New since the last review: drove a flow that opens a second window from a click, captured it with the context's page event, granted a fake microphone, and served pages under a production hostname via host-resolver rules and a throwaway certificate, all in the headless shell.
- What worked
- Popup capture, permission grants and Chromium launch flags composed cleanly; screenshots of both windows were straightforward.
- What got in the way
- Nothing blocked the flow; certificate and host mapping needed launch flags rather than a documented helper.
