Commit Graph
2208 Commits
Author SHA1 Message Date
Lucas Fernandes NogueiraandAmr Bashir 1a43e4701d refactor(log)!: take u64 in Builder::max_file_size (#3611)
* refactor(log)!: take u64 in Builder::max_file_size

* Apply suggestion from @amrbashir

---------

Co-authored-by: Amr Bashir <github@amrbashir.me>
2026-09-22 06:07:06 -03:00
Lucas Fernandes Nogueira fdfb35e531 refactor(fs)!: return Watcher from watch and watchImmediate (#3610)
* refactor(fs)!: return Watcher from watch and watchImmediate

Both resolve to a `Watcher` resource instead of an `UnwatchFn` callback;
call `await watcher.close()` to stop watching. `UnwatchFn` is removed and
`Watcher` is now exported.

* fix change file

* fmt
2026-09-22 06:06:50 -03:00
Lucas Fernandes Nogueira 8083107a0a refactor(fs)!: drop notify's serialization-compat-6, flatten WatchEvent (#3609)
`WatchEvent` now follows notify v8's format: the event kind is flattened
into the event, with `type` holding the top-level kind and `kind`/`mode`
refining it, e.g. `{ type: 'modify', kind: 'data', mode: 'content' }`
instead of `{ type: { modify: { kind: 'data', mode: 'content' } } }`.
`attrs` is now typed as `WatchEventAttributes` and its `flag` is
`rescan` instead of `Rescan`.
2026-09-22 06:05:51 -03:00
Lucas Fernandes Nogueira a315a07f36 refactor(fs)!: remove the unwatch permission (#3606)
There has been no `unwatch` command since v2.0 (`Watcher.close()` releases
the resource), so `allow-unwatch` and `deny-unwatch` never granted anything.
2026-09-22 06:05:04 -03:00
Lucas Fernandes Nogueira 5c077a3812 refactor(fs)!: remove read_text_file and write_text_file commands (#3605)
`readTextFile` and `writeTextFile` now go through `read_file` and
`write_file`, so the `allow-read-text-file`, `deny-read-text-file`,
`allow-write-text-file` and `deny-write-text-file` permissions are gone;
grant `fs:allow-read-file` and `fs:allow-write-file` instead.
2026-09-22 06:04:53 -03:00
Lucas Fernandes Nogueira 120d00558e refactor(deep-link)!: return Error::Execute when an OS command fails to run (#3603)
* refactor(deep-link)!: return Error::Execute when an OS command fails to run

On Linux, `register`, `unregister` and `is_registered` now fail with the
new `Error::Execute(command, io_error)` variant when `xdg-mime` or
`update-desktop-database` cannot be spawned, instead of logging and
returning the raw `Error::Io`. This is the change deferred to v3 in #2970.

* docs(deep-link): unregister does not run OS commands
2026-09-22 06:04:13 -03:00
Lucas Fernandes NogueiraandLucas Nogueira c7416a1a2c refactor(http)!: remove deprecated macos-system-configuration feature (#3601)
* refactor(http)!: remove deprecated macos-system-configuration feature

Use `system-proxy` (enabled by default) instead.

* chore(upload): enable reqwest's system-proxy feature instead of the deprecated alias

---------

Co-authored-by: Lucas Nogueira <lucas@crabnebula.dev>
2026-09-22 06:03:58 -03:00
Lucas Fernandes Nogueira 34a06e7f60 refactor(http)!: always enforce the scope on redirects (#3600)
* refactor(http)!: always enforce the scope on redirects

Removes the `scopeRedirects` option (and the `Config` struct with it) that
was added as an opt-in in 2.7.0. Every hop of a redirect chain is now
checked against the URL scope, so a server on an allowed origin can no
longer redirect the request to a URL the scope denies.

`tauri_plugin_http::init()` returns `TauriPlugin<R>` again.

