# Changelog All notable changes to webclaw are documented here. Format follows [Keep a Changelog](https://keepachangelog.com/). ## [0.3.2] — 2026-03-31 ### Added - **`--cookie-file` flag**: load cookies from JSON files exported by browser extensions (EditThisCookie, Cookie-Editor). Format: `[{name, value, domain, ...}]`. - **MCP `cookies` parameter**: the `scrape` tool now accepts a `cookies` array for authenticated scraping. - **Combined cookies**: `--cookie` and `--cookie-file` can be used together and merge automatically. --- ## [0.3.1] — 2026-03-30 ### Added - **Cookie warmup fallback**: when a fetch returns an Akamai challenge page, automatically visits the homepage first to collect `_abck`/`bm_sz` cookies, then retries the original URL. Enables extraction of Akamai-protected subpages (e.g. fansale ticket pages) without JS rendering. ### Changed - Upgraded to webclaw-tls v0.1.2: fixed HTTP header wire order (accept/user-agent were in wrong positions) and added H2 PRIORITY flag in HEADERS frames. - `FetchResult.headers` now uses `http::HeaderMap` instead of `HashMap` — avoids per-response allocation, preserves multi-value headers. ## [0.3.0] — 2026-03-29 ### Changed - **Replaced primp with webclaw-tls**: entire TLS fingerprinting stack is now our own. Zero primp references remain. - **Own TLS library**: [webclaw-tls](https://github.com/0xMassi/webclaw-tls) — patched rustls, h2, hyper, hyper-util, reqwest for browser-grade fingerprinting. - **Perfect Chrome 146 fingerprint**: JA4 `t13d1517h2_8daaf6152771_b6f405a00624` + Akamai HTTP/2 hash match — the only library in any language to achieve this. - **99% bypass rate**: 101/102 sites pass (up from ~85% with primp). - **Browser profiles**: Chrome 146 (Win/Mac), Firefox 135+, Safari 18, Edge 146 — captured from real browsers. ### Fixed - **HTTPS completely broken (#5)**: primp's forked rustls rejected valid certificates (UnknownIssuer on cross-signed chains like example.com). Fixed by using native OS root CAs alongside Mozilla bundle. - **Unknown certificate extensions**: servers returning SCT in certificate entries no longer cause TLS errors. ### Added - **Native root CA support**: uses OS trust store (macOS Keychain, Windows cert store) in addition to webpki-roots. - **HTTP/2 fingerprinting**: SETTINGS frame ordering and pseudo-header ordering match real browsers. - **Per-browser header ordering**: HTTP headers sent in browser-specific wire order. - **Bandwidth tracking**: atomic byte counters shared across cloned clients. --- ## [0.2.2] — 2026-03-27 ### Fixed - **`cargo install` broken with primp 1.2.0**: added missing `reqwest` patch to `[patch.crates-io]`. primp moved to reqwest 0.13 which requires a patched fork. - **Weekly dependency check**: CI now runs every Monday to catch primp patch drift before users hit it. --- ## [0.2.1] — 2026-03-27 ### Added - **Docker image on GHCR**: `docker run ghcr.io/0xmassi/webclaw` — auto-built on every release - **QuickJS data island extraction**: inline `