Files
orca/docs/reference
Jinwoo-H 3d7ed005e4 fix(mobile-web): strip unknown keys on the shell to page envelope too
Follow-up to 4c7fd1aec6. The result and event payloads were made tolerant, but the envelope around them was still strict, so an additive field on a shell frame from a newer APK made an older page drop the whole frame. For init that is every grant lost at once, which is a worse brick than the payload case.

parseMobileWebBridgeShellMessage and parseMobileWebBridgeInitialMessage now parse through tolerantMobileWebShellPayload. parseMobileWebBridgePageMessage stays strict - the shell is the authority in that direction, and the census ratchet now asserts the page envelope keeps its strict nodes.

Lead policy decision: stripping preserves the PII fence, because an undeclared resumeRoute.hostPath or a raw error message is removed before the page can read it. Three test groups flip from 'rejected' to 'parsed with the field absent': the six privileged init fields, the host-shaped resume route, and the raw error message. Bounds checks are unaffected - an over-long workspaceName still fails the frame - and the adversarial shell mutation corpus keeps every other case rejecting.

Known residual, now written into the Compatibility Policy: an unknown resumeRoute.kind still fails init. A closed variant is not a field; the page cannot invent a meaning for it, so a new route kind must negotiate.

bridge-contract.ts crossed the 300-line oxlint ceiling, so the bridge route schemas move to bridge-route-contract.ts and are re-exported. No max-lines disable.

Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb
2026-09-04 16:51:37 -04:00
..