* chore(http): compile without warnings when the cookies feature is disabled
2026-09-22 06:03:27 -03:00
Lucas Fernandes NogueiraandLucas Nogueira b566f09124 refactor(store)!: reset to defaults before merging the on-disk state in reload (#3599)
* refactor(store)!: reset to defaults before merging the on-disk state in reload

`Store::reload` / `reload()` previously merged the on-disk state into the
current in-memory store. It now resets the store to its defaults first,
so in-memory keys that are neither in the defaults nor on disk are
dropped. `reload_ignore_defaults` / `reload({ ignoreDefaults: true })`
is unchanged.

* test(store): cover reload resetting to the defaults before merging the on-disk state

---------

Co-authored-by: Lucas Nogueira <lucas@crabnebula.dev>
2026-09-22 06:03:10 -03:00
Lucas Nogueira b7897cab5d chore: run taplo fmt 2026-09-21 21:56:40 -03:00
Lucas Nogueira 2fd27c2d43 chore: set MSRV to 1.95 2026-09-21 18:48:38 -03:00
Lucas Nogueira 735ace7a5b chore: update lockfile 2026-09-21 16:06:30 -03:00
Lucas Nogueira d0cfa15b71 chore: release 3.0.0-alpha.1 websocket-js-v3.0.0-alpha.1 dialog-v3.0.0-alpha.1 process-v3.0.0-alpha.1 clipboard-manager-v3.0.0-alpha.1 positioner-v3.0.0-alpha.1 clipboard-manager-js-v3.0.0-alpha.1 http-js-v3.0.0-alpha.1 positioner-js-v3.0.0-alpha.1 autostart-js-v3.0.0-alpha.1 shell-js-v3.0.0-alpha.1 shell-v3.0.0-alpha.1 deep-link-js-v3.0.0-alpha.1 persisted-scope-v3.0.0-alpha.1 cli-v3.0.0-alpha.1 window-state-v3.0.0-alpha.1 os-v3.0.0-alpha.1 updater-v3.0.0-alpha.1 biometric-js-v3.0.0-alpha.1 websocket-v3.0.0-alpha.1 cli-js-v3.0.0-alpha.1 process-js-v3.0.0-alpha.1 deep-link-v3.0.0-alpha.1 os-js-v3.0.0-alpha.1 opener-v3.0.0-alpha.1 sql-js-v3.0.0-alpha.1 biometric-v3.0.0-alpha.1 dialog-js-v3.0.0-alpha.1 opener-js-v3.0.0-alpha.1 haptics-v3.0.0-alpha.1 sql-v3.0.0-alpha.1 log-js-v3.0.0-alpha.1 store-js-v3.0.0-alpha.1 window-state-js-v3.0.0-alpha.1 global-shortcut-js-v3.0.0-alpha.1 single-instance-v3.0.0-alpha.1 notification-v3.0.0-alpha.1 localhost-v3.0.0-alpha.1 geolocation-v3.0.0-alpha.1 geolocation-js-v3.0.0-alpha.1 store-v3.0.0-alpha.1 http-v3.0.0-alpha.1 haptics-js-v3.0.0-alpha.1 upload-v3.0.0-alpha.1 barcode-scanner-v3.0.0-alpha.1 notification-js-v3.0.0-alpha.1 stronghold-js-v3.0.0-alpha.1 fs-js-v3.0.0-alpha.1 stronghold-v3.0.0-alpha.1 autostart-v3.0.0-alpha.1 nfc-v3.0.0-alpha.1 global-shortcut-v3.0.0-alpha.1 barcode-scanner-js-v3.0.0-alpha.1 nfc-js-v3.0.0-alpha.1 updater-js-v3.0.0-alpha.1 upload-js-v3.0.0-alpha.1 fs-v3.0.0-alpha.1 log-v3.0.0-alpha.1 2026-09-21 13:53:23 -03:00
Lucas Nogueira ce7fcb3263 Merge branch 'v2' into v3 2026-09-21 13:45:38 -03:00
Lucas Nogueira 15bf611d68 chore(deps): update tauri, api, CLI 2026-09-21 13:42:00 -03:00
Lucas Nogueira 5baf71a472 fix: pnpm audit single-instance-v2.4.5 updater-v2.12.0 log-v2.9.2 updater-js-v2.12.0 http-v2.7.0 log-js-v2.9.2 2026-09-19 22:23:56 -03:00
github-actions[bot] 2393188dea publish new versions (#3591)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-19 22:23:23 -03:00
Lucas Fernandes Nogueira 1198a524b7 Merge commit from fork
Checks the URL scope on every hop of a redirect chain instead of only on the URL requested by the frontend.
Without it, a server on an allowed origin can redirect the request to any other origin - including `localhost` services, internal hosts and cloud metadata endpoints - and the plugin follows it, returning the response to the webview.
2026-09-19 21:01:48 -03:00
Lucas Fernandes Nogueira 1308bfa399 Merge commit from fork 2026-09-19 21:00:36 -03:00
Lucas Fernandes Nogueira 690dcfd694 Merge commit from fork
* feat(updater): verify the version an update was signed for

