Lucas Nogueira
5baf71a472
fix: pnpm audit
single-instance-v2.4.5
updater-v2.12.0
log-v2.9.2
updater-js-v2.12.0
http-v2.7.0
log-js-v2.9.2
2026-09-19 22:23:56 -03:00
github-actions[bot]
2393188dea
publish new versions ( #3591 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-19 22:23:23 -03:00
Lucas Fernandes Nogueira
1198a524b7
Merge commit from fork
...
Checks the URL scope on every hop of a redirect chain instead of only on the URL requested by the frontend.
Without it, a server on an allowed origin can redirect the request to any other origin - including `localhost` services, internal hosts and cloud metadata endpoints - and the plugin follows it, returning the response to the webview.
2026-09-19 21:01:48 -03:00
Lucas Fernandes Nogueira
1308bfa399
Merge commit from fork
2026-09-19 21:00:36 -03:00
Lucas Fernandes Nogueira
690dcfd694
Merge commit from fork
...
* feat(updater): verify the version an update was signed for
The endpoint response is fetched over TLS but is not signed, and the signature
only covers the artifact, so a crafted response could pair an inflated version
with an older release's url and signature to force a downgrade to a genuine
but outdated build.
Read the version back from the signature's trusted comment and reject an
update whose announced version differs. Signatures carrying no version are
only rejected under the new requireSignedVersion option, since older CLIs did
not record one.
* fix tests
2026-09-19 20:57:51 -03:00
PathGao
67cd25a10c
fix(single-instance): let the first instance come to front on Windows ( #3592 )
...
* fix(single-instance): let the first instance come to front on Windows
* move the hand-over right after the window lookup
2026-09-18 01:23:13 +08:00
Tony
2df3d93681
refactor(log): log webview location after double colon ( #3574 )
2026-09-17 16:33:47 +08:00
renovate[bot] and Tony
4b5c9549c9
chore(deps): update dependency typescript-eslint to v8.70.0 ( #3536 )
...
* chore(deps): update dependency typescript-eslint to v8.70.0
* fix rust audit
* dedupe
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Tony <legendmastertony@gmail.com >
2026-09-16 14:23:04 +08:00
github-actions[bot]
3c5d267767
publish new versions ( #3567 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
store-v2.4.5
http-js-v2.6.1
http-v2.6.1
store-js-v2.4.5
2026-09-16 12:17:22 +08:00
Tony
c050e073b6
fix(store): apply_pending_auto_save can deadlock ( #3572 )
2026-09-16 10:49:36 +08:00
Tony
0850317b5c
chore(deps): update pnpm to v12 ( #3576 )
2026-09-10 10:36:25 +08:00
Tony
2a5783397e
refactor(example): use tsconfig and change entries to ts ( #3575 )
2026-09-09 19:31:52 +08:00
renovate[bot] and Tony
b48d52cf6e
chore(deps): update dependency rollup to v4.63.1 ( #3558 )
...
* chore(deps): update dependency rollup to v4.63.1
* fix audit
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Tony <legendmastertony@gmail.com >
2026-09-09 12:43:07 +08:00
Den Ilin
a21555ddd2
fix(http): stop unhandled rejections from the fetch cleanup path ( #3566 )
...
* fix(http): stop unhandled rejections from the fetch cleanup path
The request/body cleanup commands are fired as floating promises, and the
Rust side releases a resource only once: fetch_cancel_body is
resources_table.close(rid)?, and fetch_read_body also closes the rid at
end-of-body. So every release after the first rejects with BadResourceId
into a promise nobody is listening to.
Make dropBody idempotent and let both cleanup calls handle their own
rejection.
* chore: add changefile
* chore(http): rebuild api-iife.js
2026-09-03 21:00:34 +03:00
Tony
845d8989cb
fix: ignore and fix audits ( #3564 )
...
* fix: ignore and fix audits
* openssl-sys 0.9.114
2026-09-01 17:38:21 +08:00
github-actions[bot]
6aa2854f31
publish new versions ( #3509 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
haptics-js-v2.3.3
positioner-js-v2.3.4
clipboard-manager-js-v2.3.3
websocket-v2.4.3
clipboard-manager-v2.3.3
deep-link-js-v2.4.10
websocket-js-v2.4.3
log-js-v2.9.1
upload-v2.4.1
http-js-v2.6.0
biometric-js-v2.3.3
upload-js-v2.4.1
deep-link-v2.4.10
updater-v2.11.0
log-v2.9.1
nfc-js-v2.3.6
updater-js-v2.11.0
barcode-scanner-js-v2.4.6
nfc-v2.3.6
stronghold-v2.3.2
notification-js-v2.4.0
stronghold-js-v2.3.2
notification-v2.4.0
haptics-v2.3.3
biometric-v2.3.3
shell-js-v2.3.6
barcode-scanner-v2.4.6
opener-v2.5.5
shell-v2.3.6
dialog-v2.7.3
geolocation-v2.3.3
geolocation-js-v2.3.3
dialog-js-v2.7.3
http-v2.6.0
fs-v2.5.2
persisted-scope-v2.3.8
fs-js-v2.5.2
single-instance-v2.4.4
positioner-v2.3.4
opener-js-v2.5.5
sql-js-v2.4.1
sql-v2.4.1
2026-08-31 19:17:31 +08:00
Fabian-Lars
9d6d03269a
chore(deps): update h2 to 0.4.19 ( #3556 )
2026-08-27 16:02:57 +02:00
Fabian-Lars
98f8787de4
ci: fix typo in workflow permissions
2026-08-27 14:35:49 +02:00
Fabian-Lars
1a7b12c102
ci: add explicit token permissions
2026-08-27 14:31:16 +02:00
dependabot[bot]
2f4c85c99a
chore(deps): bump serde_with ( #3490 )
...
