Repository navigation
Conversation
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…y default branch
|
@assaf758 is attempting to deploy a commit to the Manaflow Team on Vercel. A member of the Team first needs to authorize it. |
|
To use Codex here, create an environment for this repo. |
📝 WalkthroughWalkthroughThe PR introduces a WebKit TLS certificate bypass feature comprising a runtime-configurable BrowserCertBypassSettings enum, CLI startup flag --ignore-certificate-errors, socket command browser.cert_bypass for get/set actions, and browser delegate modifications to skip server trust validation when enabled. Changes
Sequence DiagramsequenceDiagram
participant WebView as WebView
participant NavDelegate as BrowserNavigationDelegate
participant Settings as BrowserCertBypassSettings
participant TLSChallenge as TLS Challenge Handler
WebView->>NavDelegate: didReceive(challenge)
NavDelegate->>NavDelegate: Check authenticationMethod == ServerTrust
NavDelegate->>Settings: isEnabled()
alt Bypass Enabled
Settings-->>NavDelegate: true
NavDelegate->>NavDelegate: Extract serverTrust credential
NavDelegate->>TLSChallenge: useCredential(serverTrust)
TLSChallenge-->>WebView: Accept connection
else Bypass Disabled
Settings-->>NavDelegate: false
NavDelegate->>TLSChallenge: Default handling
TLSChallenge-->>WebView: Standard cert validation
end
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~22 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 2 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (2 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Greptile SummaryThis PR adds Chrome-style TLS certificate bypass for local development against HTTPS servers with self-signed or unknown-root certificates. It introduces
Confidence Score: 3/5
Important Files Changed
Sequence DiagramsequenceDiagram
participant CLI as cmux CLI
participant App as cmuxApp.init()
participant TC as TerminalController
participant CBS as BrowserCertBypassSettings<br/>(@MainActor)
participant UD as UserDefaults
participant ND as BrowserNavigationDelegate
Note over App,CBS: Launch path
CLI->>App: --ignore-certificate-errors
App->>CBS: runtimeOverride = true
Note over CLI,CBS: Runtime socket path
CLI->>TC: browser.cert_bypass set true
TC->>TC: v2MainSync { }
TC->>CBS: runtimeOverride = true
TC-->>CLI: {"enabled": true}
CLI->>TC: browser.cert_bypass get
TC->>TC: v2MainSync { }
TC->>CBS: isEnabled()
CBS->>UD: bool(forKey:) [fallback only]
CBS-->>TC: true / false
TC-->>CLI: {"enabled": true/false}
Note over ND,CBS: TLS challenge path (always main thread)
ND->>CBS: isEnabled() [⚠ no @MainActor on ND]
CBS-->>ND: true
ND-->>ND: completionHandler(.useCredential, trust)
Last reviewed commit: 14d2322 |
| if challenge.protectionSpace.authenticationMethod == NSURLAuthenticationMethodServerTrust, | ||
| BrowserCertBypassSettings.isEnabled(), | ||
| let serverTrust = challenge.protectionSpace.serverTrust { |
There was a problem hiding this comment.
@MainActor isolation violation in delegate callback
BrowserCertBypassSettings is annotated @MainActor, meaning all its static members (runtimeOverride, isEnabled()) are main-actor-isolated. BrowserNavigationDelegate is a plain NSObject subclass without @MainActor isolation, so the call to BrowserCertBypassSettings.isEnabled() here is a Swift concurrency isolation violation.
While WKNavigationDelegate callbacks are always dispatched on the main thread at runtime, Swift's type system does not know this — there is no @MainActor annotation on the class or method to make it verifiable at compile time. Under Swift 6 strict concurrency (-strict-concurrency=complete), this will be a compiler error.
The fix is either to annotate BrowserNavigationDelegate (or at least this method) as @MainActor, or mark BrowserCertBypassSettings as nonisolated(unsafe) if the invariant is enforced by a comment:
// Option A — annotate the class or method:
@MainActor
func webView(
_ webView: WKWebView,
didReceive challenge: URLAuthenticationChallenge,
completionHandler: @escaping (URLSession.AuthChallengeDisposition, URLCredential?) -> Void
) {or add @MainActor to the BrowserNavigationDelegate class declaration itself.
| return 0 | ||
|
|
There was a problem hiding this comment.
Test teardown sets runtimeOverride to a concrete value instead of clearing it
The finally block restores runtimeOverride to True or False — never to its original state of None (the sentinel that causes isEnabled() to fall back to UserDefaults). If the app was started without --ignore-certificate-errors and without a UserDefaults entry (so initial == False comes from the UserDefaults.bool default of false, not from an explicit override), then after this test runtimeOverride is permanently set to False, shadowing any live UserDefaults change for the rest of the session.
This means a developer who has defaults write ai.manaflow.cmux browserIgnoreCertificateErrors -bool true set would find bypass silently disabled after the test suite runs.
A safer teardown would be to add a reset action to the socket command (and call it here), or accept that the test is destructive and document it clearly:
finally:
# NOTE: this sets runtimeOverride to False, not None.
# If the initial state relied on UserDefaults it will be shadowed
# for the rest of the session.
c._call("browser.cert_bypass", {"action": "set", "value": "true" if initial else "false"})| private func v2BrowserCertBypass(params: [String: Any]) -> V2CallResult { | ||
| let action = (params["action"] as? String) ?? (params["args"] as? [String])?.first ?? "" | ||
| switch action { | ||
| case "get": | ||
| var result: V2CallResult = .err(code: "internal", message: "Unexpected", data: nil) | ||
| v2MainSync { | ||
| result = .ok(["enabled": BrowserCertBypassSettings.isEnabled()]) | ||
| } | ||
| return result | ||
| case "set": | ||
| let rawValue = (params["args"] as? [String])?.dropFirst().first | ||
| ?? (params["value"] as? String) | ||
| ?? (params["enabled"] as? Bool).map { $0 ? "true" : "false" } | ||
| guard let rawValue else { | ||
| return .err(code: "invalid_params", message: "Missing value: use 'set true' or 'set false'", data: nil) | ||
| } | ||
| switch rawValue.lowercased() { | ||
| case "true", "1", "yes": | ||
| v2MainSync { BrowserCertBypassSettings.runtimeOverride = true } | ||
| return .ok(["enabled": true]) | ||
| case "false", "0", "no": | ||
| v2MainSync { BrowserCertBypassSettings.runtimeOverride = false } | ||
| return .ok(["enabled": false]) | ||
| default: | ||
| return .err(code: "invalid_params", message: "Invalid value '\(rawValue)': use 'true' or 'false'", data: nil) | ||
| } | ||
| default: | ||
| return .err(code: "invalid_params", message: "Unknown action '\(action)': use 'get' or 'set'", data: nil) | ||
| } | ||
| } |
There was a problem hiding this comment.
No reset action to clear runtimeOverride back to nil
Once runtimeOverride is set to false (either by cert-bypass set false or by the test), there is no way to restore the nil sentinel that defers to UserDefaults. A developer who has browserIgnoreCertificateErrors=true in UserDefaults and then runs cert-bypass set false to temporarily disable it cannot get back to "use UserDefaults" without restarting the app.
Consider adding a reset action:
case "reset":
v2MainSync { BrowserCertBypassSettings.runtimeOverride = nil }
var result: V2CallResult = .err(code: "internal", message: "Unexpected", data: nil)
v2MainSync {
result = .ok(["enabled": BrowserCertBypassSettings.isEnabled()])
}
return resultThis would also solve the test teardown issue described above.
There was a problem hiding this comment.
Actionable comments posted: 7
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@CLI/cmux.swift`:
- Line 5054: The new help text "cert-bypass [get | set <true|false>]" in
CLI/cmux.swift is currently raw English; replace the literal string with a
localized call using String(localized: "cli.cert-bypass.help", defaultValue:
"cert-bypass [get | set <true|false>]") (or a similarly named key) and then add
that key and English value to Resources/Localizable.xcstrings; ensure you update
any call sites that display the help so they use the localized string (search
for the exact literal or the function that builds the help lines in
CLI/cmux.swift to locate where to substitute).
- Around line 3906-3919: Validate the argument count for the "cert-bypass"
subcommand before calling client.sendV2: check subArgs and ensure only allowed
forms ("get" with exactly 0 extra tokens, or "set" followed by exactly one value
and no additional tokens); if the arity is invalid, emit a clear error/usage
message via output and return without calling client.sendV2. Update the block
that sets action/params (references: subArgs, action, params, payload,
client.sendV2, output) to perform this validation and only populate
params["value"] and call client.sendV2 when the argument count matches the
expected "set <true|false>" pattern.
In `@docs/superpowers/plans/2026-03-10-webkit-cert-bypass.md`:
- Around line 230-240: The CLI examples use the old socket-style name and flags;
update them to the actual user-facing CLI syntax used by this PR: replace
occurrences like "cmux browser.cert_bypass --action get" and "cmux
browser.cert_bypass --action set --value true/false" with the correct forms
"cmux browser cert-bypass get" and "cmux browser cert-bypass set true" (and
"cmux browser cert-bypass set false"), and make the same changes for the other
affected block (lines ~350-359) so all examples show "cmux browser cert-bypass
get|set <true|false>".
In `@docs/superpowers/specs/2026-03-10-webkit-cert-bypass-design.md`:
- Around line 59-63: Add a language tag to the fenced code block that contains
the browser.cert_bypass examples (the block starting with "browser.cert_bypass
get → {"enabled": true|false}" and the two set lines) by changing the opening
triple backticks to include a tag like "text" so Markdownlint stops flagging it
and syntax highlighting is preserved.
In `@Sources/Panels/BrowserPanel.swift`:
- Around line 3820-3831: The unconditional server-trust bypass accepts all
NSURLAuthenticationMethodServerTrust challenges when
BrowserCertBypassSettings.isEnabled(), which is too broad; update the
conditional in the authentication challenge handler to also verify the host is a
development/loopback host or is present in an explicit allowlist before calling
completionHandler(.useCredential, URLCredential(trust: serverTrust)).
Specifically, keep the existing checks for NSURLAuthenticationMethodServerTrust
and serverTrust, but add a guard that inspects challenge.protectionSpace.host
(e.g., allow "localhost", "127.0.0.1", "::1", or configured dev hostnames) or
consults a BrowserCertBypassSettings.allowlist API, and only return
.useCredential when that host check passes.
In `@Sources/TerminalController.swift`:
- Around line 1984-1985: The dispatcher wires the method via the case
"browser.cert_bypass" and implements it in v2BrowserCertBypass, but
v2Capabilities() does not advertise "browser.cert_bypass", so clients
discovering methods via system.capabilities may not see it; update
v2Capabilities() to include "browser.cert_bypass" in the capability
list/response (the same collection returned by
v2Capabilities()/system.capabilities) so the advertised capabilities match the
implemented handler.
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 99ae8758-dafc-445d-bbb9-0b69d8d7667a
📒 Files selected for processing (7)
CLI/cmux.swiftSources/Panels/BrowserPanel.swiftSources/TerminalController.swiftSources/cmuxApp.swiftdocs/superpowers/plans/2026-03-10-webkit-cert-bypass.mddocs/superpowers/specs/2026-03-10-webkit-cert-bypass-design.mdtests_v2/test_browser_cert_bypass.py
| if subcommand == "cert-bypass" { | ||
| let action = subArgs.first ?? "get" | ||
| var params: [String: Any] = ["action": action] | ||
| if let value = subArgs.dropFirst().first { | ||
| params["value"] = value | ||
| } | ||
| let payload = try client.sendV2(method: "browser.cert_bypass", params: params) | ||
| if let enabled = payload["enabled"] as? Bool { | ||
| output(payload, fallback: enabled ? "true" : "false") | ||
| } else { | ||
| output(payload, fallback: "OK") | ||
| } | ||
| return | ||
| } |
There was a problem hiding this comment.
Validate cert-bypass arity before forwarding.
This branch silently ignores tokens after the first value. For example, cmux browser cert-bypass set true typo will still execute set true, which hides user mistakes and diverges from the documented get | set <true|false> contract.
🛠️ Suggested validation
if subcommand == "cert-bypass" {
- let action = subArgs.first ?? "get"
- var params: [String: Any] = ["action": action]
- if let value = subArgs.dropFirst().first {
- params["value"] = value
- }
+ let normalizedArgs = subArgs.map { $0.lowercased() }
+ let action = normalizedArgs.first ?? "get"
+ guard action == "get" || action == "set" else {
+ throw CLIError(message: "browser cert-bypass requires 'get' or 'set <true|false>'")
+ }
+ guard normalizedArgs.count <= 2 else {
+ throw CLIError(message: "browser cert-bypass accepts: get | set <true|false>")
+ }
+
+ var params: [String: Any] = ["action": action]
+ if action == "set" {
+ guard let value = normalizedArgs.dropFirst().first,
+ parseBoolString(value) != nil else {
+ throw CLIError(message: "browser cert-bypass set requires <true|false>")
+ }
+ params["value"] = value
+ } else if normalizedArgs.count > 1 {
+ throw CLIError(message: "browser cert-bypass get does not accept a value")
+ }
let payload = try client.sendV2(method: "browser.cert_bypass", params: params)
if let enabled = payload["enabled"] as? Bool {
output(payload, fallback: enabled ? "true" : "false")🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@CLI/cmux.swift` around lines 3906 - 3919, Validate the argument count for the
"cert-bypass" subcommand before calling client.sendV2: check subArgs and ensure
only allowed forms ("get" with exactly 0 extra tokens, or "set" followed by
exactly one value and no additional tokens); if the arity is invalid, emit a
clear error/usage message via output and return without calling client.sendV2.
Update the block that sets action/params (references: subArgs, action, params,
payload, client.sendV2, output) to perform this validation and only populate
params["value"] and call client.sendV2 when the argument count matches the
expected "set <true|false>" pattern.
| viewport <width> <height> | ||
| geolocation|geo <latitude> <longitude> | ||
| offline <true|false> | ||
| cert-bypass [get | set <true|false>] |
There was a problem hiding this comment.
Localize the new browser help entry.
This adds new user-facing help text as raw English in Swift source. Please move it through the localization path and add the key to Resources/Localizable.xcstrings.
As per coding guidelines, "All user-facing strings must be localized using String(localized: "key.name", defaultValue: "English text") and added to Resources/Localizable.xcstrings."
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@CLI/cmux.swift` at line 5054, The new help text "cert-bypass [get | set
<true|false>]" in CLI/cmux.swift is currently raw English; replace the literal
string with a localized call using String(localized: "cli.cert-bypass.help",
defaultValue: "cert-bypass [get | set <true|false>]") (or a similarly named key)
and then add that key and English value to Resources/Localizable.xcstrings;
ensure you update any call sites that display the help so they use the localized
string (search for the exact literal or the function that builds the help lines
in CLI/cmux.swift to locate where to substitute).
| **How callers invoke it via CLI:** | ||
| ```bash | ||
| # Get current state | ||
| cmux browser.cert_bypass --action get | ||
|
|
||
| # Enable (session-only, does not persist) | ||
| cmux browser.cert_bypass --action set --value true | ||
|
|
||
| # Disable | ||
| cmux browser.cert_bypass --action set --value false | ||
| ``` |
There was a problem hiding this comment.
Use the actual CLI syntax in these examples.
These snippets are showing the socket method name and --action/--value params, but the user-facing CLI for this PR is cmux browser cert-bypass get|set <true|false>. Keeping the underscore form here will point readers at a command shape that doesn’t exist.
📝 Suggested fix
-# Get current state
-cmux browser.cert_bypass --action get
+# Get current state
+cmux browser cert-bypass get
-# Enable (session-only, does not persist)
-cmux browser.cert_bypass --action set --value true
+# Enable (session-only, does not persist)
+cmux browser cert-bypass set true
-# Disable
-cmux browser.cert_bypass --action set --value false
+# Disable
+cmux browser cert-bypass set false-# Toggle at runtime (session-only)
-cmux browser.cert_bypass --action set --value true
+# Toggle at runtime (session-only)
+cmux browser cert-bypass set trueAlso applies to: 350-359
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@docs/superpowers/plans/2026-03-10-webkit-cert-bypass.md` around lines 230 -
240, The CLI examples use the old socket-style name and flags; update them to
the actual user-facing CLI syntax used by this PR: replace occurrences like
"cmux browser.cert_bypass --action get" and "cmux browser.cert_bypass --action
set --value true/false" with the correct forms "cmux browser cert-bypass get"
and "cmux browser cert-bypass set true" (and "cmux browser cert-bypass set
false"), and make the same changes for the other affected block (lines ~350-359)
so all examples show "cmux browser cert-bypass get|set <true|false>".
| ``` | ||
| browser.cert_bypass get → {"enabled": true|false} (reflects effective state) | ||
| browser.cert_bypass set true → {"enabled": true} (sets runtimeOverride, session only) | ||
| browser.cert_bypass set false → {"enabled": false} (sets runtimeOverride, session only) | ||
| ``` |
There was a problem hiding this comment.
Add a language tag to this fenced block.
Markdownlint is already flagging this block, and labeling it (text is enough here) will fix the warning and preserve syntax highlighting.
📝 Suggested fix
-```
+```text
browser.cert_bypass get → {"enabled": true|false} (reflects effective state)
browser.cert_bypass set true → {"enabled": true} (sets runtimeOverride, session only)
browser.cert_bypass set false → {"enabled": false} (sets runtimeOverride, session only)
</details>
<details>
<summary>🧰 Tools</summary>
<details>
<summary>🪛 markdownlint-cli2 (0.21.0)</summary>
[warning] 59-59: Fenced code blocks should have a language specified
(MD040, fenced-code-language)
</details>
</details>
<details>
<summary>🤖 Prompt for AI Agents</summary>
Verify each finding against the current code and only fix it if needed.
In @docs/superpowers/specs/2026-03-10-webkit-cert-bypass-design.md around lines
59 - 63, Add a language tag to the fenced code block that contains the
browser.cert_bypass examples (the block starting with "browser.cert_bypass get →
{"enabled": true|false}" and the two set lines) by changing the opening triple
backticks to include a tag like "text" so Markdownlint stops flagging it and
syntax highlighting is preserved.
</details>
<!-- fingerprinting:phantom:poseidon:grasshopper -->
<!-- This is an auto-generated comment by CodeRabbit -->
| // When certificate bypass is active (--ignore-certificate-errors or browser.cert_bypass set true), | ||
| // unconditionally trust server certificates. This covers self-signed and unknown-root certs | ||
| // common in local development (e.g. https://localhost:8443). Only server trust challenges | ||
| // are bypassed; client cert and other challenge types still use default handling. | ||
| if challenge.protectionSpace.authenticationMethod == NSURLAuthenticationMethodServerTrust, | ||
| BrowserCertBypassSettings.isEnabled(), | ||
| let serverTrust = challenge.protectionSpace.serverTrust { | ||
| #if DEBUG | ||
| dlog("browser.cert_bypass: accepting server trust for \(challenge.protectionSpace.host)") | ||
| #endif | ||
| completionHandler(.useCredential, URLCredential(trust: serverTrust)) | ||
| return |
There was a problem hiding this comment.
Scope the bypass to development hosts.
With the current condition, enabling this flag accepts every NSURLAuthenticationMethodServerTrust challenge, not just self-signed localhost/dev endpoints. Because the default can also come from UserDefaults, this silently disables certificate validation for arbitrary remote sites too, which is broader than the stated local-dev use case. Please gate this with an explicit loopback/dev-host check or a dedicated allowlist before returning .useCredential.
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@Sources/Panels/BrowserPanel.swift` around lines 3820 - 3831, The
unconditional server-trust bypass accepts all
NSURLAuthenticationMethodServerTrust challenges when
BrowserCertBypassSettings.isEnabled(), which is too broad; update the
conditional in the authentication challenge handler to also verify the host is a
development/loopback host or is present in an explicit allowlist before calling
completionHandler(.useCredential, URLCredential(trust: serverTrust)).
Specifically, keep the existing checks for NSURLAuthenticationMethodServerTrust
and serverTrust, but add a guard that inspects challenge.protectionSpace.host
(e.g., allow "localhost", "127.0.0.1", "::1", or configured dev hostnames) or
consults a BrowserCertBypassSettings.allowlist API, and only return
.useCredential when that host check passes.
| case "browser.cert_bypass": | ||
| return v2Result(id: id, self.v2BrowserCertBypass(params: params)) |
There was a problem hiding this comment.
Advertise browser.cert_bypass in system.capabilities.
Line 1984 wires the method into the dispatcher, but v2Capabilities() still omits it. Clients that discover methods through system.capabilities will assume this API is unavailable and never call it.
Suggested follow-up
"browser.input_mouse",
"browser.input_keyboard",
"browser.input_touch",
+ "browser.cert_bypass",🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@Sources/TerminalController.swift` around lines 1984 - 1985, The dispatcher
wires the method via the case "browser.cert_bypass" and implements it in
v2BrowserCertBypass, but v2Capabilities() does not advertise
"browser.cert_bypass", so clients discovering methods via system.capabilities
may not see it; update v2Capabilities() to include "browser.cert_bypass" in the
capability list/response (the same collection returned by
v2Capabilities()/system.capabilities) so the advertised capabilities match the
implemented handler.
| private func v2BrowserCertBypass(params: [String: Any]) -> V2CallResult { | ||
| let action = (params["action"] as? String) ?? (params["args"] as? [String])?.first ?? "" | ||
| switch action { | ||
| case "get": | ||
| var result: V2CallResult = .err(code: "internal", message: "Unexpected", data: nil) | ||
| v2MainSync { | ||
| result = .ok(["enabled": BrowserCertBypassSettings.isEnabled()]) | ||
| } | ||
| return result | ||
| case "set": | ||
| let rawValue = (params["args"] as? [String])?.dropFirst().first | ||
| ?? (params["value"] as? String) | ||
| ?? (params["enabled"] as? Bool).map { $0 ? "true" : "false" } | ||
| guard let rawValue else { | ||
| return .err(code: "invalid_params", message: "Missing value: use 'set true' or 'set false'", data: nil) | ||
| } | ||
| switch rawValue.lowercased() { | ||
| case "true", "1", "yes": | ||
| v2MainSync { BrowserCertBypassSettings.runtimeOverride = true } | ||
| return .ok(["enabled": true]) | ||
| case "false", "0", "no": | ||
| v2MainSync { BrowserCertBypassSettings.runtimeOverride = false } | ||
| return .ok(["enabled": false]) | ||
| default: | ||
| return .err(code: "invalid_params", message: "Invalid value '\(rawValue)': use 'true' or 'false'", data: nil) | ||
| } | ||
| default: | ||
| return .err(code: "invalid_params", message: "Unknown action '\(action)': use 'get' or 'set'", data: nil) | ||
| } | ||
| } |
There was a problem hiding this comment.
Localize the new response messages.
This handler adds new user-visible socket/CLI messages as hard-coded English strings. Please route them through String(localized:..., defaultValue:...) and add the keys to Resources/Localizable.xcstrings.
As per coding guidelines, "All user-facing strings must be localized using String(localized: "key.name", defaultValue: "English text") and added to Resources/Localizable.xcstrings."
There was a problem hiding this comment.
No issues found across 7 files
Since this is your first cubic review, here's how it works:
- cubic automatically reviews your code and comments on bugs and improvements
- Teach cubic by replying to its comments. cubic learns from your replies and gets better over time
- Add one-off context when rerunning by tagging
@cubic-dev-aiwith guidance or docs links (includingllms.txt) - Ask questions if you need clarification on any suggestion
Summary
Adds Chrome-style certificate bypass for local development against HTTPS servers with self-signed or unknown-root certificates.
browserIgnoreCertificateErrorsfor persistent defaultUsage
Launch with bypass active:
cmux --ignore-certificate-errors
Toggle at runtime:
cmux browser cert-bypass set true
cmux browser cert-bypass get
Persist across restarts:
defaults write ai.manaflow.cmux browserIgnoreCertificateErrors -bool true
Implementation notes
Testing
Demo Video
NA
Review Trigger (Copy/Paste as PR comment)
Checklist
Summary by cubic
Adds a Chrome-style certificate bypass so the embedded browser can load self-signed or unknown-root HTTPS servers during local development. Only
NSURLAuthenticationMethodServerTrustis bypassed; client cert flows, MDM/Entra CA trust, and SSO extensions are unaffected.New Features
--ignore-certificate-errorslaunch flag enables session-only bypass.browser cert-bypass get|set <true|false>CLI/socket toggle at runtime (session-only).browserIgnoreCertificateErrorsin UserDefaults; runtime/flag take precedence.tests_v2/test_browser_cert_bypass.py.Migration
cmux --ignore-certificate-errorscmux browser cert-bypass set trueandcmux browser cert-bypass getdefaults write ai.manaflow.cmux browserIgnoreCertificateErrors -bool trueWritten for commit 14d2322. Summary will update on new commits.
Summary by CodeRabbit
New Features
--ignore-certificate-errorsCLI flag at startup or thebrowser.cert_bypasssocket command at runtime (get/set actions).Documentation