WebView origin / native-bridge reachability check

Diagnostic page for an authorised Bugcrowd test of the Canva Android app. This page runs on the origin . It records which in-app WebView interfaces are reachable from this origin and, if a message channel is available, issues one read-only API call (the same call the app uses to render the Projects screen) and shows the HTTP status and a short excerpt of the response. No data is modified. No credentials are supplied by this page.

1. Origin & bridge
2. Message channel handshake
waiting…
3. Read-only API call (/vfolders/listvirtualfolder)
waiting…