A framed client app receives a working, origin-bound identity. The postMessage token is primary; the cookie question is only whether it is available as an optimisation.
https://app1.muster.calab.vip.Edge gutters first — they need no cooperation and keep working if pane.js is
stale. Then pane.js forwarding on app1 (swipe:"full").
swipe:"none"), drag the horizontal strip: the rail must not move,
and you must still be able to leave via the gutters or dots.A framed app cannot get its own push on iOS — that is what forces the broker. Prove the brokered path, and prove the registry gate.
Defensive check, not an architectural fork — the host app is top-level and owns the session. Confirm a framed client app cannot steal the lock-screen controls.
Open app2 — the probes run on load and log themselves. Every row should read refused, except the own-origin service worker, which is meant to succeed because isolation is by origin.
| Time | Test | Result | Source | Note |
|---|---|---|---|---|
| loading… | ||||