Frame 73 of 107 · windows-internal-browser
Sandboxed app-hosted browser with tabs, redirects, bookmark sanitization, and private authentication escape
1144 × 741 px · 65,346 bytes · batch windows-internal-browser
呢一頁只講一張相:邊個 scene 出,邊個 batch 收,尺寸、指令、憑證全部照抄記錄,冇記錄就照直講冇。
What the sources record
- Asset file
- docs/assets/screenshots/app-hosted-browser-authentication.png
- Pixel dimensions
- 1,144 × 741 px, read from the PNG IHDR header
- File size
- 65,346 bytes on disk
- PNG encoding
- 8-bit truecolour (IHDR colour type 2)
- Gallery output id
- app-hosted-browser-authentication
- Scene
- internal-browser-authentication
- Capture batch
- windows-internal-browser
- Platform
- windows-headless
- Feature Gallery section
- App-hosted browser
- Guided workflow caption
- Sandboxed app-hosted browser with tabs, redirects, bookmark sanitization, and private authentication escape
- Publication status
- Published asset retained; current Windows refresh is blocked (blocked)
- Current refresh gap
- blocked: The internal-browser scene needs its bespoke loopback browser fixture; it was not re-run by the canonical gallery refresh. Required evidence: A genuine hidden-Windows-desktop run of the owning loopback browser fixture, its original PNG, and the browser privacy receipt. Exact batch commands: node .codex/verification/verify_internal_browser_cdp.js --port <owned-cdp-port> --run-root <owned-temp-run-root> --receipt <owned-temp-run-root>\internal-browser-cdp-receipt.json | Lowlevel capture_screenshot(client_only=true, hwnd=<resolved-browser-hwnd>, path=<owned-temp-run-root>\captures\app-hosted-browser-authentication.png)
Alternative text
App-hosted browser showing captured redirects, a sanitized
bookmark, and the private authentication escape
The alternative text above is the Feature Gallery's own Markdown alt text for this frame, so the image describes itself identically in the wiki and here.
The interaction the harness performs
Drive same-tab redirect, popup capture, New Tab, sanitized bookmark, then leave the nonbookmarkable authentication tab and external-browser escape action visible.
Fixture the capture batch requires
Production Electron plus the verifier-owned bounded loopback redirect, popup, bookmark, and authentication fixture.
Privacy gate the capture must pass
Verifier forbids account cookies, OAuth codes, signed URLs, tokens, user paths, and personal content; inspect the original client-only frame.
Regenerating this capture
Run these commands in order, exactly as the capture batch records them. Placeholders in angle brackets are the verifier's own run root, fixture path and CDP port.
-
node .codex/verification/verify_internal_browser_cdp.js --port <owned-cdp-port> --run-root <owned-temp-run-root> --receipt <owned-temp-run-root>\internal-browser-cdp-receipt.json -
Lowlevel capture_screenshot(client_only=true, hwnd=<resolved-browser-hwnd>, path=<owned-temp-run-root>\captures\app-hosted-browser-authentication.png)
Dated acceptance receipt
No dated receipt under docs/verification/ names
app-hosted-browser-authentication.png. The frame is
published without its own dated acceptance document; the build,
interaction and privacy evidence for its batch is recorded in
HANDOFF.md and in the Feature Gallery's refresh notes
instead.