In-app WebView bridge check

Authorized security research for Bugcrowd (Canva). This page runs on , which is not a Canva domain. It confirms the in-app bridge is reachable from this origin and harvests the account's own session cookie, which the off-device relay (worker.py) then uses to prove takeover away from the phone. It changes nothing. The cookie is hidden by default; use /full/ to see it.

running…