Problem
Every signed API sync (including the basic "sync all bookmarks") returns HTTP 406 {"code":-1,"success":false}. Nothing syncs.
Ruled out
- Re-login / re-extract cookie — still 406
- Pristine v1.2.0 release
main.js (unmodified) — still 406
- Not album-related: plain
/api/sns/web/v2/note/collect/page (no collect_id) 406s too
Findings
Intercepted the requests the logged-in in-app webview makes itself, vs the plugin's manually-signed ones:
- The webview's own
note/collect/page and board/user return 200
- The webview's own requests carry no
x-rap-param
- The webview's
x-s-common is much shorter than what signRequest() produces (different structure)
Looks like the SDK 4.2.6 x-s-common / fingerprint format is outdated vs the current XHS web (webBuild 6.12.3) and is rejected server-side.
Env: Obsidian (Windows), plugin v1.2.0; XHS webBuild 6.12.3, CN-region account.
Note: letting the webview's own page make the request and intercepting its response does return 200 — possible workaround.
Problem
Every signed API sync (including the basic "sync all bookmarks") returns
HTTP 406 {"code":-1,"success":false}. Nothing syncs.Ruled out
main.js(unmodified) — still 406/api/sns/web/v2/note/collect/page(nocollect_id) 406s tooFindings
Intercepted the requests the logged-in in-app webview makes itself, vs the plugin's manually-signed ones:
note/collect/pageandboard/userreturn 200x-rap-paramx-s-commonis much shorter than whatsignRequest()produces (different structure)Looks like the SDK
4.2.6x-s-common/ fingerprint format is outdated vs the current XHS web (webBuild 6.12.3) and is rejected server-side.Env: Obsidian (Windows), plugin v1.2.0; XHS
webBuild 6.12.3, CN-region account.Note: letting the webview's own page make the request and intercepting its response does return 200 — possible workaround.