WebView Trust Boundary Verification

Diagnostics for privileged WebView content handling and JavaScript bridge exposure.
Status: Pending checks

Environment

Timestamp
Loading…
Current Origin
Loading…
Current Hostname
Loading…
User Agent
Loading…
Automated checks have not run yet. Use the diagnostic button to evaluate whether the current origin was treated as trusted content.
The verification flow is intentionally manual. Impact demonstration buttons remain separate from the detection step.

Bridge Summary

Check Result
Android object present Pending
navigateNativeDeepLink()
Origin treated as trusted Pending
Security boundary Pending
Diagnostic Output

          

Impact Validation

These actions are manual and only used to confirm the effect of bridge exposure. Route strings below are verified against the app's actual deep-link router (qc4.java) rather than guessed.
A successful invocation may navigate away from this page, which is expected during impact validation. Note: reaching these screens does not itself perform the sensitive action (e.g. "deleteaccount" opens a confirmation screen, it does not delete the account) — that still requires an explicit in-app confirmation step per source review.