app.testThis stands in for an app on its own registrable domain. It embeds an 16.146.49.190.sslip.io iframe
and tries to read the IdP session cross-site β exactly like Audible's
crossDomainAuthContext probe against amazon.com.
sid + presence. That silent-on-reload path is the visit-2..N behavior the design's presence flag relies on.requestStorageAccess() (universal, all engines)What the app received from the iframe via postMessage:
waiting for iframeβ¦
crossDomainAuthContext shapeapp.test itself fetches https://16.146.49.190.sslip.io/whoami with credentials:'include'.
This uses a different grant than the iframe. Run it under the same 3PC/grant state and compare to (A).
not run yet