|
UnENVerse 0.42.6
Local-first desktop secrets manager — TypeScript frontend
|
Web session provider presets — Phase 24.5. More...
import presetsJson;Functions | |
| function export | presets () |
| function export | findPreset (id:string) |
| Required cookies the entry's jar does not have. | |
| function async | sapisidHash (sapisid:string, origin:string, nowMs=Date.now()) |
SHA1(timestamp + " " + SAPISID + " " + origin), hex-encoded — the one derivation this module actually computes rather than copies. | |
| for (const recipe of preset.header_recipe) | |
Variables | |
| export interface | HeaderRecipeEntry |
| source | __pad0__ |
| static_value | __pad1__ |
| cookie_name | __pad2__ |
| strip_quotes | __pad3__ |
| derived_id | __pad4__ |
| export interface | SessionPreset |
| label | __pad5__ |
| required_cookies | __pad6__ |
| optional_cookies | __pad7__ |
| header_recipe | __pad8__ |
| bindings | __pad9__ |
What the session is bound to — user_agent and/or origin. | |
| verified_on | __pad10__ |
| const | PRESETS |
| const | out |
| value | __pad11__ |
Web session provider presets — Phase 24.5.
session-presets.json names, for a handful of sites, which cookies a session needs and what header a copy derives from them. Nothing here is fetched or verified automatically — the form flags a missing required cookie by name, and that is the whole feature. Every preset carries the date its shape was last checked against a real capture; treat an old one as a starting point, not a guarantee the site has not changed since.
The one real computation is sapisidhash — YouTube/Google's Authorization: SAPISIDHASH <ts>_<sha1(ts + " " + SAPISID + " " + origin)> — which is why deriveHeaders is async: crypto.subtle.digest is a promise, and there is no synchronous SHA-1 in a browser without a bundled library the CSP would have to allow.
| function export presets | ( | ) |
| function export findPreset | ( | id:string | ) |
Required cookies the entry's jar does not have.
Empty means the session is complete as far as this preset can tell.
| function async sapisidHash | ( | sapisid:string, | |
| origin:string, | |||
nowMs = Date.now() |
|||
| ) |
SHA1(timestamp + " " + SAPISID + " " + origin), hex-encoded — the one derivation this module actually computes rather than copies.
SHA-1 here is not a security choice, it is Google's: this is the exact legacy algorithm their own endpoints still require for this header, unlike every other use of a hash in this project. One header per recipe entry the jar can actually satisfy — a cookie source with no matching cookie, or a derived source this module does not know how to compute, is silently omitted rather than emitted empty or thrown; the caller decides whether that is fatal.
| for | ( | const recipe of preset. | header_recipe | ) |
| export interface HeaderRecipeEntry |
| source __pad0__ |
| static_value __pad1__ |
| cookie_name __pad2__ |
| strip_quotes __pad3__ |
| derived_id __pad4__ |
| export interface SessionPreset |
| label __pad5__ |
| required_cookies __pad6__ |
| optional_cookies __pad7__ |
| header_recipe __pad8__ |
| bindings __pad9__ |
What the session is bound to — user_agent and/or origin.
Copying it under a different one of these usually 401s or gets flagged; the form warns rather than blocks, since "usually" is not "always".
| verified_on __pad10__ |
| const PRESETS |
| return out |
| value __pad11__ |