Files
amethyst/commons
Claude a6b6b08f29 fix(browser): one consent gate for every page-initiated download
Builds on the reported fix: every download a page starts (WebView
DownloadListener or the browser.download bridge message) becomes a
DownloadOffer shown on the consent card before anything is fetched
or written.

- Per-surface DownloadCooldown that actually runs (the old gate's
  cooldown stamp was never written), plus one offer prepared at a time
  so a page can't queue 25 MiB decodes.
- Cookies read on the main thread from the tab's own WebView profile
  again (the lambda was invoked on the download thread).
- Use the listener's contentLength instead of a pre-consent HEAD probe:
  no request leaves before the user says yes, no 10s card delay.
- The card shows and the save writes the same sanitized name; unknown
  sizes are hidden instead of "-1 B"; long names keep their extension.
- Inline data: URLs decode off the main thread; the rules (risky
  extensions, data: URL decoding with a hard cap, cooldown) move to
  commons with unit tests.
- Drop the hand-written values-es strings (Crowdin-managed) and the
  unused gate code.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E3cqjbY7FX2zrkGXCVXpFD
2026-09-30 19:28:24 +00:00
..