Compare commits
33
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
91829b0ed9 | ||
|
|
caffc996ff | ||
|
|
cd13a6d124 | ||
|
|
566258e9c8 | ||
|
|
dc2a8e2307 | ||
|
|
f48b53fd8e | ||
|
|
ccfee938b7 | ||
|
|
28d952bcbd | ||
|
|
9bc023d239 | ||
|
|
fd82177a7d | ||
|
|
112210a99b | ||
|
|
f4a83940b1 | ||
|
|
377888a427 | ||
|
|
e24113a78b | ||
|
|
3baab91f70 | ||
|
|
0aa8837b2f | ||
|
|
373ca1dc14 | ||
|
|
7a4c21768f | ||
|
|
7b26629dc7 | ||
|
|
e446ea97f9 | ||
|
|
36af325e2d | ||
|
|
e2ef8b6f2a | ||
|
|
7a4975fa3e | ||
|
|
c9912f8463 | ||
|
|
238614a94b | ||
|
|
b11507221f | ||
|
|
b6fef53264 | ||
|
|
ec6ae6621a | ||
|
|
105a7706fa | ||
|
|
a950392a6f | ||
|
|
8087cc029d | ||
|
|
11f9e0c9b6 | ||
|
|
cc835ee2b0 |
@@ -116,8 +116,8 @@ struct ContentView: View {
|
||||
showUpdateSheet = true
|
||||
}
|
||||
.sheet(isPresented: $showLogin) {
|
||||
LoginSheetView(isPresented: $showLogin) {
|
||||
Task { await vm.reloadAPIWebViewAndRefresh() }
|
||||
LoginSheetView(isPresented: $showLogin) { webView in
|
||||
Task { await vm.adoptAndRefresh(webView) }
|
||||
}
|
||||
}
|
||||
.sheet(isPresented: $showUpdateSheet) {
|
||||
|
||||
@@ -15,9 +15,9 @@
|
||||
<key>CFBundlePackageType</key>
|
||||
<string>APPL</string>
|
||||
<key>CFBundleShortVersionString</key>
|
||||
<string>1.2.1-beta.12</string>
|
||||
<string>1.2.1-beta.20</string>
|
||||
<key>CFBundleVersion</key>
|
||||
<string>60</string>
|
||||
<string>68</string>
|
||||
<key>LSMinimumSystemVersion</key>
|
||||
<string>13.0</string>
|
||||
<key>LSUIElement</key>
|
||||
|
||||
@@ -4,7 +4,7 @@ import WebKit
|
||||
// MARK: - Login Web View
|
||||
|
||||
struct LoginWebView: NSViewRepresentable {
|
||||
let onAuthenticated: () -> Void
|
||||
let onAuthenticated: (WKWebView) -> Void
|
||||
|
||||
func makeNSView(context: Context) -> WKWebView {
|
||||
let config = WKWebViewConfiguration()
|
||||
@@ -12,6 +12,7 @@ struct LoginWebView: NSViewRepresentable {
|
||||
|
||||
let webView = WKWebView(frame: .zero, configuration: config)
|
||||
webView.navigationDelegate = context.coordinator
|
||||
context.coordinator.webView = webView
|
||||
|
||||
// KVO on url catches SPA pushState navigations that don't fire didFinish
|
||||
context.coordinator.urlObservation = webView.observe(\.url, options: [.new]) { [weak coordinator = context.coordinator] wv, _ in
|
||||
@@ -29,20 +30,24 @@ struct LoginWebView: NSViewRepresentable {
|
||||
}
|
||||
|
||||
class Coordinator: NSObject, WKNavigationDelegate {
|
||||
let onAuthenticated: () -> Void
|
||||
let onAuthenticated: (WKWebView) -> Void
|
||||
weak var webView: WKWebView?
|
||||
var didAuthenticate = false
|
||||
var urlObservation: NSKeyValueObservation?
