mirror of
https://github.com/stablyai/orca.git
synced 2026-09-29 08:03:20 +00:00
The page reached a desktop method by first reading `mobileWeb.host.catalog` for a grant, then forwarding through it. Every grant field duplicated something the desktop already enforced: the allowlist is the mobile-scope socket gate, the byte budgets are the bridge envelope, `workspaceParam` was `worktree` in every entry, and `scope` was "did the page send a workspaceId". The shell now forwards `workspace.hostRequest` and `workspace.hostSubscribe` straight through. It rewrites the opaque workspace handle when the payload carries one, checks one envelope in both directions, and derives a stream's desktop cancel name from its subscribe name: `X.watch` to `X.unwatch` and `X.subscribe` to `X.unsubscribe`. Unary versus stream is decided by which shell operation the page called. `files.unwatch` and `nativeChat.unsubscribe` keep their names for the released native app and gain `mobileWeb.`-prefixed aliases sharing the same handler. Shell feature negotiation goes with it: `init.shellFeatures` had no consumer beyond its own tests, so the protocol version is the bridge's only compat gate. That constant and the package bridge range move into `bridge-limits.ts`, and `bridge-protocol-version.ts`, `bridge-release-policy.ts` and `shell-feature-contract.ts` are deleted. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb