Compare commits
23
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
e2ef8b6f2a | ||
|
|
7a4975fa3e | ||
|
|
c9912f8463 | ||
|
|
238614a94b | ||
|
|
b11507221f | ||
|
|
b6fef53264 | ||
|
|
ec6ae6621a | ||
|
|
105a7706fa | ||
|
|
a950392a6f | ||
|
|
8087cc029d | ||
|
|
11f9e0c9b6 | ||
|
|
cc835ee2b0 | ||
|
|
8e7328b2c5 | ||
|
|
709eb12382 | ||
|
|
e866324a48 | ||
|
|
a62584221b | ||
|
|
fc7fd19652 | ||
|
|
58b947e515 | ||
|
|
88252e4d59 | ||
|
|
ad2ff3a7b6 | ||
|
|
1a9d9cd22a | ||
|
|
b8826ace9b | ||
|
|
2a0de269ff |
@@ -15,9 +15,9 @@
|
||||
<key>CFBundlePackageType</key>
|
||||
<string>APPL</string>
|
||||
<key>CFBundleShortVersionString</key>
|
||||
<string>1.2.1-beta.8</string>
|
||||
<string>1.2.1-beta.15</string>
|
||||
<key>CFBundleVersion</key>
|
||||
<string>56</string>
|
||||
<string>63</string>
|
||||
<key>LSMinimumSystemVersion</key>
|
||||
<string>13.0</string>
|
||||
<key>LSUIElement</key>
|
||||
|
||||
@@ -12,6 +12,12 @@ struct LoginWebView: NSViewRepresentable {
|
||||
|
||||
let webView = WKWebView(frame: .zero, configuration: config)
|
||||
webView.navigationDelegate = context.coordinator
|
||||
|
||||
// KVO on url catches SPA pushState navigations that don't fire didFinish
|
||||
context.coordinator.urlObservation = webView.observe(\.url, options: [.new]) { [weak coordinator = context.coordinator] wv, _ in
|
||||
coordinator?.checkCurrentURL(wv.url?.absoluteString)
|
||||
}
|
||||
|
||||
webView.load(URLRequest(url: URL(string: "https://claude.ai/login")!))
|
||||
return webView
|
||||
}
|
||||
@@ -25,33 +31,28 @@ struct LoginWebView: NSViewRepresentable {
|
||||
class Coordinator: NSObject, WKNavigationDelegate {
|
||||
let onAuthenticated: () -> Void
|
||||
var didAuthenticate = false
|
||||
var urlObservation: NSKeyValueObservation?
|
||||
|
||||
init(onAuthenticated: @escaping () -> Void) {
|
||||
self.onAuthenticated = onAuthenticated
|
||||
}
|
||||
|
||||
func webView(_ webView: WKWebView, didFinish navigation: WKNavigation!) {
|
||||
guard !didAuthenticate else { return }
|
||||
// Don't fire on the login/auth pages themselves
|
||||
if let url = webView.url?.absoluteString,
|
||||
url.contains("/login") || url.contains("/auth") { return }
|
||||
|
||||
// Ask the WebView itself whether we're authenticated — it uses its own
|
||||
// session (cookies, localStorage, etc.) so we don't need to know the
|
||||
// cookie domain or name.
