mirror of
https://github.com/tauri-apps/plugins-workspace.git
synced 2026-09-22 21:30:44 +02:00
refactor(http)!: always enforce the scope on redirects (#3600)
* refactor(http)!: always enforce the scope on redirects Removes the `scopeRedirects` option (and the `Config` struct with it) that was added as an opt-in in 2.7.0. Every hop of a redirect chain is now checked against the URL scope, so a server on an allowed origin can no longer redirect the request to a URL the scope denies. `tauri_plugin_http::init()` returns `TauriPlugin<R>` again. * chore(http): compile without warnings when the cookies feature is disabled
This commit is contained in:
@@ -0,0 +1,6 @@
|
||||
---
|
||||
"http": major
|
||||
"http-js": major
|
||||
---
|
||||
|
||||
**Breaking:** The URL scope is now always checked on every hop of a redirect chain, so every redirect target must be allowed by the scope or the request fails with `url not allowed on the configured scope`. This was previously opt-in through the `scopeRedirects` plugin configuration, which has been removed along with the `Config` struct: `tauri_plugin_http::init()` returns `TauriPlugin<R>` again, and any `plugins > http` object must be removed from `tauri.conf.json`.
|
||||
Reference in New Issue
Block a user