AUTHORIZED TEST ENDPOINT
Water Run LIFF Lab
This page processes LIFF state only in this browser. It does not request a profile, access token, ID token, or location. For the authorized context test, an available chat-context identifier is reduced locally to a short SHA-256 prefix and the raw value is never rendered or transmitted.
Safe status
- LIFF configured
- No
- Initialized
- No
- In LIFF client
- Unknown
- Context type
- Not read
- Context ID proof
- Not read
- View type
- Not read
- Message API
- Unknown
- Granted lab scopes
- Not read
- Runtime class
- Not tested
- Native bridge
- Not tested
- Synthetic token
- Not tested
- File canary
- Not tested
- Cross-origin iframe
- Not tested
- Cross-origin main frame
- Not tested
- Foreign closeWindow
- Not tested
- Native callback escaping
- Not tested
- Native JS redirect/CSP
- Not tested
- Owner camera prime
- Not tested
- Foreign iframe camera
- Not tested
Waiting for configuration.
WebView boundary canaries
These checks use a synthetic local file and invalid token strings only. They do not read account data, chats, profile, location, or real tokens.
Explicit synthetic canary
Sending is never automatic. It requires both this checkbox and a button press, and sends only the fixed text shown below to the currently open owner-controlled test chat.
[AUTHORIZED LIFF LAB] synthetic canary