WebView origin / native-bridge reachability check

Diagnostic page for an authorised Bugcrowd test of the Canva Android app. This page runs on the origin , which is not a Canva domain. It records which in-app WebView interfaces are reachable from this origin and, if the native message channel can be established, issues one read-only API call (the same call the app uses to list the current account's folders) and shows the HTTP status plus a short excerpt of the response. No data is modified.

1. Origin & bridge
2. Channel handshake (SYN / SYN-ACK / ACK)
waiting…
3. Read-only API call — POST /vfolders/listvirtualfolder
waiting…