In-app WebView bridge check

Diagnostic page for an authorised Bugcrowd test of the Canva Android app. It runs on , which is not a Canva domain, and checks which in-app interfaces this origin can reach. Everything runs against the tester's own account; the two write steps below restore the original state immediately, so nothing is left changed.

1. Origin & bridge
2. Channel handshake (SYN → SYN-ACK → ACK)
waiting…
3. Read — folder list (POST /vfolders/listvirtualfolder)
waiting…
4. Read — account profile (GET /profile/users/<id>)
waiting…
5. Secure key-value store — write, read back, delete (temporary key)
waiting…
6. Design link access — set to public, then back to private
waiting…