Skip to content

fix(extension): resolve DSH authentication cookie conflicts in 0.1.2 - #9

Merged
HeftyKoo merged 1 commit into
mainfrom
codex/fix-dsh-web-auth
Sep 26, 2026
Merged

HeftyKoo merged 1 commit into
mainfrom
codex/fix-dsh-web-auth

Conversation

@HeftyKoo

Copy link
Copy Markdown
Owner

Chrome could show dsh web authentication required after a user approved AgentOnWeb because an old first-party DSH cookie preceded the newly delegated partitioned cookie. Send the current session with a tab-and-port-scoped HTTP header rule while retaining partitioned cookies for WebSocket authentication. Clear stale rules when the background restarts and remove both delegations on revocation.

Release the browser extension as 0.1.2; the DSH npm plugin remains 0.1.1. Chrome adds declarativeNetRequestWithHostAccess; Firefox keeps its existing cookie path. Includes a repeatable real-browser regression and diagnosis/acceptance notes.

Validation: pnpm release:audit passed (86 tests, 1 existing skip), typecheck, privacy/architecture checks, all browser builds, native Safari manifest validation and reproducible packages. Real-browser conflicting-cookie regression passed with DSH 0.1.2-alpha.3 and 0.1.5-rc.3. Computer Use on real YouTube verified native approval, page refresh/reopen and extension reload/reconnect with DSH 0.1.5-rc.3. No model turn was sent.

@HeftyKoo
HeftyKoo marked this pull request as ready for review September 26, 2026 03:19
@HeftyKoo
HeftyKoo merged commit 5740f07 into main Sep 26, 2026
1 check passed
@HeftyKoo
HeftyKoo deleted the codex/fix-dsh-web-auth branch September 26, 2026 03:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant