AUTHORIZED TEST ENDPOINT

Water Run LIFF Lab

This page processes LIFF state only in this browser. It does not request a profile, access token, ID token, or location. For the authorized context test, an available chat-context identifier is reduced locally to a short SHA-256 prefix and the raw value is never rendered or transmitted.

Safe status

LIFF configured
No
Initialized
No
In LIFF client
Unknown
Context type
Not read
Context ID proof
Not read
View type
Not read
Message API
Unknown
Granted lab scopes
Not read
Runtime class
Not tested
Native bridge
Not tested
Synthetic token
Not tested
File canary
Not tested
Cross-origin iframe
Not tested
Cross-origin main frame
Not tested
Foreign closeWindow
Not tested
Native callback escaping
Not tested
Native JS redirect/CSP
Not tested
Owner camera prime
Not tested
Foreign iframe camera
Not tested

Waiting for configuration.

WebView boundary canaries

These checks use a synthetic local file and invalid token strings only. They do not read account data, chats, profile, location, or real tokens.

Explicit synthetic canary

Sending is never automatic. It requires both this checkbox and a button press, and sends only the fixed text shown below to the currently open owner-controlled test chat.

[AUTHORIZED LIFF LAB] synthetic canary