Track HTTPS embedded app gate and remaining payment recovery boundaries

This commit is contained in:
archipelago
2026-10-06 14:56:34 -04:00
parent 9771378bfd
commit c3bfbe8519
3 changed files with 43 additions and 0 deletions
+6
View File
@@ -372,3 +372,9 @@ as a substitute for repairing the standard public-channel experience.
absolute positioning that overlaps content. Verify tall neighbours, shrinking
results, long labels, keyboard access and mobile/desktop layouts.
- Record actual browser geometry checks and deployment acceptance separately.
## 17. HTTPS embedded app authentication (reported 6 October)
- User reports opening apps inside an iframe on an HTTPS node shows the app gate, while opening the same app in a separate tab works. Reproduce both modes with the same authenticated session before identifying a cause.
- Trace generated launch origins, cookie attributes and scope, bootstrap redirects, iframe navigation and gate session exchange. Preserve authentication and public-management access restrictions; do not bypass the gate or expose credentials to embedded apps.
- Test HTTPS iframe and tab, HTTP LAN compatibility, desktop/mobile companion, reload, expired sessions, denied access and logout. Record actual-node evidence separately from fixtures. This remains open, not a confirmed diagnosis.