mirror of
https://github.com/stablyai/orca.git
synced 2026-10-01 16:02:03 +00:00
* fix(browser): give a tab's identity one owner so viewport presets stop dropping client hints A desktop viewport preset installed a CDP user-agent override with no userAgentMetadata. Chromium then drops navigator.userAgentData and every sec-ch-ua header for that tab: a Chrome UA with no client hints. Identity was decided separately by the session request hook, the Google sign-in switch and the viewport code, and nothing decided per tab who it should claim to be. resolveBrowserTabIdentity now derives it from the process identity mode, whether the URL is a Google auth host, and whether a mobile preset is requested. applyTabIdentity is the one writer: it keeps the WebContents UA on the process or Firefox identity and clears the CDP override whenever that layer already presents the identity. Viewport emulation only records the requested preset; its metrics and touch steps log failures independently, so a rejected step can no longer skip the identity restore. * test(browser): read the presented identity instead of casting the guest stub * test(browser): drop a comment that described desktop presets writing a UA * fix(browser): keep same-document navigations and unapplied presets off the tab identity A same-document navigation (pushState/replaceState) now never rewrites the WebContents user agent. Chromium reloads a still-loading document when its user agent changes, so an OAuth callback that strips its code with replaceState after a redirect off Google sign-in was requested twice, replaying the one-time code. Measured on Electron 43.7.5: the callback URL hits the server twice with the write, once without. The session request hook now derives the mobile identity from the CDP override the tab actually holds instead of the requested preset. A preset whose write never landed (debugger attach refused while DevTools is open, a failed write, a detach) no longer puts the iPhone user agent and mobile client hints on the wire while the document reports desktop. * fix(browser): restore identity after a failed navigation without reloading the error page did-fail-load fires while the failed URL's error page is still loading, and WebContents.setUserAgent() at that moment makes Chromium reload it. After a redirect onto or off the Google sign-in host (identity moved over CDP only), the restore rewrote the WebContents UA there and replayed the failed request. The restore now goes over CDP; the next navigation rewrites the WebContents UA. * refactor(browser): let only a navigation start write the WebContents user agent Two review rounds each found a caller that asked the identity writer to rewrite the WebContents UA at a moment Chromium reloads or cancels the page (a same-document navigation, a failed load). A boolean at every call site left that decision to the callers. The writer now has two entry points: presentTabIdentityAtNavigationStart, the only one that may write the WebContents UA and only for a cross-document navigation, and retargetTabIdentity, which goes over CDP only and serves redirects, failed loads and preset changes. A table test pins the rule for every entry point. * test(browser): reject touch emulation regardless of payload in the identity-restore test The mock rejected only maxTouchPoints 0, so the test would stop exercising a failed touch step once the touch payload is fixed.