|
||||
|
||||
init(onAuthenticated: @escaping () -> Void) {
|
||||
init(onAuthenticated: @escaping (WKWebView) -> Void) {
|
||||
self.onAuthenticated = onAuthenticated
|
||||
}
|
||||
|
||||
func checkCurrentURL(_ url: String?) {
|
||||
guard !didAuthenticate, let url else { return }
|
||||
guard !didAuthenticate, let url, let wv = webView else { return }
|
||||
// Ignore navigations to external OAuth providers (Google, etc.) —
|
||||
// only consider auth complete when we land back on claude.ai/anthropic.com
|
||||
guard url.contains("claude.ai") || url.contains("anthropic.com") else { return }
|
||||
if url.contains("/login") || url.contains("/auth") { return }
|
||||
didAuthenticate = true
|
||||
DispatchQueue.main.asyncAfter(deadline: .now() + 0.5) {
|
||||
self.onAuthenticated()
|
||||
self.onAuthenticated(wv)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -57,7 +62,7 @@ struct LoginWebView: NSViewRepresentable {
|
||||
|
||||
struct LoginSheetView: View {
|
||||
@Binding var isPresented: Bool
|
||||
let onDone: () -> Void
|
||||
let onDone: (WKWebView) -> Void
|
||||
@State private var authenticated = false
|
||||
|
||||
var body: some View {
|
||||
@@ -67,12 +72,9 @@ struct LoginSheetView: View {
|
||||
.font(.system(size: 13, weight: .semibold))
|
||||
Spacer()
|
||||
if authenticated {
|
||||
Button("Done") {
|
||||
isPresented = false
|
||||
onDone()
|
||||
}
|
||||
.buttonStyle(.borderedProminent)
|
||||
.controlSize(.small)
|
||||
Button("Done") { isPresented = false }
|
||||
.buttonStyle(.borderedProminent)
|
||||
.controlSize(.small)
|
||||
} else {
|
||||
Button("Cancel") { isPresented = false }
|
||||
.buttonStyle(.bordered)
|
||||
@@ -85,12 +87,13 @@ struct LoginSheetView: View {
|
||||
|
||||
Divider()
|
||||
|
||||
LoginWebView {
|
||||
LoginWebView { webView in
|
||||
authenticated = true
|
||||
// Auto-dismiss and refresh after brief delay
|
||||
DispatchQueue.main.asyncAfter(deadline: .now() + 0.8) {
|
||||
// Adopt the authenticated WebView immediately (before sheet tears it down),
|
||||
// then auto-dismiss after a moment so the user sees confirmation.
|
||||
onDone(webView)
|
||||
DispatchQueue.main.asyncAfter(deadline: .now() + 1.2) {
|
||||
isPresented = false
|
||||
onDone()
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -30,10 +30,6 @@ class UsageViewModel: ObservableObject {
|
||||
private var previousPercents: [String: Double] = [:]
|
||||
private var firedThresholds: [String: Set<Int>] = [:]
|
||||
|
||||
// Background WKWebView used for all API calls — runs fetch() in the page's auth context
|
||||
private var apiWebView: WKWebView?
|
||||
private var apiDelegate: APIWebViewDelegate?
|
||||
|
||||
init() {
|
||||
let saved = UserDefaults.standard.double(forKey: "refresh_interval")
|
||||
refreshInterval = saved > 0 ? saved : 60
|
||||
@@ -42,48 +38,50 @@ class UsageViewModel: ObservableObject {
|
||||
burnHistoryStore = saved
|
||||
}
|
||||
loadPlaceholderData()
|
||||
setupAPIWebView()
|
||||
Task { await checkInitialSignInState() }
|
||||
}
|
||||
|
||||
// MARK: - Background API WebView
|
||||
|
||||
private func setupAPIWebView() {
|
||||
let config = WKWebViewConfiguration()
|
||||
config.websiteDataStore = WKWebsiteDataStore.default()
|
||||
let wv = WKWebView(frame: CGRect(x: 0, y: 0, width: 1, height: 1), configuration: config)
|
||||
let del = APIWebViewDelegate()
|
||||
wv.navigationDelegate = del
|
||||
apiWebView = wv
|
||||
apiDelegate = del
|
||||
wv.load(URLRequest(url: URL(string: "https://claude.ai")!))
|
||||
}
|
||||
|
||||
// Called after login: reloads the background WebView to pick up the new session, then refreshes.
