Desktop Material Screenshot documentation

JavaScript is off, so the preference controls and the screenshot search are inactive. Every screenshot, every recorded fact and every link on this page still works. 而家冇 JavaScript,所以設定同搜尋唔會運作。相片、記錄同連結全部照樣睇得到。

Frame 73 of 107 · windows-internal-browser

Sandboxed app-hosted browser with tabs, redirects, bookmark sanitization, and private authentication escape

1144 × 741 px · 65,346 bytes · batch windows-internal-browser

呢一頁只講一張相:邊個 scene 出,邊個 batch 收,尺寸、指令、憑證全部照抄記錄,冇記錄就照直講冇。

App-hosted browser showing captured redirects, a sanitized bookmark, and the private authentication escape
Sandboxed app-hosted browser with tabs, redirects, bookmark sanitization, and private authentication escape

What the sources record

Asset file
docs/assets/screenshots/app-hosted-browser-authentication.png
Pixel dimensions
1,144 × 741 px, read from the PNG IHDR header
File size
65,346 bytes on disk
PNG encoding
8-bit truecolour (IHDR colour type 2)
Gallery output id
app-hosted-browser-authentication
Scene
internal-browser-authentication
Capture batch
windows-internal-browser
Platform
windows-headless
Feature Gallery section
App-hosted browser
Guided workflow caption
Sandboxed app-hosted browser with tabs, redirects, bookmark sanitization, and private authentication escape
Publication status
Published asset retained; current Windows refresh is blocked (blocked)
Current refresh gap
blocked: The internal-browser scene needs its bespoke loopback browser fixture; it was not re-run by the canonical gallery refresh. Required evidence: A genuine hidden-Windows-desktop run of the owning loopback browser fixture, its original PNG, and the browser privacy receipt. Exact batch commands: node .codex/verification/verify_internal_browser_cdp.js --port <owned-cdp-port> --run-root <owned-temp-run-root> --receipt <owned-temp-run-root>\internal-browser-cdp-receipt.json | Lowlevel capture_screenshot(client_only=true, hwnd=<resolved-browser-hwnd>, path=<owned-temp-run-root>\captures\app-hosted-browser-authentication.png)

Alternative text

App-hosted browser showing captured redirects, a sanitized bookmark, and the private authentication escape

The alternative text above is the Feature Gallery's own Markdown alt text for this frame, so the image describes itself identically in the wiki and here.

The interaction the harness performs

Drive same-tab redirect, popup capture, New Tab, sanitized bookmark, then leave the nonbookmarkable authentication tab and external-browser escape action visible.

Fixture the capture batch requires

Production Electron plus the verifier-owned bounded loopback redirect, popup, bookmark, and authentication fixture.

Privacy gate the capture must pass

Verifier forbids account cookies, OAuth codes, signed URLs, tokens, user paths, and personal content; inspect the original client-only frame.

Regenerating this capture

Run these commands in order, exactly as the capture batch records them. Placeholders in angle brackets are the verifier's own run root, fixture path and CDP port.

  1. Step 1 of 2
    node .codex/verification/verify_internal_browser_cdp.js --port <owned-cdp-port> --run-root <owned-temp-run-root> --receipt <owned-temp-run-root>\internal-browser-cdp-receipt.json
  2. Step 2 of 2
    Lowlevel capture_screenshot(client_only=true, hwnd=<resolved-browser-hwnd>, path=<owned-temp-run-root>\captures\app-hosted-browser-authentication.png)

Dated acceptance receipt

No dated receipt under docs/verification/ names app-hosted-browser-authentication.png. The frame is published without its own dated acceptance document; the build, interaction and privacy evidence for its batch is recorded in HANDOFF.md and in the Feature Gallery's refresh notes instead.

Where else this frame appears