|
||||
webView.callAsyncJavaScript(
|
||||
"const r = await fetch('/api/bootstrap', {credentials: 'include'}); return r.status;",
|
||||
arguments: [:], in: nil, in: .defaultClient
|
||||
) { [weak self] result in
|
||||
guard let self, !self.didAuthenticate else { return }
|
||||
if case .success(let val) = result, let status = val as? Int, status == 200 {
|
||||
self.didAuthenticate = true
|
||||
DispatchQueue.main.asyncAfter(deadline: .now() + 0.3) {
|
||||
self.onAuthenticated()
|
||||
}
|
||||
}
|
||||
func checkCurrentURL(_ url: String?) {
|
||||
guard !didAuthenticate, let url else { return }
|
||||
// Ignore navigations to external OAuth providers (Google, etc.) —
|
||||
// only consider auth complete when we land back on claude.ai/anthropic.com
|
||||
guard url.contains("claude.ai") || url.contains("anthropic.com") else { return }
|
||||
if url.contains("/login") || url.contains("/auth") { return }
|
||||
didAuthenticate = true
|
||||
DispatchQueue.main.asyncAfter(deadline: .now() + 0.5) {
|
||||
self.onAuthenticated()
|
||||
}
|
||||
}
|
||||
|
||||
// Covers full cross-document navigations
|
||||
func webView(_ webView: WKWebView, didFinish navigation: WKNavigation!) {
|
||||
checkCurrentURL(webView.url?.absoluteString)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -126,27 +126,39 @@ class UsageViewModel: ObservableObject {
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Bootstrap (org ID + email + plan label in one call)
|
||||
// MARK: - HTTP helpers
|
||||
|
||||
// Builds a URLRequest with browser-like headers and cookies from WKWebsiteDataStore.
|
||||
//
|
||||
// httpShouldHandleCookies MUST be false: when true, URLSession replaces any manually-set
|
||||
// Cookie header with its own HTTPCookieStorage (which is empty — claude.ai cookies live in
|
||||
// WKWebsiteDataStore, not HTTPCookieStorage), causing every request to go out with no cookies.
|
||||
private func claudeAPIRequest(for url: URL) async -> URLRequest {
|
||||
var req = URLRequest(url: url)
|
||||
req.setValue("application/json, text/plain, */*", forHTTPHeaderField: "accept")
|
||||
req.setValue("Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36", forHTTPHeaderField: "User-Agent")
|
||||
req.setValue("https://claude.ai", forHTTPHeaderField: "Origin")
|
||||
req.setValue("https://claude.ai/", forHTTPHeaderField: "Referer")
|
||||
req.setValue("same-origin", forHTTPHeaderField: "sec-fetch-site")
|
||||
req.setValue("cors", forHTTPHeaderField: "sec-fetch-mode")
|
||||
req.setValue("empty", forHTTPHeaderField: "sec-fetch-dest")
|
||||
req.httpShouldHandleCookies = false
|
||||
req.setValue("application/json", forHTTPHeaderField: "accept")
|
||||
req.setValue("https://claude.ai", forHTTPHeaderField: "origin")
|
||||
req.setValue("https://claude.ai/", forHTTPHeaderField: "referer")
|
||||
req.setValue(
|
||||
"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36",
|
||||
forHTTPHeaderField: "user-agent")
|
||||
if let cookie = await claudeCookieHeader() {
|
||||
req.setValue(cookie, forHTTPHeaderField: "Cookie")
|
||||
req.setValue(cookie, forHTTPHeaderField: "cookie")
|
||||
}
|
||||
return req
|
||||
}
|
||||
|
||||
private func claudeCookieHeader() async -> String? {
|
||||
let cookies = await WKWebsiteDataStore.default().httpCookieStore.allCookies()
|
||||
guard !cookies.isEmpty else { return nil }
|
||||
return HTTPCookie.requestHeaderFields(with: cookies)["Cookie"]
|
||||
}
|
||||
|
||||
// MARK: - Bootstrap (org ID + email + plan label in one call)
|
||||
|
||||
private func fetchBootstrap() async throws -> (orgId: String?, email: String?, planLabel: String?) {
|
||||
let url = URL(string: "https://claude.ai/api/bootstrap")!