The endpoint response is fetched over TLS but is not signed, and the signature
only covers the artifact, so a crafted response could pair an inflated version
with an older release's url and signature to force a downgrade to a genuine
but outdated build.

Read the version back from the signature's trusted comment and reject an
update whose announced version differs. Signatures carrying no version are
only rejected under the new requireSignedVersion option, since older CLIs did
not record one.

* fix tests
2026-09-19 20:57:51 -03:00
PathGao 67cd25a10c fix(single-instance): let the first instance come to front on Windows (#3592)
* fix(single-instance): let the first instance come to front on Windows

* move the hand-over right after the window lookup
2026-09-18 01:23:13 +08:00
Tony 2df3d93681 refactor(log): log webview location after double colon (#3574) 2026-09-17 16:33:47 +08:00
renovate[bot]andTony 4b5c9549c9 chore(deps): update dependency typescript-eslint to v8.70.0 (#3536)
* chore(deps): update dependency typescript-eslint to v8.70.0

* fix rust audit

* dedupe

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Tony <legendmastertony@gmail.com>
2026-09-16 14:23:04 +08:00
github-actions[bot] 3c5d267767 publish new versions (#3567)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
store-v2.4.5 http-js-v2.6.1 http-v2.6.1 store-js-v2.4.5
2026-09-16 12:17:22 +08:00
Tony c050e073b6 fix(store): apply_pending_auto_save can deadlock (#3572) 2026-09-16 10:49:36 +08:00
Lucas Nogueira 53b57024e5 fix(ci): install libgtk-4-dev positioner-js-v3.0.0-alpha.0 biometric-v3.0.0-alpha.0 cli-v3.0.0-alpha.0 window-state-js-v3.0.0-alpha.0 opener-js-v3.0.0-alpha.0 websocket-v3.0.0-alpha.0 notification-js-v3.0.0-alpha.0 clipboard-manager-js-v3.0.0-alpha.0 opener-v3.0.0-alpha.0 websocket-js-v3.0.0-alpha.0 os-js-v3.0.0-alpha.0 clipboard-manager-v3.0.0-alpha.0 upload-v3.0.0-alpha.0 os-v3.0.0-alpha.0 deep-link-js-v3.0.0-alpha.0 nfc-v3.0.0-alpha.0 upload-js-v3.0.0-alpha.0 nfc-js-v3.0.0-alpha.0 cli-js-v3.0.0-alpha.0 deep-link-v3.0.0-alpha.0 updater-v3.0.0-alpha.0 autostart-v3.0.0-alpha.0 log-v3.0.0-alpha.0 persisted-scope-v3.0.0-alpha.0 updater-js-v3.0.0-alpha.0 notification-v3.0.0-alpha.0 dialog-js-v3.0.0-alpha.0 window-state-v3.0.0-alpha.0 log-js-v3.0.0-alpha.0 stronghold-js-v3.0.0-alpha.0 process-js-v3.0.0-alpha.0 dialog-v3.0.0-alpha.0 store-v3.0.0-alpha.0 localhost-v3.0.0-alpha.0 stronghold-v3.0.0-alpha.0 process-v3.0.0-alpha.0 http-v3.0.0-alpha.0 store-js-v3.0.0-alpha.0 shell-js-v3.0.0-alpha.0 fs-js-v3.0.0-alpha.0 barcode-scanner-v3.0.0-alpha.0 fs-v3.0.0-alpha.0 sql-v3.0.0-alpha.0 http-js-v3.0.0-alpha.0 autostart-js-v3.0.0-alpha.0 geolocation-js-v3.0.0-alpha.0 haptics-v3.0.0-alpha.0 sql-js-v3.0.0-alpha.0 shell-v3.0.0-alpha.0 geolocation-v3.0.0-alpha.0 global-shortcut-js-v3.0.0-alpha.0 biometric-js-v3.0.0-alpha.0 single-instance-v3.0.0-alpha.0 haptics-js-v3.0.0-alpha.0 global-shortcut-v3.0.0-alpha.0 barcode-scanner-js-v3.0.0-alpha.0 positioner-v3.0.0-alpha.0 2026-09-13 15:58:13 -03:00
Lucas Nogueira 6967afaef8 chore: tauri 3.0 alpha release 2026-09-13 15:55:49 -03:00
Lucas Nogueira e87544c67d Merge remote-tracking branch 'origin/v2' into v3 2026-09-12 13:28:21 -03:00
Tony 0850317b5c chore(deps): update pnpm to v12 (#3576) 2026-09-10 10:36:25 +08:00
Tony 2a5783397e refactor(example): use tsconfig and change entries to ts (#3575) 2026-09-09 19:31:52 +08:00
renovate[bot]andTony b48d52cf6e chore(deps): update dependency rollup to v4.63.1 (#3558)
* chore(deps): update dependency rollup to v4.63.1

