Conversation
…r test-runner handoff New tool.cookies method across protocol/daemon/CLI/extension, reusing the tool.evaluate sandbox: resolveTargetTab + enforceAgentWindow (Agent Window tabs only), query scoped to the tab's own URL via CDP Network.getCookies. Classified BrowserMutation so the pending-interrupt gate applies. Primary use case: export a logged-in session's cookies as JSON and load them into a headless test runner (Playwright storageState) for repeatable UI regression against production sites whose auth cookies are httpOnly and therefore invisible to Runtime.evaluate / document.cookie. Verified end to end against youtube.com: 23 cookies exported (15 httpOnly, incl. LOGIN_INFO/HSID/SSID); a Playwright context booted from the converted storageState renders the signed-in UI (avatar, personalized feed). Co-Authored-By: Claude Code <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Agents frequently need to hand a logged-in browser session to a headless test runner (Playwright
storageState, and similar) to get repeatable UI regression against production sites. Today that chain is broken: production auth cookies (LOGIN_INFO,HSID, …) arehttpOnly, so they are invisible toRuntime.evaluate/document.cookie, and the debug request capture does not include request headers. There is no legitimate path from "the site I opened in the Agent Window" to "a test-runner credential file" — even when the human explicitly wants exactly that.This PR adds one narrowly-scoped tool for that handoff.
What it adds
bsk cookies --session <id> [--tab-id N] [--json]→tool.cookiesCookiesParams/CookiesResult/CookieEntryinbsk-protocol(tool.cookiesMethod, unit-tested serde roundtrips)cookiessubcommand (same exit-code policy asevaluate)handleCookiesreusing thetool.evaluatesandbox verbatim —lookupSession→resolveTargetTab→enforceAgentWindow→ CDPNetwork.getCookiesSecurity red-lines honored (design §6)
This is the part I tried hardest to get right, since the obvious risk is turning this into a token-exfil window:
tool.evaluate(resolveTargetTab+enforceAgentWindow). Arbitrary user tabs are refused withpermission_denied; only sites the human explicitly handed to the agent can be exported.Network.getCookies { urls: [tab.url] }. The export cannot be widened to browser-wide, other domains, or "all cookies" — there is no parameter for it.BrowserMutation(conservative, same class astool.evaluate) rather than a passive read, so the pending-interrupt gate applies to it.http(s)tabs only — refused otherwise.If maintainers would prefer additional gating (e.g. an opt-in setting, or a user consent prompt per export), I'm happy to extend it — the current shape is the minimum that keeps the tool useful.
End-to-end verification
Against
youtube.com(signed-in session):The same conversion run with only
document.cookie-visible cookies stays signed out — i.e. the tool adds exactly the capability that was missing, nothing more.Notes for maintainers
1.3(old peers reject the unknown method with the usual version-skew error rather than breaking the handshake). Happy to bump to1.4if the project's convention prefers a minor bump for new methods.Unreleased / Addedentry.🤖 Generated with Claude Code