Repository navigation
v1.8.1 — session isolation on every engine, hardened loopback API
Cross-session cookie isolation is now a build-breaking CI assertion on macOS, Windows AND Linux.
- Windows: every session gets its own WebView2 profile (
with_profile_name) + InPrivate. InPrivate alone was not enough — all InPrivate controllers of one environment share a single profile (Edge InPrivate semantics, measured in CI); named profiles give each session an isolated cookies/storage/cache domain while sharing the runtime. (#6, closed) - macOS: non-persistent
WKWebsiteDataStoreper session (unchanged, now asserted). - Linux: isolated WebContexts per session, cookies never touch disk (now asserted). Known residual: WebKitGTK still writes HTTP cache/HSTS to
~/.cache/~/.local/share— needs the wry ephemeral-context lifetime fixed upstream. - Security hardening: constant-time token comparison; DNS-rebinding guard (non-local
Hostheader → 403,/healthexempt);--proxyURLs credential-redacted before logging. - Demo:
demo/signed-webhook— a 150-line HMAC-chained mock counterparty; fraud analysis as a diff, not a log read (#5).
Also in this train: the tollbooth dataset is CC BY 4.0 with x402/paywall signals (v1.8.0's bench round 2), and the walled-web post is live at https://dev.to/slabb/my-agent-met-the-real-web-403s-challenges-and-the-coming-tollbooth-1h2g
Binaries for macOS arm64, Windows x64, Linux x64 + arm64.