* fix audit

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Tony <legendmastertony@gmail.com>
2026-09-09 12:43:07 +08:00
Lucas Nogueira 835adce473 chore: update tauri 2026-09-08 17:53:34 -03:00
Den Ilin a21555ddd2 fix(http): stop unhandled rejections from the fetch cleanup path (#3566)
* fix(http): stop unhandled rejections from the fetch cleanup path

The request/body cleanup commands are fired as floating promises, and the
Rust side releases a resource only once: fetch_cancel_body is
resources_table.close(rid)?, and fetch_read_body also closes the rid at
end-of-body. So every release after the first rejects with BadResourceId
into a promise nobody is listening to.

Make dropBody idempotent and let both cleanup calls handle their own
rejection.

* chore: add changefile

* chore(http): rebuild api-iife.js
2026-09-03 21:00:34 +03:00
Tony 845d8989cb fix: ignore and fix audits (#3564)
* fix: ignore and fix audits

* openssl-sys 0.9.114
2026-09-01 17:38:21 +08:00
github-actions[bot] 6aa2854f31 publish new versions (#3509)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
haptics-js-v2.3.3 positioner-js-v2.3.4 clipboard-manager-js-v2.3.3 websocket-v2.4.3 clipboard-manager-v2.3.3 deep-link-js-v2.4.10 websocket-js-v2.4.3 log-js-v2.9.1 upload-v2.4.1 http-js-v2.6.0 biometric-js-v2.3.3 upload-js-v2.4.1 deep-link-v2.4.10 updater-v2.11.0 log-v2.9.1 nfc-js-v2.3.6 updater-js-v2.11.0 barcode-scanner-js-v2.4.6 nfc-v2.3.6 stronghold-v2.3.2 notification-js-v2.4.0 stronghold-js-v2.3.2 notification-v2.4.0 haptics-v2.3.3 biometric-v2.3.3 shell-js-v2.3.6 barcode-scanner-v2.4.6 opener-v2.5.5 shell-v2.3.6 dialog-v2.7.3 geolocation-v2.3.3 geolocation-js-v2.3.3 dialog-js-v2.7.3 http-v2.6.0 fs-v2.5.2 persisted-scope-v2.3.8 fs-js-v2.5.2 single-instance-v2.4.4 positioner-v2.3.4 opener-js-v2.5.5 sql-js-v2.4.1 sql-v2.4.1
2026-08-31 19:17:31 +08:00
Fabian-Lars 9d6d03269a chore(deps): update h2 to 0.4.19 (#3556) 2026-08-27 16:02:57 +02:00
Fabian-Lars 98f8787de4 ci: fix typo in workflow permissions 2026-08-27 14:35:49 +02:00
Fabian-Lars 1a7b12c102 ci: add explicit token permissions 2026-08-27 14:31:16 +02:00
dependabot[bot] 2f4c85c99a chore(deps): bump serde_with (#3490)
Bumps [serde_with](https://github.com/jonasbb/serde_with) from 3.9.0 to 3.22.0.
- [Release notes](https://github.com/jonasbb/serde_with/releases)
- [Commits](https://github.com/jonasbb/serde_with/compare/v3.9.0...v3.22.0)

