iOS: authenticate each request by its own header only (no cookies/credential cache)

Two accounts can share one server; the Share Extension's folder listing and
the upload sessions now ignore cookies and stored credentials so one account's
session can never answer for another. Logs each PROPFIND (user, path, status).

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
Ayushya Amitabh
2026-10-06 20:18:20 -04:00
co-authored by Claude Sonnet 5.5
parent 02d612bfec
commit 02d9d799a6
3 changed files with 25 additions and 1 deletions
+5
View File
@@ -34,6 +34,11 @@ final class TransferManager: NSObject {
config.sessionSendsLaunchEvents = true
config.isDiscretionary = false
config.waitsForConnectivity = true
// Two accounts can share a server: authenticate by the request's own
// header only, never a cookie another account's request left behind.
config.httpShouldSetCookies = false
config.httpCookieAcceptPolicy = .never
config.urlCredentialStorage = nil
return URLSession(configuration: config, delegate: self, delegateQueue: nil)
}()