refactor(http)!: always enforce the scope on redirects (#3600)

* refactor(http)!: always enforce the scope on redirects

Removes the `scopeRedirects` option (and the `Config` struct with it) that
was added as an opt-in in 2.7.0. Every hop of a redirect chain is now
checked against the URL scope, so a server on an allowed origin can no
longer redirect the request to a URL the scope denies.

`tauri_plugin_http::init()` returns `TauriPlugin<R>` again.

* chore(http): compile without warnings when the cookies feature is disabled
This commit is contained in:
Lucas Fernandes Nogueira
2026-09-22 06:03:27 -03:00
committed by GitHub
parent b566f09124
commit 34a06e7f60
5 changed files with 37 additions and 116 deletions
+2 -3
View File
@@ -77,9 +77,8 @@ export interface ClientOptions {
* Defines the maximum number of redirects the client should follow.
* If set to 0, no redirects will be followed.
*
* When the `scopeRedirects` plugin configuration is enabled, every redirect must
* also be allowed by the configured scope, otherwise the request fails
* instead of being followed.
* Every redirect must also be allowed by the configured scope,
* otherwise the request fails instead of being followed.
*/
maxRedirections?: number
/** Timeout in milliseconds */