Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Remove the `cookieJar` injection point from `StoreSandboxSecretScreen`

Open Beginner friendly
#26,112 1 comment 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
75/100
Issue type
Refactor
Clarity
Clearly specified
Activity status
Active
Tech stack
ios, swift

Research direction

Start at WordPress/Classes/ViewRelated/Developer/StoreSandboxSecretScreen.swift (init around L38–L46) and drop or default the cookieJar parameter to HTTPCookieStorage.shared, renaming it cookieStorage if kept. Update DebugMenuViewController and the SwiftUI previews that pass the storage. Check WeeklyRoundupDebugScreen.swift L197–L201 for the copy-paste that constructs StoreSandboxSecretScreen. Done when the screen always writes the store_sandbox cookie to shared storage and the unused CookieJar naming is gone.

Written by the indexing model from the issue text.

Description

[Type] Tech Debt

Found while reviewing #26103.

StoreSandboxSecretScreen.init(cookieJar:) accepts any HTTPCookieStorage, but the screen only works when it is given HTTPCookieStorage.shared.

Details

https://github.com/wordpress-mobile/WordPress-iOS/blob/3db37280b4bd84f1cc4e68526f84c35d507149a6/WordPress/Classes/ViewRelated/Developer/StoreSandboxSecretScreen.swift#L38-L46

  • The screen writes the store_sandbox cookie into the injected storage.
  • Both consumers of that cookie read HTTPCookieStorage.shared directly — WebKitViewController.configureSandboxStore(_:) and SiteCreationPurchasingWebFlowController.injectSandboxStoreCookie(into:completion:).
  • Passing any other storage would write the secret where neither consumer looks, and the sandbox would silently not be applied.
  • The only production call site is DebugMenuViewController, which passes HTTPCookieStorage.shared. The other two callers are previews, and pass the same value.

The cookieJar name is also a leftover: as of #26103 the property is an HTTPCookieStorage, not a CookieJar.

Suggested fix

Drop the parameter and use HTTPCookieStorage.shared inside the screen. If the injection point is worth keeping for previews, default it to .shared and rename it cookieStorage.

Related

WeeklyRoundupDebugScreen_Preview instantiates StoreSandboxSecretScreen rather than WeeklyRoundupDebugScreen. That looks like a copy-paste slip, and it goes through the same initializer:

https://github.com/wordpress-mobile/WordPress-iOS/blob/3db37280b4bd84f1cc4e68526f84c35d507149a6/WordPress/Classes/ViewRelated/Developer/WeeklyRoundupDebugScreen.swift#L197-L201

Dominant language
Swift
Stars
3.9k
Forks
1.2k
Avg merge
1d 18h
Merged PRs (30d)
56

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from wordpress-mobile/WordPress-iOS

All issues in wordpress-mobile/WordPress-iOS

Similar issues

More Swift issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.