|
||||
var req = await claudeAPIRequest(for: url)
|
||||
guard req.value(forHTTPHeaderField: "Cookie") != nil else { throw AppError.notAuthenticated }
|
||||
let req = await claudeAPIRequest(for: url)
|
||||
let (data, response) = try await URLSession.shared.data(for: req)
|
||||
guard let http = response as? HTTPURLResponse else { throw AppError.networkError }
|
||||
if http.statusCode == 401 || http.statusCode == 403 { throw AppError.notAuthenticated }
|
||||
@@ -156,17 +168,14 @@ class UsageViewModel: ObservableObject {
|
||||
}
|
||||
|
||||
let account = json["account"] as? [String: Any]
|
||||
// memberships may live under account or at root (older API shape)
|
||||
let memberships = (account?["memberships"] ?? json["memberships"]) as? [[String: Any]]
|
||||
let firstOrg = memberships?.first?["organization"] as? [String: Any]
|
||||
|
||||
// org ID — primary path then flat-list fallback then dedicated endpoint
|
||||
var orgId: String? = firstOrg?["uuid"] as? String
|
||||
if orgId == nil {
|
||||
orgId = (json["organizations"] as? [[String: Any]])?.first?["uuid"] as? String
|
||||
}
|
||||
if orgId == nil {
|
||||
// Final fallback: fetch /api/organizations directly
|
||||
let orgsReq = await claudeAPIRequest(for: URL(string: "https://claude.ai/api/organizations")!)
|
||||
if let (orgsData, orgsResp) = try? await URLSession.shared.data(for: orgsReq),
|
||||
let orgsHttp = orgsResp as? HTTPURLResponse, orgsHttp.statusCode == 200,
|
||||
@@ -177,7 +186,6 @@ class UsageViewModel: ObservableObject {
|
||||
|
||||
let email = account?["email_address"] as? String
|
||||
|
||||
// plan label from capabilities e.g. "claude_pro" -> "Pro"
|
||||
var planLabel: String? = nil
|
||||
if let caps = firstOrg?["capabilities"] as? [String],
|
||||
let cap = caps.first(where: { $0.hasPrefix("claude_") }) {
|
||||
@@ -190,14 +198,6 @@ class UsageViewModel: ObservableObject {
|
||||
|
||||
// MARK: - Fetch usage
|
||||
|
||||
private func claudeCookieHeader() async -> String? {
|
||||
let cookies = await WKWebsiteDataStore.default().httpCookieStore.allCookies()
|
||||
guard !cookies.isEmpty else { return nil }
|
||||
// Send all cookies from the app's WebView store — the session token may be
|
||||
// on any domain (claude.ai, anthropic.com, or an auth sub-service).
|
||||
return HTTPCookie.requestHeaderFields(with: cookies)["Cookie"]
|
||||
}
|
||||
|
||||
private func fetchUsage(orgId: String) async throws -> UsageResponse {
|
||||
let url = URL(string: "https://claude.ai/api/organizations/\(orgId)/usage")!
|
||||
let req = await claudeAPIRequest(for: url)
|
||||
|
||||
@@ -10,7 +10,7 @@
|
||||
[](https://swift.org)
|
||||
[](https://github.com/superdooper86/claudechecker/releases)
|
||||
[](LICENSE)
|
||||
[](https://github.com/superdooper86/claudechecker/releases/tag/v1.2.1-beta.7) <!-- BETA_BADGE -->
|
||||
[](https://github.com/superdooper86/claudechecker/releases/tag/v1.2.1-beta.14) <!-- BETA_BADGE -->
|
||||
|
||||
</div>
|
||||
|
||||
|
||||
+7
-9
@@ -1,12 +1,10 @@
|
||||
## What's new in v1.2.1
|
||||
|
||||
### Bug fixes
|
||||
- Fixed "Not signed in" showing incorrectly on launch when the session was already active
|
||||
- Sign-in state is now detected immediately from stored cookies on startup, before the first data refresh completes
|
||||
- Fixed login window auto-closing before the user could sign in — the login window now correctly loads the `/login` page so it only detects auth after the actual sign-in redirect
|
||||
- Fixed "No API key configured" showing after signing out — now correctly shows "Not signed in" with a prompt to sign in
|
||||
- Added `/api/organizations` as a final fallback for org ID resolution when the bootstrap API response doesn't include it
|
||||
- Fixed usage data not loading — API requests now include required browser-like headers (Origin, Referer, User-Agent)
|
||||
- Fixed Settings incorrectly showing "Signed in" after a failed refresh — sign-in state now resets when authentication fails
|
||||
- Rewrote login detection to use the WebView's own fetch call instead of inspecting cookie domains — correctly detects auth regardless of which domain the session token is stored on
|
||||
- Fixed API requests not including session cookies — now sends all cookies from the app's WebView store rather than filtering by domain
|
||||
- Fixed the root cause of "Not signed in" errors: URLSession was silently discarding the manually-set Cookie header because `httpShouldHandleCookies` defaults to `true`, which makes URLSession replace it with its own (empty) HTTPCookieStorage — claude.ai session cookies live in WKWebsiteDataStore, not HTTPCookieStorage. Setting `httpShouldHandleCookies = false` ensures the cookies are actually sent.