|
||||
func reloadAPIWebViewAndRefresh() async {
|
||||
guard let wv = apiWebView, let del = apiDelegate else {
|
||||
await refresh()
|
||||
return
|
||||
}
|
||||
await withCheckedContinuation { (cont: CheckedContinuation<Void, Never>) in
|
||||
del.onDidFinish = { cont.resume() }
|
||||
wv.load(URLRequest(url: URL(string: "https://claude.ai")!))
|
||||
}
|
||||
// Brief pause for the page's JS auth state to settle after navigation
|
||||
// Called after login: cookies are already in WKWebsiteDataStore.default() —
|
||||
// brief sleep lets the store commit, then refresh uses URLSession.
|
||||
func adoptAndRefresh(_ loginWebView: WKWebView) async {
|
||||
try? await Task.sleep(nanoseconds: 500_000_000)
|
||||
await refresh()
|
||||
}
|
||||
|
||||
// Runs a fetch() call inside the background WebView's page context (same-origin, credentials included).
|
||||
private func webViewFetch(_ path: String) async throws -> (statusCode: Int, body: String) {
|
||||
guard let wv = apiWebView else { throw AppError.networkError }
|
||||
let js = "const r = await fetch(path, {credentials:'include'}); return {s: r.status, b: await r.text()};"
|
||||
let result = try await wv.callAsyncJavaScript(
|
||||
js, arguments: ["path": path], in: nil, in: .page)
|
||||
guard let d = result as? [String: Any],
|
||||
let s = (d["s"] as? NSNumber)?.intValue,
|
||||
let b = d["b"] as? String else { throw AppError.networkError }
|
||||
return (s, b)
|
||||
// Fetches an API path via URLSession with browser-like headers.
|
||||
// Claude.ai's API requires sec-fetch-*, Origin, Referer, and a browser User-Agent
|
||||
// to avoid 401 — matching how the Windows version (HttpClient) handles this.
|
||||
private func urlFetch(_ path: String) async throws -> (Int, String) {
|
||||
let cookies = await WKWebsiteDataStore.default().httpCookieStore.allCookies()
|
||||
let claudeCookies = cookies.filter {
|
||||
$0.domain.contains("claude.ai") || $0.domain.contains("anthropic.com")
|
||||
}
|
||||
guard !claudeCookies.isEmpty else { throw AppError.notAuthenticated }
|
||||
|
||||
var req = URLRequest(url: URL(string: "https://claude.ai\(path)")!)
|
||||
req.httpShouldHandleCookies = false
|
||||
if let cookieHeader = HTTPCookie.requestHeaderFields(with: claudeCookies)["Cookie"] {
|
||||
req.setValue(cookieHeader, forHTTPHeaderField: "Cookie")
|
||||
}
|
||||
req.setValue("application/json", forHTTPHeaderField: "Accept")
|
||||
req.setValue("https://claude.ai", forHTTPHeaderField: "Origin")
|
||||
req.setValue("https://claude.ai/", forHTTPHeaderField: "Referer")
|
||||
req.setValue("empty", forHTTPHeaderField: "sec-fetch-dest")
|
||||
req.setValue("cors", forHTTPHeaderField: "sec-fetch-mode")
|
||||
req.setValue("same-origin", forHTTPHeaderField: "sec-fetch-site")
|
||||
req.setValue(
|
||||
"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36",
|
||||
forHTTPHeaderField: "User-Agent")
|
||||
req.setValue(
|
||||
"\"Chromium\";v=\"124\", \"Google Chrome\";v=\"124\", \"Not-A.Brand\";v=\"99\"",
|
||||
forHTTPHeaderField: "sec-ch-ua")
|
||||
req.setValue("?0", forHTTPHeaderField: "sec-ch-ua-mobile")
|
||||
req.setValue("\"macOS\"", forHTTPHeaderField: "sec-ch-ua-platform")
|
||||
|
||||
let (data, response) = try await URLSession.shared.data(for: req)
|
||||
guard let http = response as? HTTPURLResponse else { throw AppError.networkError }
|
||||
let body = String(data: data, encoding: .utf8) ?? ""
|
||||
return (http.statusCode, body)
|
||||
}
|
||||
|
||||
private func checkInitialSignInState() async {
|
||||
@@ -106,8 +104,6 @@ class UsageViewModel: ObservableObject {
|
||||
extraUsage = nil
|
||||
prepaidCredits = nil
|
||||
overageSpendLimit = nil
|
||||
// Reload background WebView to clear its session too
|
||||
apiWebView?.load(URLRequest(url: URL(string: "https://claude.ai")!))
