Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
20 KiB
Changelog
[2.7.0]
-
1198a524Security: Added thescopeRedirectsplugin configuration option, which checks the URL scope on every hop of a redirect chain instead of only on the URL requested by the frontend. Without it, a server on an allowed origin can redirect the request to any other origin - includinglocalhostservices, internal hosts and cloud metadata endpoints - and the plugin follows it, returning the response to the webview.{ "plugins": { "http": { "scopeRedirects": true } } }It is opt-in because a redirect to a URL that is not allowed by the scope now fails with
url not allowed on the configured scopeinstead of being followed, so applications that rely on being redirected outside of their scope must add the redirect target to the scope. This will become the default in v3.Note that
tauri_plugin_http::init()now returnsTauriPlugin<R, Option<Config>>instead ofTauriPlugin<R>.
[2.6.1]
a21555dd(#3566 by @followdarko) Fix unhandled promise rejections on everyfetchteardown: the request/body cleanup commands were fired as floating promises, and releasing an already-released resource rejects withThe resource id N is invalid..dropBodyis now idempotent and both cleanup calls handle their own rejection.
[2.6.0]
f8053e65(#3527 by @Legend-Master) Documented Cargo feature flags in each plugin's crate-level documentation.19fb3926(#3528 by @Legend-Master) Addedsystem-proxyfeature to replace the oldmacos-system-configurationfeature flag to match the new reqwest API.
Dependencies
- Upgraded to
fs-js@2.5.2
[2.5.9]
Dependencies
- Upgraded to
fs-js@2.5.1
[2.5.8]
29712892(#3252 by @NVolcz) Correct Response header initialization to support cloning and ensure Set-Cookie visibility.
Dependencies
- Upgraded to
fs-js@2.5.0
[2.5.7]
61e9b0ab(#3228) Cleanup resource when the returnedReadableStream.cancelis called to avoid memory leaks
[2.5.6]
b1dbee2c(#3210 by @FabianLars) Fixed an issue that caused the Origin header to always benullon macOS, iOS and Linux.
[2.5.5]
e8915f17(#2562 by @amrbashir) Fix aborting a request in the middle of a streaming response.
Dependencies
- Upgraded to
fs-js@2.4.5
[2.5.4]
93426f85Fixed an issue that caused docs.rs builds to fail. No user facing changes.
Dependencies
- Upgraded to
fs-js@2.4.4
[2.5.3]
Dependencies
- Upgraded to
fs-js@2.4.3
[2.5.2]
Dependencies
- Upgraded to
fs-js@2.4.2
[2.5.1]
Dependencies
- Upgraded to
fs-js@2.4.1
[2.5.0]
Dependencies
- Upgraded to
fs-js@2.4.0
[2.4.4]
ff384cba(#2636 by @asomethings) Properly handle responses with status code 204.
Dependencies
- Upgraded to
fs-js@2.3.0
[2.4.3]
37c0477a(#2561) Addzstdcargo feature flag to enablereqwest/zstdflag.9ebbfb2e(#1978) Persist cookies to disk and load it on next app start.
Dependencies
- Upgraded to
fs-js@2.2.1
[2.4.2]
a15eedf3(#2535 by @amrbashir) Fixfetchoccasionally throwing an error due to trying to close the underline stream twice.
[2.4.1]
d3183aa9(#2522 by @adrieljss) Fixfetchblocking until the whole response is read even if it was a streaming response.
[2.4.0]
cb38f54f(#2479 by @adrieljss) Add stream support for HTTP stream responses.
[2.3.0]
10513649(#2204 by @RickeyWard) Adddangerous-settingsfeature flag and new JSdangeroption to disable tls hostname/certificate validation.
[2.2.0]
3a79266b(#2173 by @FabianLars) Bumped all plugins tov2.2.0. From now, the versions for the Rust and JavaScript packages of each plugin will be in sync with each other.
Dependencies
- Upgraded to
fs@2.2.0
[2.0.2]
Dependencies
- Upgraded to
fs-js@2.0.4
[2.0.4]
a3b553dd(#2079 by @amrbashir) Add tracing logs for requestes and responses behindtracingfeature flag.
Dependencies
- Upgraded to
fs@2.1.0
[2.0.3]
Dependencies
- Upgraded to
fs@2.0.3
[2.0.1]
cfd48b3b(#1941 by @Nipsuli) Allow skipping sendingOriginheader in HTTP requests by settingOriginheader to an empty string when callingfetch.9b2840db(#1884 by @amrbashir) Retain headers order.
