Skip to content

fix(plugin): lock windows to the origin they first load from - #17

Merged
zippy merged 3 commits into
mainfrom
security/navigation-lock
Sep 30, 2026
Merged

zippy merged 3 commits into
mainfrom
security/navigation-lock

Conversation

@zippy

@zippy zippy commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

Summary

Windows from main_window_builder are confined to the origin they first load from. Without this, a link could replace the app's UI with a remote page that keeps the window's IPC access.

The origin is recorded from the webview's first navigation, or its first page load on Android, where the initial load never reaches the navigation handler. It is observed rather than predicted from the config, so mobile dev proxies, use_https_scheme and the custom-protocol rewrites on Windows and Android do not produce a blank window.

  • Navigation to any other origin is refused and logged.
  • blob: URLs of the origin are allowed, so a UI can still hand the user a file. data: URLs are refused.
  • On desktop, window.open and target="_blank" open nothing. Tauri has no on_new_window on mobile, so Android loads the target in the same webview, where the navigation check applies, and iOS opens nothing.
  • HolochainPlugin::lock_navigation applies the same policy to windows an app builds itself. navigation_allowed, origin_of and same_origin are public.
  • The record is per webview label and is dropped when the window is destroyed, not when it is unbound.

on_new_window arrived in Tauri 2.8. The workspace floor moves from 2.5.1 to 2.11, the version CI builds.

Two follow-up PRs stack on this one: the Linux media grant and the legacy websocket origins. Both use the origin record added here.

TODO:

  • CHANGELOG updated with appropriate info
  • npm run ci passes

@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 4b618a2e-04f7-4892-b519-6be1f7611edb

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@zippy
zippy force-pushed the security/navigation-lock branch from f492d78 to c66a1d2 Compare September 24, 2026 18:13
@zippy
zippy marked this pull request as ready for review September 25, 2026 14:38
@zippy
zippy requested a review from a team as a code owner September 25, 2026 14:38
Comment thread crates/tauri-plugin-hc/src/lib.rs
Comment thread Cargo.toml Outdated
@zippy zippy mentioned this pull request Sep 29, 2026
1 of 2 tasks
@zippy
zippy requested a review from mattyg September 29, 2026 17:50
mattyg
mattyg previously approved these changes Sep 29, 2026
@zippy
zippy enabled auto-merge (rebase) September 30, 2026 15:22
@zippy
zippy force-pushed the security/navigation-lock branch from fd6d87d to c4ca0a1 Compare September 30, 2026 15:22
Record each webview's origin from its first navigation or page load and refuse
navigation anywhere else, except blob: URLs of that origin; window.open and
target=_blank open nothing. main_window_builder applies this, and
HolochainPlugin::lock_navigation applies it to windows an app builds itself.
on_new_window needs Tauri 2.8, so the workspace floor moves to 2.8.0.
The legacy path attached an app interface with AllowedOrigins::Any and
injected a reusable, non-expiring token into the page. No consumer uses it,
so remove it rather than harden it (supersedes #19).

BREAKING CHANGE: WindowOptions::use_app_websocket, the injected
__HC_LAUNCHER_ENV__, Runtime::ensure_app_websocket, Runtime::setup_app and
AppAuth are removed. Use Runtime::install_app_if_missing instead of setup_app.
@zippy
zippy force-pushed the security/navigation-lock branch from c4ca0a1 to 162aea0 Compare September 30, 2026 15:35
@cocogitto-bot

cocogitto-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown

✔️ e7de910...162aea0 - Conventional commits check succeeded.

@zippy
zippy merged commit 8399246 into main Sep 30, 2026
6 checks passed
@zippy
zippy deleted the security/navigation-lock branch September 30, 2026 16:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants