699 B
699 B
WebView-Native Bridge Policy
Allowed Commands
| Command | Description |
|---|---|
getDeviceInfo |
Return device id, platform, app version |
registerPushToken |
Register current push token |
openBiometricPrompt |
Run biometric or device PIN prompt |
blockSession |
Block a session after native verification |
blockLinkedApp |
Block a linked RP after native verification |
openSettings |
Open native app settings |
Rules
- Do not pass private keys to WebView.
- Do not store long-lived refresh tokens in WebView storage.
- Validate origin and session before processing bridge commands.
- Native layer must verify sensitive commands before calling backend APIs.