Bumps [serde_with](https://github.com/jonasbb/serde_with ) from 3.9.0 to 3.22.0.
- [Release notes](https://github.com/jonasbb/serde_with/releases )
- [Commits](https://github.com/jonasbb/serde_with/compare/v3.9.0...v3.22.0 )
---
updated-dependencies:
- dependency-name: serde_with
dependency-version: 3.21.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-27 14:23:25 +02:00
renovate[bot]
c546de0616
chore(deps): update dependency rollup to v4.62.5 ( #3520 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-27 14:04:52 +02:00
Tony
db9c5998fe
fix(android): missing consumer-rules.pro ( #3531 )
...
* fix(android): missing `consumer-rules.pro`
* setup android test
* copy right too new
* build api first
* we're still on gradle 8 right now...
* restore the right host on mac
2026-08-13 17:44:29 +08:00
renovate[bot] and Tony
9c9343772b
chore(deps): update dependency typescript-eslint to v8.66.0 ( #3391 )
...
* chore(deps): update dependency typescript-eslint to v8.66.0
* bump nanoid for audit
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Tony <legendmastertony@gmail.com >
2026-08-10 16:15:04 +08:00
Tony
685610ae78
fix(fs): default permissions ( #3507 )
...
* Fix deny-webview-data platfroms and scopes
* Fix `create-app-specific-dirs` scopes
* Fix read-app-specific-dirs-recursive
* Re-generate schema and docs
* Remove unused `fs:allow-unwatch`
* Add change file
* Remove unused permissions
* Update linux permissions
* Update change file
* regenerate doc md and schema
2026-08-10 15:48:27 +08:00
Tony
f8053e659e
docs: cargo features ( #3527 )
...
* dialog
* fs
* geolocation
* haptic
* log
* single instance
* notification
* updater
* ##
* persisted scopes
* stronghold
* sql
* upload
* websocket
* http
(this one was too long that I generated through codex, didn't review yet)
* add change file
* no persisted-scope-js
* add `://`
* Merge branch 'v2' into document-cargo-features
* update system-proxy docs
* finish http docs
* notification doesn't need version bumps
* clean up docs
2026-08-05 15:48:11 +08:00
Tony
19fb3926fd
feat(http): add system-proxy feature ( #3528 )
...
* feat(http): add `system-proxy` feature
* require reqwest 0.12.16
2026-08-04 19:51:32 +08:00
Tony
2371be839f
feat(updater): add system-proxy feature ( #3526 )
...
* feat(updater): add `system-proxy` feature
* enable by default
2026-08-04 16:37:00 +08:00
Tony
e215ff90d3
chore: remove outdated prod features ( #3525 )
2026-08-04 15:45:25 +08:00
renovate[bot] and Tony
ba89f32eb0
chore(deps): update dependency @zerodevx/svelte-json-view to v2 ( #3524 )
...
* chore(deps): update dependency @zerodevx/svelte-json-view to v2
* update pnpm to 11.20.0?
* bump brace-expansion for audit
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Tony <legendmastertony@gmail.com >
2026-08-04 10:46:11 +08:00
purvsinojiya-inventyv
cc9ec9b4ad
fix(dialog): use parsed MIME type for Android save dialog ( #3519 )
2026-07-29 17:05:43 +02:00
paul valladares
dc7f87bc7e
chore: exclude dev-only files from published crates ( #3518 )
...
* chore: exclude dev-only files from published crates
* format
2026-07-29 09:35:15 +02:00
Michael Kadziela
304292d740
feat(notification): add rust Action/ActionType api. fix action registration in Android ( #2805 )
2026-07-27 13:03:43 +02:00
Tony
622f02bf21
fix(updater): check ShellExecuteW results ( #3516 )
...
* fix(updater): check `ShellExecuteW` results
* document the exit on windows
2026-07-27 16:38:50 +08:00
renovate[bot] and Tony
abc903c240
chore(deps): update dependency rollup to v4.62.2 ( #3423 )
...
* chore(deps): update dependency rollup to v4.62.2
* Fix audit
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Tony <legendmastertony@gmail.com >
2026-07-27 13:29:36 +08:00
Tony
ab7489c964
feat(updater): option to not restart after install ( #3299 )
...
