fix: use WebView JS fetch for auth detection; send all cookies to API

Cookie domain filtering was wrong — the session token domain is unknown
and was never found by claude.ai/anthropic.com filters.

LoginView: replace getAllCookies domain check with callAsyncJavaScript
that fetches /api/bootstrap directly from the WebView. The WebView uses
its own full session (all cookies, any domain) so auth is detected
correctly regardless of where the token lives.

UsageViewModel: claudeCookieHeader now sends all cookies from the app's
WKWebsiteDataStore instead of filtering by domain. checkInitialSignInState
likewise checks for any cookie.
This commit is contained in:
superdooper86
2026-05-11 10:06:33 +02:00
parent f28f7b8a5a
commit ac7ffe81af
4 changed files with 22 additions and 14 deletions
+5 -4
View File
@@ -43,8 +43,7 @@ class UsageViewModel: ObservableObject {
private func checkInitialSignInState() async {
let cookies = await WKWebsiteDataStore.default().httpCookieStore.allCookies()
let hasAnyCookie = cookies.contains { $0.domain.contains("claude.ai") || $0.domain.contains("anthropic.com") }
if hasAnyCookie { isSignedIn = true }
if !cookies.isEmpty { isSignedIn = true }
}
func signOut() async {
@@ -193,8 +192,10 @@ class UsageViewModel: ObservableObject {
private func claudeCookieHeader() async -> String? {
let cookies = await WKWebsiteDataStore.default().httpCookieStore.allCookies()
let claudeCookies = cookies.filter { $0.domain.contains("claude.ai") || $0.domain.contains("anthropic.com") }
return HTTPCookie.requestHeaderFields(with: claudeCookies)["Cookie"]
guard !cookies.isEmpty else { return nil }
// Send all cookies from the app's WebView store the session token may be
// on any domain (claude.ai, anthropic.com, or an auth sub-service).
return HTTPCookie.requestHeaderFields(with: cookies)["Cookie"]
}
private func fetchUsage(orgId: String) async throws -> UsageResponse {