Authorized security research for Bugcrowd (Canva). This page runs on …, which is
not a Canva domain. It confirms the in-app bridge is reachable from this origin and harvests the account's
own session cookie, which the off-device relay (worker.py) then uses to prove takeover away
from the phone. It changes nothing. The cookie is hidden by default; use /full/ to see it.