|
||||
}
|
||||
|
||||
func refresh() async {
|
||||
@@ -137,8 +133,8 @@ class UsageViewModel: ObservableObject {
|
||||
async let overageFetch = fetchOverageSpendLimit(orgId: orgId)
|
||||
let (usage, prepaid, overage) = try await (usageFetch, prepaidFetch, overageFetch)
|
||||
limits = buildLimits(from: usage)
|
||||
extraUsage = usage.extraUsage
|
||||
prepaidCredits = prepaid
|
||||
extraUsage = usage.extraUsage
|
||||
prepaidCredits = prepaid
|
||||
overageSpendLimit = overage
|
||||
lastUpdated = Date()
|
||||
isSignedIn = true
|
||||
@@ -173,12 +169,16 @@ class UsageViewModel: ObservableObject {
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Bootstrap (org ID + email + plan label in one call)
|
||||
// MARK: - Bootstrap
|
||||
|
||||
private func fetchBootstrap() async throws -> (orgId: String?, email: String?, planLabel: String?) {
|
||||
let (status, body) = try await webViewFetch("/api/bootstrap")
|
||||
let (status, body) = try await urlFetch("/api/bootstrap")
|
||||
if status == 401 || status == 403 { throw AppError.notAuthenticated }
|
||||
guard status == 200 else { throw AppError.networkError }
|
||||
guard status == 200 else { throw AppError.detail("bootstrap \(status): \(body.prefix(80))") }
|
||||
// If WebKit followed a redirect to the login page we get HTML instead of JSON.
|
||||
guard body.trimmingCharacters(in: .whitespacesAndNewlines).hasPrefix("{") else {
|
||||
throw AppError.notAuthenticated
|
||||
}
|
||||
guard let data = body.data(using: .utf8),
|
||||
let json = try? JSONSerialization.jsonObject(with: data) as? [String: Any] else {
|
||||
return (nil, nil, nil)
|
||||
@@ -193,7 +193,7 @@ class UsageViewModel: ObservableObject {
|
||||
orgId = (json["organizations"] as? [[String: Any]])?.first?["uuid"] as? String
|
||||
}
|
||||
if orgId == nil {
|
||||
if let (orgsStatus, orgsBody) = try? await webViewFetch("/api/organizations"),
|
||||
if let (orgsStatus, orgsBody) = try? await urlFetch("/api/organizations"),
|
||||
orgsStatus == 200,
|
||||
let orgsData = orgsBody.data(using: .utf8),
|
||||
let orgs = try? JSONSerialization.jsonObject(with: orgsData) as? [[String: Any]] {
|
||||
@@ -216,7 +216,7 @@ class UsageViewModel: ObservableObject {
|
||||
// MARK: - Fetch usage
|
||||
|
||||
private func fetchUsage(orgId: String) async throws -> UsageResponse {
|
||||
let (status, body) = try await webViewFetch("/api/organizations/\(orgId)/usage")
|
||||
let (status, body) = try await urlFetch("/api/organizations/\(orgId)/usage")
|
||||
if status == 401 || status == 403 { throw AppError.notAuthenticated }
|
||||
guard status == 200 else { throw AppError.networkError }
|
||||
guard let data = body.data(using: .utf8) else { throw AppError.networkError }
|
||||
@@ -224,14 +224,14 @@ class UsageViewModel: ObservableObject {
|
||||
}
|
||||
|
||||
private func fetchPrepaidCredits(orgId: String) async throws -> PrepaidCredits? {
|
||||
guard let (status, body) = try? await webViewFetch("/api/organizations/\(orgId)/prepaid/credits"),
|
||||
guard let (status, body) = try? await urlFetch("/api/organizations/\(orgId)/prepaid/credits"),
|
||||
status == 200,
|
||||
let data = body.data(using: .utf8) else { return nil }
|
||||
return try? JSONDecoder().decode(PrepaidCredits.self, from: data)
|
||||
}
|
||||
|
||||
private func fetchOverageSpendLimit(orgId: String) async throws -> OverageSpendLimit? {
|
||||
guard let (status, body) = try? await webViewFetch("/api/organizations/\(orgId)/overage_spend_limit"),
|
||||
guard let (status, body) = try? await urlFetch("/api/organizations/\(orgId)/overage_spend_limit"),
|
||||
status == 200,
|
||||
let data = body.data(using: .utf8) else { return nil }
|
||||
return try? JSONDecoder().decode(OverageSpendLimit.self, from: data)
|
||||
@@ -350,29 +350,16 @@ class UsageViewModel: ObservableObject {
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - API WebView Delegate
|
||||
|
||||
private class APIWebViewDelegate: NSObject, WKNavigationDelegate {
|
||||
var onDidFinish: (() -> Void)?