---
updated-dependencies:
- dependency-name: serde_with
  dependency-version: 3.21.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-27 14:23:25 +02:00
renovate[bot] c546de0616 chore(deps): update dependency rollup to v4.62.5 (#3520)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-27 14:04:52 +02:00
Tony db9c5998fe fix(android): missing consumer-rules.pro (#3531)
* fix(android): missing `consumer-rules.pro`

* setup android test

* copy right too new

* build api first

* we're still on gradle 8 right now...

* restore the right host on mac
2026-08-13 17:44:29 +08:00
renovate[bot]andTony 9c9343772b chore(deps): update dependency typescript-eslint to v8.66.0 (#3391)
* chore(deps): update dependency typescript-eslint to v8.66.0

* bump nanoid for audit

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Tony <legendmastertony@gmail.com>
2026-08-10 16:15:04 +08:00
Tony 685610ae78 fix(fs): default permissions (#3507)
* Fix deny-webview-data platfroms and scopes

* Fix `create-app-specific-dirs` scopes

* Fix read-app-specific-dirs-recursive

* Re-generate schema and docs

* Remove unused `fs:allow-unwatch`

* Add change file

* Remove unused permissions

* Update linux permissions

* Update change file

* regenerate doc md and schema
2026-08-10 15:48:27 +08:00
Tony f8053e659e docs: cargo features (#3527)
* dialog

* fs

* geolocation

* haptic

* log

* single instance

* notification

* updater

* ##

* persisted scopes

* stronghold

* sql

* upload

* websocket

* http
(this one was too long that I generated through codex, didn't review yet)

* add change file

* no persisted-scope-js

* add `://`

* Merge branch 'v2' into document-cargo-features

* update system-proxy docs

* finish http docs

* notification doesn't need version bumps

* clean up docs
2026-08-05 15:48:11 +08:00
Tony 19fb3926fd feat(http): add system-proxy feature (#3528)
* feat(http): add `system-proxy` feature

* require reqwest 0.12.16
2026-08-04 19:51:32 +08:00
Tony 2371be839f feat(updater): add system-proxy feature (#3526)
* feat(updater): add `system-proxy` feature

* enable by default
2026-08-04 16:37:00 +08:00
Tony e215ff90d3 chore: remove outdated prod features (#3525) 2026-08-04 15:45:25 +08:00
renovate[bot]andTony ba89f32eb0 chore(deps): update dependency @zerodevx/svelte-json-view to v2 (#3524)
* chore(deps): update dependency @zerodevx/svelte-json-view to v2

* update pnpm to 11.20.0?

* bump brace-expansion for audit

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Tony <legendmastertony@gmail.com>
2026-08-04 10:46:11 +08:00
purvsinojiya-inventyv cc9ec9b4ad fix(dialog): use parsed MIME type for Android save dialog (#3519) 2026-07-29 17:05:43 +02:00
paul valladares dc7f87bc7e chore: exclude dev-only files from published crates (#3518)
* chore: exclude dev-only files from published crates

* format
2026-07-29 09:35:15 +02:00