Skip to content

All sync returns HTTP 406 — signed requests rejected (likely outdated x-s-common vs webBuild 6.12.3) #2

Description

@ZhangdingLiu

Problem
Every signed API sync (including the basic "sync all bookmarks") returns HTTP 406 {"code":-1,"success":false}. Nothing syncs.

Ruled out

  • Re-login / re-extract cookie — still 406
  • Pristine v1.2.0 release main.js (unmodified) — still 406
  • Not album-related: plain /api/sns/web/v2/note/collect/page (no collect_id) 406s too

Findings
Intercepted the requests the logged-in in-app webview makes itself, vs the plugin's manually-signed ones:

  • The webview's own note/collect/page and board/user return 200
  • The webview's own requests carry no x-rap-param
  • The webview's x-s-common is much shorter than what signRequest() produces (different structure)

Looks like the SDK 4.2.6 x-s-common / fingerprint format is outdated vs the current XHS web (webBuild 6.12.3) and is rejected server-side.

Env: Obsidian (Windows), plugin v1.2.0; XHS webBuild 6.12.3, CN-region account.

Note: letting the webview's own page make the request and intercepting its response does return 200 — possible workaround.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions