Skip to content

v1.8.1 — session isolation on every engine, hardened loopback API

Choose a tag to compare

@slabbdev slabbdev released this 08 Oct 18:05
· 41 commits to main since this release

Cross-session cookie isolation is now a build-breaking CI assertion on macOS, Windows AND Linux.

  • Windows: every session gets its own WebView2 profile (with_profile_name) + InPrivate. InPrivate alone was not enough — all InPrivate controllers of one environment share a single profile (Edge InPrivate semantics, measured in CI); named profiles give each session an isolated cookies/storage/cache domain while sharing the runtime. (#6, closed)
  • macOS: non-persistent WKWebsiteDataStore per session (unchanged, now asserted).
  • Linux: isolated WebContexts per session, cookies never touch disk (now asserted). Known residual: WebKitGTK still writes HTTP cache/HSTS to ~/.cache/~/.local/share — needs the wry ephemeral-context lifetime fixed upstream.
  • Security hardening: constant-time token comparison; DNS-rebinding guard (non-local Host header → 403, /health exempt); --proxy URLs credential-redacted before logging.
  • Demo: demo/signed-webhook — a 150-line HMAC-chained mock counterparty; fraud analysis as a diff, not a log read (#5).

Also in this train: the tollbooth dataset is CC BY 4.0 with x402/paywall signals (v1.8.0's bench round 2), and the walled-web post is live at https://dev.to/slabb/my-agent-met-the-real-web-403s-challenges-and-the-coming-tollbooth-1h2g

Binaries for macOS arm64, Windows x64, Linux x64 + arm64.