|
||||
- Added browser-like request headers (User-Agent, Origin, Referer) matching what Claude's API expects, consistent with the working Windows implementation
|
||||
- Removed background WKWebView complexity added in beta.12–13 — reverted to simple URLSession approach with correct cookie handling
|
||||
- Fixed login window auto-closing before the user could sign in — login window loads `/login` so auth is only detected after the actual sign-in redirect
|
||||
- Fixed login detection for Next.js SPA navigation using KVO on WebView URL (history.pushState doesn't trigger didFinish)
|
||||
- Added `/api/organizations` as a final fallback for org ID resolution
|
||||
- Fixed Settings incorrectly showing "Signed in" after a failed refresh
|
||||
|
||||
+3
-3
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"version": "1.2.1-beta.7",
|
||||
"url": "https://github.com/superdooper86/claudechecker/releases/download/v1.2.1-beta.7/ClaudeChecker.zip",
|
||||
"notes": "## What's new in v1.2.1\n\n### Bug fixes\n- Fixed \"Not signed in\" showing incorrectly on launch when the session was already active\n- Sign-in state is now detected immediately from stored cookies on startup, before the first data refresh completes\n- Fixed login window auto-closing before the user could sign in — the login window now correctly loads the `/login` page so it only detects auth after the actual sign-in redirect\n- Fixed \"No API key configured\" showing after signing out — now correctly shows \"Not signed in\" with a prompt to sign in\n- Added `/api/organizations` as a final fallback for org ID resolution when the bootstrap API response doesn't include it\n- Fixed usage data not loading — API requests now include required browser-like headers (Origin, Referer, User-Agent)\n- Fixed sign-in detection and cookie handling for accounts whose session cookies are on the `anthropic.com` domain rather than `claude.ai`\n- Fixed Settings incorrectly showing \"Signed in\" after a failed refresh — sign-in state now resets when authentication fails"
|
||||
"version": "1.2.1-beta.14",
|
||||
"url": "https://github.com/superdooper86/claudechecker/releases/download/v1.2.1-beta.14/ClaudeChecker.zip",
|
||||
"notes": "## What's new in v1.2.1\n\n### Bug fixes\n- Fixed the root cause of \"Not signed in\" errors: URLSession was silently discarding the manually-set Cookie header because `httpShouldHandleCookies` defaults to `true`, which makes URLSession replace it with its own (empty) HTTPCookieStorage — claude.ai session cookies live in WKWebsiteDataStore, not HTTPCookieStorage. Setting `httpShouldHandleCookies = false` ensures the cookies are actually sent.\n- Added browser-like request headers (User-Agent, Origin, Referer) matching what Claude's API expects, consistent with the working Windows implementation\n- Removed background WKWebView complexity added in beta.12–13 — reverted to simple URLSession approach with correct cookie handling\n- Fixed login window auto-closing before the user could sign in — login window loads `/login` so auth is only detected after the actual sign-in redirect\n- Fixed login detection for Next.js SPA navigation using KVO on WebView URL (history.pushState doesn't trigger didFinish)\n- Added `/api/organizations` as a final fallback for org ID resolution\n- Fixed Settings incorrectly showing \"Signed in\" after a failed refresh"
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user