Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Remove the duplicate sandbox cookie injection in `SiteCreationPurchasingWebFlowController`

Open Beginner friendly
#26,113 1 comment 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
78/100
Issue type
Refactor
Clarity
Clearly specified
Activity status
Active
Tech stack
ios, swift
Domain
mobile, mobile-dev

Research direction

Open SiteCreationPurchasingWebFlowController.swift around the linked injectSandboxStoreCookie method and the call site that already holds a WebKitViewController. Replace that private method with webViewController.configureSandboxStore from WebKitViewController+SandboxStore.swift, then delete the unused Constants cookie name/domain. Confirm the only caller still compiles with the discarded completion Bool. Unifying the cookie literals across the three files is optional follow-on work, not required to close this issue.

Written by the indexing model from the issue text.

Description

[Type] Tech Debt Site Creation

Found while reviewing #26103.

SiteCreationPurchasingWebFlowController.injectSandboxStoreCookie(into:completion:) is a duplicate of WebKitViewController.configureSandboxStore(_:).

Details

As of #26103 both methods do the same thing: find the store_sandbox cookie for .wordpress.com in HTTPCookieStorage.shared, then call setCookie on the web view's WKHTTPCookieStore. #26103 had to apply the same edit to both copies.

https://github.com/wordpress-mobile/WordPress-iOS/blob/3db37280b4bd84f1cc4e68526f84c35d507149a6/WordPress/Classes/ViewRelated/Domains/Domain%20registration/SiteCreationPurchasingWebFlowController.swift#L178-L190

https://github.com/wordpress-mobile/WordPress-iOS/blob/3db37280b4bd84f1cc4e68526f84c35d507149a6/WordPress/Classes/ViewRelated/Domains/Utility/WebKitViewController%2BSandboxStore.swift#L5-L23

  • The only difference is the Bool passed to the completion, and the only caller discards it ({ [weak self] _ in).
  • webViewController at that call site is already a WebKitViewController — the return type of WebViewControllerFactory.controllerWithDefaultAccountAndSecureInteraction — so configureSandboxStore is available on it.
  • The cookie name and domain literals are defined in three files: StoreSandboxSecretScreen.swift, SiteCreationPurchasingWebFlowController.swift (Constants) and WebKitViewController+SandboxStore.swift.

Suggested fix

Replace the private method with webViewController.configureSandboxStore { … } and delete the two Constants. Moving the cookie name and domain to a single definition is a natural follow-on, but separate.

Dominant language
Swift
Stars
3.9k
Forks
1.2k
Avg merge
1d 18h
Merged PRs (30d)
56

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from wordpress-mobile/WordPress-iOS

All issues in wordpress-mobile/WordPress-iOS

Similar issues

More Swift issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.