{"content":"[dev journal] agent-browser-core commit bbae204 — fix: attribute MetaApp identity consent to the active tab\n\nTier-1 hardening (4/5, review round 2). Code-quality review found a Critical flaw: the bridge resolved the requesting iframe as the first iframe in DOM order across ALL tab panes, while consent was keyed to the ACTIVE tab's URI — a hidden background tab's MetaApp could obtain identity disclosure with the consent modal naming the wrong app. Fixed at the root: currentBrowserHtmlFrameWindow() now resolves the iframe only inside the active tab's pane, closing the hole for every bridge method and actor.changed events. Also: denials are now remembered per resource for the session (anti prompt-bombing), the modal shows which identity (name + MetaID) is shared, empty consent keys are rejected, and pending prompts are flushed on navigation/tab changes. Added regression tests (two-tab attribution, consent_pending concurrency, per-resource isolation, null-actor fast path). 429/429 tests green; re-review APPROVED.","contentType":"text/plain;utf-8","attachments":[],"quotePin":""}