Harden session boundary behavior - #11
Merged
Merged
Conversation
nicodes
added this pull request to stack #12
September 12, 2026 23:44
nicodes
force-pushed
the
issue-155-behavior
branch
from
September 12, 2026 23:45
7cbb383 to
de0f097
Compare
nicodes
force-pushed
the
issue-155-behavior
branch
from
September 12, 2026 23:45
de0f097 to
6875837
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
sessionStorageopt-in and caller-injected native credential persistence0.0.2Tracks aviorstudio/fieldsofrevik#155 without auto-closing the cross-repository issue before publication verification.
Acceptance evidence
JwtModule.inspect_unverified()validates three canonical base64url segments, UTF-8, JSON objects, algorithm policy, typed claims, exact integer bounds, and a 64 KiB cap. Metadata and expiry results remaintrusted = false; tests reachedTEST_REACHED:jwt_module_test:20.NativeCredentialAdapter; Web persistence requires explicitWEB_SESSION_STORAGE. JSON payloads are acyclic/lossless and capped at 1 MiB; tests reachedTEST_REACHED:session_store_module_test:26.OS.get_unique_id()and Web uses cryptographic process-memory IDs by default with explicit tab persistence. JavaScript APIs are invoked throughJavaScriptBridge.get_interface(...).call(...), including quoted/newline storage-key coverage; native tests reachedTEST_REACHED:client_id_module_test:4.PACKAGE_LIFECYCLE_REACHED:enable-restart-smoke-disable-restart), and packaged Web smoke (WEB_TEST_REACHED:packaged-addon-smoke). Local ZIP SHA-256:ddd012067fbb4a3060f1a560096daca2f01a485c65d6a8acb755e3901db5eaf0.playwright-cli0.1.18 against the Godot 4.7.2 Web export; 0 console errors, visible PASS, and direct assertions confirmed both escapedsessionStoragekeys and values.Local verification
Godot:
4.7.2.stable.official.ed1daf0bf. Playwright CLI:0.1.18.All passed. Gate-control error output is deliberate negative-control evidence followed by
CONTROL_FAILED_AS_EXPECTEDandCONTROL_RESTORED_PASS:pass.Exact-head CI
1ed6a5fc3f21d5e00a19f0b74e0a16ea2ee055degate-evidence-1ed6a5fc3f21d5e00a19f0b74e0a16ea2ee055de(10309241726)sha256:ed6a0b366e7f9acaa89a3375726fd6701178341e2152dd8ebbd896fb3794ef80ddd012067fbb4a3060f1a560096daca2f01a485c65d6a8acb755e3901db5eaf0, equal to the locally tested package; closed-manifest verification passed again after download.d21bcf23c965ab281b72670ae3e0b1f65300e1158329735df0b9d72cb3a531e3.No review requested or awaited (Team No Review).