[2.0.1]
a1a82208(#1873 by @lucasfernog) Downgrade MSRV to 1.77.2 to support Windows 7.
Dependencies
- Upgraded to
fs@2.0.1
[2.0.0]
e2c4dfb6Update to tauri v2 stable release.
Dependencies
- Upgraded to
fs@2.0.0
[2.0.0-rc.6]
Dependencies
- Upgraded to
fs@2.0.0-rc.6
[2.0.0-rc.5]
Dependencies
- Upgraded to
fs@2.0.0-rc.5
[2.0.0-rc.4]
Dependencies
- Upgraded to
fs@2.0.0-rc.4
[2.0.0-rc.3]
Dependencies
- Upgraded to
fs@2.0.0-rc.3
[2.0.0-rc.2]
Dependencies
- Upgraded to
fs@2.0.0-rc.2
[2.0.0-rc.2]
e2e97db5(#1701 by @lucasfernog) Update to tauri 2.0.0-rc.8
[2.0.0-rc.1]
[2.0.0-rc.0]
9887d1Update to tauri RC.
Dependencies
- Upgraded to
fs@2.0.0-rc.0
[2.0.0-beta.9]
99d6ac0f(#1606 by @FabianLars) The JS packages now specify the minimum@tauri-apps/apiversion instead of a single exact version.6de87966(#1597 by @Legend-Master) Update to tauri beta.25.
[2.0.0-beta.8]
ac9a25cc(#1395 by @amrbashir) Fix cancelling requests usingAbortSignal.a6654932(#1526 by @amrbashir) Fix missingSet-Cookieheaders in the response which meantrequest.headers.getSetCookie()always returned empty array.22a17980(#1537 by @lucasfernog) Update to tauri beta.24.
[2.0.0-beta.7]
[2.0.0-beta.6]
0f739dbc(#1392 by @amrbashir) Allow settingOriginheader whenunsafe-headersfeature flag is active.
[2.0.0-beta.5]
[2.0.0-beta.4]
9d7ae45b(#1354) Include headers created by browser if not declared by user, which fixes missing headers likeContent-Typewhen usingFormData.430bd6f4(#1363) Update to tauri beta.20.
[2.0.0-beta.3]
[2.0.0-beta.6]
Dependencies
- Upgraded to
fs@2.0.0-beta.6
[2.0.0-beta.5]
500ff10(#1166) Breaking change: Removed thedefault-tlsfeature flag. Therustls-tls,http2,macos-system-configuration, andcharsetfeature flags are now enabled by default.e3d41f4(#1191) Internally use the webview scoped resources table instead of the app one, so other webviews can't access other webviews resources.7e2fcc5(#1146) Update dependencies to align with tauri 2.0.0-beta.14.e3d41f4(#1191) Update for tauri 2.0.0-beta.15.
Dependencies
- Upgraded to
fs@2.0.0-beta.5
[2.0.0-beta.4]
Dependencies
- Upgraded to
fs@2.0.0-beta.4
[2.0.0-beta.3]
c873e4d(#1059) Fixes scope not allowing subpaths, query parameters and hash when those values are empty.a04ea2f(#1071) The global API script is now only added to the binary when thewithGlobalTauriconfig is true.753c7be(#1050) Addunsafe-headerscargo feature flag to allow using forbidden headers.
Dependencies
- Upgraded to
fs@2.0.0-beta.3
[2.0.0-beta.2]
[2.0.0-beta.1]
569defbUpdate to tauri beta.4.
[2.0.0-beta.0]
d198c01(#862) Update to tauri beta.1a34720(#858) Fix http fetch client option init with parameterconnectTimeout
[2.0.0-alpha.9]
Dependencies
- Upgraded to
fs@2.0.0-alpha.7
[2.0.0-alpha.6]
[2.0.0-alpha.5]
[2.0.0-alpha.4]
[2.0.0-alpha.3]
[2.0.0-alpha.2]
[2.0.0-alpha.3]
Dependencies
- Upgraded to
fs@2.0.0-alpha.2
[2.0.0-alpha.2]
[2.0.0-alpha.1]
7d9df72(#428) Multipart requests are now handled in JavaScript by theRequestJavaScript class so you just need to use aFormDatabody and not set the content-type header tomultipart/form-data.application/x-www-form-urlencodedrequests must be done manually.7d9df72(#428) The http plugin has been rewritten from scratch and now only exposes afetchfunction in Javascript and Re-exportsreqwestcrate in Rust. The newfetchmethod tries to be as close and compliant to thefetchWeb API as possible.d74fc0a(#555) Update to alpha.11.