* feat(updater): option to not restart after install
* More platform cfg
* Add the same function for `UpdaterBuilder`
* Fix missing `#[cfg(windows)]`
* Mark `current_exe_args` cfg(windows)
* Mark `on_before_exit` cfg(windows)
* Mark `installer_args` cfg(windows)
* Note about `installer_arg` apply to both
* Remove current args and restart together
* Only build needed bundle on windows as well
* Remove `/NS` since it breaks the msi updater
* Add launch updater debug log
* Add a folder to test updates
* Remove unused `#[allow(unused)]`
* Format
* messed up git stage
* Add change file
* Clean up
* Disable NSIS compression for API example
* Bump wry for v1 test to pull in https://github.com/tauri-apps/wry/pull/1703
* format
* Make typescript happy
* Close new update on destroy
2026-07-21 18:25:16 +08:00
Vitor Ayres and Tony
3fb27bf13a
fix(docs): deep link platform specific and fs scope ( #3504 )
...
* deep link fix Platform Specific heading
* fix fs permission toml
* .changes
* Update change files
Co-authored-by: Tony <68118705+Legend-Master@users.noreply.github.com >
* Update .changes/fs-deny-scope.md
* fix eol
---------
Co-authored-by: Tony <68118705+Legend-Master@users.noreply.github.com >
2026-07-21 14:56:52 +08:00
Tony
7e45774610
refactor(fs): cfg gate some ios code ( #3510 )
2026-07-21 14:42:45 +08:00
Pascal Auf der Maur and Fabian-Lars
526726162f
fix(nfc): adapt backend invoke to frontend ( #3419 )
...
* fix(nfc): adapt backend invoke to frontend
* Revert "fix(nfc): adapt backend invoke to frontend"
This reverts commit e34306e083 .
* fix: enforce nfc function return type
* Update .changes/nfc.md
Co-authored-by: Fabian-Lars <30730186+FabianLars@users.noreply.github.com >
---------
Co-authored-by: Fabian-Lars <30730186+FabianLars@users.noreply.github.com >
2026-07-20 13:11:20 +02:00
github-actions[bot]
03afae6d72
publish new versions ( #3500 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
dialog-v2.7.2
dialog-js-v2.7.2
store-v2.4.4
store-js-v2.4.4
2026-07-19 00:40:36 +08:00
renovate[bot] and Tony
57ac986453
chore(deps): update dependency @tauri-apps/cli to v2.11.4 ( #3463 )
...
* chore(deps): update dependency @tauri-apps/cli to v2.11.4
* Use workspace dependencies in example
* Bump tauri
* Leftover
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Tony <legendmastertony@gmail.com >
2026-07-18 22:28:03 +08:00
Tony
2ed6d6c1de
fix(store): StoreOptions.defaults should not be required ( #3499 )
2026-07-18 19:46:31 +08:00
Tony
cdfd462955
chore(example): set color-cheme ( #3493 )
...
This allows the unstyled user agent elements (like the checkbox) match the selected theme colors
2026-07-16 21:31:40 +08:00
Tony
d6e0b6bbb1
chore(example): clean up and migrate to ts partially ( #3492 )
...
* chore(example): clean up and migrate to ts
* Add missing permissions
* Mirror line-height: 1.5 and remove h-*
2026-07-16 19:47:52 +08:00
Tony
40ae0a7fa0
enhance(dialog): use MaterialAlertDialogBuilder ( #3491 )
...
* Fix example insets
* Add app-region: drag
* Use `Theme.Material3.DayNight.NoActionBar`
* Re-generate some kotlin files
* Use MaterialAlertDialogBuilder
* Add change file
* Revert back to margin-top: 0.5rem
* Re-generate outdated gradle wrapper from #3039
* Move title bar to its own file
* Fix cancel message
2026-07-16 17:27:19 +08:00
Tony
edc52ea056
chore(deps): bump create-pull-request to v8 ( #3489 )
2026-07-15 23:49:37 +08:00
Tony
a0d949d93e
chore(deps): update pnpm to v11 ( #3487 )
...
* chore(deps): update pnpm to v11
* Remove all `version: 11`
* Bump tsx
2026-07-15 20:24:01 +08:00
Tony
13c63af965
chore: fix clippy ( #3488 )
2026-07-15 16:01:07 +08:00
github-actions[bot]
cad301fcc1
publish new versions ( #3447 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
log-v2.9.0
log-js-v2.9.0
single-instance-v2.4.3
positioner-js-v2.3.3
positioner-v2.3.3
2026-07-14 01:10:29 +02:00
Bajoca
254f222e0e
chore(log): use kv stable feature rather than unstable ( #3477 )
2026-07-13 13:23:56 +02:00
Tony
b1439be667
chore: ignore cargo audit errors ( #3481 )
...
* chore: ignore cargo audit errors
* Bump anyhow
2026-07-13 16:51:50 +08:00