|
||||
|
||||
func webView(_ webView: WKWebView, didFinish navigation: WKNavigation!) {
|
||||
let cb = onDidFinish; onDidFinish = nil; cb?()
|
||||
}
|
||||
func webView(_ webView: WKWebView, didFail navigation: WKNavigation!, withError error: Error) {
|
||||
let cb = onDidFinish; onDidFinish = nil; cb?()
|
||||
}
|
||||
func webView(_ webView: WKWebView, didFailProvisionalNavigation navigation: WKNavigation!, withError error: Error) {
|
||||
let cb = onDidFinish; onDidFinish = nil; cb?()
|
||||
}
|
||||
}
|
||||
|
||||
enum AppError: LocalizedError {
|
||||
case notAuthenticated
|
||||
case networkError
|
||||
case detail(String)
|
||||
var errorDescription: String? {
|
||||
switch self {
|
||||
case .notAuthenticated: return "Not signed into claude.ai — open claude.ai in your browser first."
|
||||
case .networkError: return "Network error fetching usage data."
|
||||
case .notAuthenticated: return "Not signed into claude.ai — open claude.ai in your browser first."
|
||||
case .networkError: return "Network error fetching usage data."
|
||||
case .detail(let msg): return msg
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -10,7 +10,7 @@
|
||||
[](https://swift.org)
|
||||
[](https://github.com/superdooper86/claudechecker/releases)
|
||||
[](LICENSE)
|
||||
[](https://github.com/superdooper86/claudechecker/releases/tag/v1.2.1-beta.11) <!-- BETA_BADGE -->
|
||||
[](https://github.com/superdooper86/claudechecker/releases/tag/v1.2.1-beta.19) <!-- BETA_BADGE -->
|
||||
|
||||
</div>
|
||||
|
||||
|
||||
+17
-9
@@ -1,12 +1,20 @@
|
||||
## What's new in v1.2.1-beta.18
|
||||
|
||||
### Bug fixes
|
||||
- Replaced callAsyncJavaScript fetch approach with WebKit navigation: instead of running `fetch()` in the page's JS context (which was returning 401 because it bypasses the SPA's auth interceptors), each API call now navigates the WebView to the API URL directly. WebKit sends full browser headers and cookies automatically at the HTTP layer, the same way a real browser navigation works. This is more reliable regardless of what server-side auth mechanism claude.ai uses.
|
||||
- API calls are now sequential to share a single WebView for all navigations
|
||||
- Added redirect detection: if WebKit follows a 302 to /login, the response is treated as an auth failure rather than returning HTML to the JSON parser
|
||||
|
||||
## What's new in v1.2.1-beta.17
|
||||
|
||||
### Bug fixes
|
||||
- Fixed "Not signed in" after login by adopting the login WebView directly for API calls
|
||||
- Added diagnostic error messages for JS errors and unexpected responses
|
||||
|
||||
## What's new in v1.2.1
|
||||
|
||||
### Bug fixes
|
||||
- Fixed usage data not loading after sign-in — API calls now run inside a persistent background WebView using the page's own fetch(), so all credentials (cookies, localStorage tokens, etc.) are included automatically
|
||||
- Fixed "Not signed in" showing after login — the background WebView is now reloaded after sign-in to pick up the new session before the first data refresh
|
||||
- Fixed "Not signed in" showing incorrectly on launch when the session was already active
|
||||
- Sign-in state is now detected immediately from stored cookies on startup, before the first data refresh completes
|
||||
- Fixed login window auto-closing before the user could sign in — the login window now correctly loads the `/login` page so it only detects auth after the actual sign-in redirect
|
||||
- Fixed "No API key configured" showing after signing out — now correctly shows "Not signed in" with a prompt to sign in
|
||||
- Added `/api/organizations` as a final fallback for org ID resolution when the bootstrap API response doesn't include it
|
||||
- Fixed Settings incorrectly showing "Signed in" after a failed refresh — sign-in state now resets when authentication fails
|
||||
- Rewrote login detection to use KVO on the WebView URL — correctly detects auth for Next.js SPA navigation (history.pushState) that doesn't trigger didFinish
|
||||
- Fixed WebKit suspending the background WKWebView: anchored in a transparent 1×1 NSWindow
|
||||
- Fixed login window auto-closing before sign-in completes
|
||||
- Added /api/organizations as a final fallback for org ID resolution
|
||||
- Fixed Settings incorrectly showing "Signed in" after a failed refresh
|
||||
|
||||
+3
-3
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"version": "1.2.1-beta.11",
|
||||
"url": "https://github.com/superdooper86/claudechecker/releases/download/v1.2.1-beta.11/ClaudeChecker.zip",
|
||||
"notes": "## What's new in v1.2.1\n\n### Bug fixes\n- Fixed \"Not signed in\" showing incorrectly on launch when the session was already active\n- Sign-in state is now detected immediately from stored cookies on startup, before the first data refresh completes\n- Fixed login window auto-closing before the user could sign in — the login window now correctly loads the `/login` page so it only detects auth after the actual sign-in redirect\n- Fixed \"No API key configured\" showing after signing out — now correctly shows \"Not signed in\" with a prompt to sign in\n- Added `/api/organizations` as a final fallback for org ID resolution when the bootstrap API response doesn't include it\n- Fixed usage data not loading — API requests now include required browser-like headers (Origin, Referer, User-Agent)\n- Fixed Settings incorrectly showing \"Signed in\" after a failed refresh — sign-in state now resets when authentication fails\n- Rewrote login detection to use the WebView's own fetch call instead of inspecting cookie domains — correctly detects auth regardless of which domain the session token is stored on\n- Fixed API requests not including session cookies — now sends all cookies from the app's WebView store rather than filtering by domain"
|
||||
"version": "1.2.1-beta.19",
|
||||
"url": "https://github.com/superdooper86/claudechecker/releases/download/v1.2.1-beta.19/ClaudeChecker.zip",
|
||||
"notes": "## What's new in v1.2.1-beta.18\n\n### Bug fixes\n- Replaced callAsyncJavaScript fetch approach with WebKit navigation: instead of running `fetch()` in the page's JS context (which was returning 401 because it bypasses the SPA's auth interceptors), each API call now navigates the WebView to the API URL directly. WebKit sends full browser headers and cookies automatically at the HTTP layer, the same way a real browser navigation works. This is more reliable regardless of what server-side auth mechanism claude.ai uses.\n- API calls are now sequential to share a single WebView for all navigations\n- Added redirect detection: if WebKit follows a 302 to /login, the response is treated as an auth failure rather than returning HTML to the JSON parser\n\n## What's new in v1.2.1-beta.17\n\n### Bug fixes\n- Fixed \"Not signed in\" after login by adopting the login WebView directly for API calls\n- Added diagnostic error messages for JS errors and unexpected responses\n\n## What's new in v1.2.1\n\n### Bug fixes\n- Fixed WebKit suspending the background WKWebView: anchored in a transparent 1×1 NSWindow\n- Fixed login window auto-closing before sign-in completes\n- Added /api/organizations as a final fallback for org ID resolution\n- Fixed Settings incorrectly showing \"Signed in\" after a failed refresh"
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user