/** * Cookie picker UI — self-contained HTML page * * Dark theme, two-panel layout, vanilla HTML/CSS/JS. * Left: source browser domains with search + import buttons. * Right: imported domains with trash buttons. * No cookie values exposed anywhere. */ export function getCookiePickerHTML(serverPort: number, options: { pickerInstance?: string; browser?: string; profile?: string; targetOrigin?: string; verifyAuth?: boolean; clearStorage?: boolean; verificationAvailable?: boolean; storageResetAvailable?: boolean; } = {}): string { const baseUrl = `http://127.0.0.1:${serverPort}`; let targetOrigin: string | undefined; try { const target = new URL(options.targetOrigin ?? ''); if (['http:', 'https:'].includes(target.protocol)) targetOrigin = target.origin; } catch {} const config = JSON.stringify({ pickerInstance: options.pickerInstance, browser: options.browser, profile: options.profile, targetOrigin, verifyAuth: options.verifyAuth === true, clearStorage: options.clearStorage === true, verificationAvailable: options.verificationAvailable === true, storageResetAvailable: options.storageResetAvailable !== false, }).replace(/[<>&\u2028\u2029]/g, character => '\\u' + character.charCodeAt(0).toString(16).padStart(4, '0')); return `
Copy cookies from the browser and profile you choose to this GStack Browser session. Copying cookies does not prove that you are signed in. Cookies are shared by tabs in this session.