fix: use WebView JS fetch for auth detection; send all cookies to API
Cookie domain filtering was wrong — the session token domain is unknown and was never found by claude.ai/anthropic.com filters. LoginView: replace getAllCookies domain check with callAsyncJavaScript that fetches /api/bootstrap directly from the WebView. The WebView uses its own full session (all cookies, any domain) so auth is detected correctly regardless of where the token lives. UsageViewModel: claudeCookieHeader now sends all cookies from the app's WKWebsiteDataStore instead of filtering by domain. checkInitialSignInState likewise checks for any cookie.
This commit is contained in:
@@ -36,13 +36,19 @@ struct LoginWebView: NSViewRepresentable {
|
||||
if let url = webView.url?.absoluteString,
|
||||
url.contains("/login") || url.contains("/auth") { return }
|
||||
|
||||
// URL is not a login/auth page, so if any claude.ai cookie exists we're signed in
|
||||
WKWebsiteDataStore.default().httpCookieStore.getAllCookies { cookies in
|
||||
let hasAnyCookie = cookies.contains { $0.domain.contains("claude.ai") || $0.domain.contains("anthropic.com") }
|
||||
guard hasAnyCookie, !self.didAuthenticate else { return }
|
||||
self.didAuthenticate = true
|
||||
DispatchQueue.main.asyncAfter(deadline: .now() + 0.5) {
|
||||
self.onAuthenticated()
|
||||
// Ask the WebView itself whether we're authenticated — it uses its own
|
||||
// session (cookies, localStorage, etc.) so we don't need to know the
|
||||
// cookie domain or name.
|
||||
webView.callAsyncJavaScript(
|
||||
"const r = await fetch('/api/bootstrap', {credentials: 'include'}); return r.status;",
|
||||
arguments: [:], in: nil, in: .defaultClient
|
||||
) { [weak self] result in
|
||||
guard let self, !self.didAuthenticate else { return }
|
||||
if case .success(let val) = result, let status = val as? Int, status == 200 {
|
||||
self.didAuthenticate = true
|
||||
DispatchQueue.main.asyncAfter(deadline: .now() + 0.3) {
|
||||
self.onAuthenticated()
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user