL host cannot carry, and host comparisons are case-insensitive. A failed main-frame document no longer stops at Chromium's error page: the shell hides the WebView and reports `failed` with a reason the React Native shell shows. iOS uses a custom scheme, whose opaque host preserves case and `_`, which is why only the Android lane saw this. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb