Skip to content

http full changelog

Oct 7, 2026
  • b443d6be (#3669 by @followdarko) fetch_send now releases the request's resources once the send settles. Before, a request that got a response or failed to send left its FetchRequest and abort sender in the webview's resource table until the webview was destroyed, so a long-lived app grew with every request.
  • 3113a54c (#3670 by @FabianLars) Updated inner dependency urlpattern from v0.3 to v0.6 to fix advisories about unmaintained unic- crates.
Sep 29, 2026
Sep 26, 2026
  • ae3c808e (#3602) The plugin's global API script (used with app.withGlobalTauri) now resolves the core API from window.__TAURI__ instead of bundling its own copy of @tauri-apps/api. Values created with the core API are now accepted by plugin APIs in global mode (e.g. an Image from window.__TAURI__.image passed to clipboardManager.writeImage, which previously failed the instanceof check against the plugin's private copy), and the script is considerably smaller.
  • 9b29b601 Update MSRV to 1.90 to match tauri.
  • a87a3c7d Update documentation.
  • Upgraded to fs-js@2.6.0

  • 1198a524 Security: Added the scopeRedirects plugin configuration option, which checks the URL scope on every hop of a redirect chain instead of only on the URL requested by the frontend. Without it, a server on an allowed origin can redirect the request to any other origin - including localhost services, internal hosts and cloud metadata endpoints - and the plugin follows it, returning the response to the webview.

    {
    "plugins": {
    "http": {
    "scopeRedirects": true
    }
    }
    }

    It is opt-in because a redirect to a URL that is not allowed by the scope now fails with url not allowed on the configured scope instead of being followed, so applications that rely on being redirected outside of their scope must add the redirect target to the scope. This will become the default in v3.

    Note that tauri_plugin_http::init() now returns TauriPlugin<R, Option<Config>> instead of TauriPlugin<R>.

Sep 16, 2026
  • a21555dd (#3566 by @followdarko) Fix unhandled promise rejections on every fetch teardown: the request/body cleanup commands were fired as floating promises, and releasing an already-released resource rejects with The resource id N is invalid.. dropBody is now idempotent and both cleanup calls handle their own rejection.
Aug 31, 2026
  • Upgraded to fs-js@2.5.2
May 2, 2026
  • Upgraded to fs-js@2.5.1
Apr 4, 2026
  • 29712892 (#3252 by @NVolcz) Correct Response header initialization to support cloning and ensure Set-Cookie visibility.
  • Upgraded to fs-js@2.5.0
Feb 3, 2026
  • 61e9b0ab (#3228) Cleanup resource when the returned ReadableStream.cancel is called to avoid memory leaks
Jan 14, 2026
  • b1dbee2c (#3210 by @FabianLars) Fixed an issue that caused the Origin header to always be null on macOS, iOS and Linux.
Jan 8, 2026
  • Upgraded to fs-js@2.4.5
Oct 27, 2025
  • 93426f85 Fixed an issue that caused docs.rs builds to fail. No user facing changes.
  • Upgraded to fs-js@2.4.4
Oct 26, 2025
  • Upgraded to fs-js@2.4.3
Aug 20, 2025
  • Upgraded to fs-js@2.4.2
Jul 20, 2025
  • Upgraded to fs-js@2.4.1
Jun 25, 2025
  • Upgraded to fs-js@2.4.0
May 20, 2025
  • Upgraded to fs-js@2.3.0
Apr 2, 2025
  • 37c0477a (#2561) Add zstd cargo feature flag to enable reqwest/zstd flag.
  • 9ebbfb2e (#1978) Persist cookies to disk and load it on next app start.
  • Upgraded to fs-js@2.2.1
Mar 17, 2025
  • a15eedf3 (#2535 by @amrbashir) Fix fetch occasionally throwing an error due to trying to close the underline stream twice.
Mar 15, 2025
  • d3183aa9 (#2522 by @adrieljss) Fix fetch blocking until the whole response is read even if it was a streaming response.
Mar 10, 2025
Jan 27, 2025
  • 10513649 (#2204 by @RickeyWard) Add dangerous-settings feature flag and new JS danger option to disable tls hostname/certificate validation.
Dec 9, 2024
  • 3a79266b (#2173 by @FabianLars) Bumped all plugins to v2.2.0. From now, the versions for the Rust and JavaScript packages of each plugin will be in sync with each other.
  • Upgraded to fs@2.2.0
Dec 2, 2024
  • Upgraded to fs@2.1.0
Oct 21, 2024
  • Upgraded to fs@2.0.3
Dec 9, 2024
  • Upgraded to fs-js@2.0.4
Oct 20, 2024
  • Upgraded to fs@2.0.1
Oct 2, 2024
  • e2c4dfb6 Update to tauri v2 stable release.
  • Upgraded to fs@2.0.0
Oct 2, 2024
  • Upgraded to fs@2.0.0-rc.6
Sep 15, 2024
  • Upgraded to fs@2.0.0-rc.5
Sep 12, 2024
  • Upgraded to fs@2.0.0-rc.4
Sep 5, 2024
  • Upgraded to fs@2.0.0-rc.3
Aug 29, 2024
Aug 17, 2024
Aug 2, 2024
  • Upgraded to fs@2.0.0-rc.0
Jul 31, 2024
Jul 12, 2024
Jul 2, 2024
Jun 17, 2024
  • Upgraded to fs@2.0.0-beta.6
May 30, 2024
  • 9013854f(#1382) Update to tauri beta.22.

  • 500ff10(#1166) Breaking change: Removed the default-tls feature flag. The rustls-tls, http2, macos-system-configuration, and charset feature flags are now enabled by default.

  • e3d41f4(#1191) Internally use the webview scoped resources table instead of the app one, so other webviews can't access other webviews resources.

  • 7e2fcc5(#1146) Update dependencies to align with tauri 2.0.0-beta.14.

  • e3d41f4(#1191) Update for tauri 2.0.0-beta.15.

  • Upgraded to fs@2.0.0-beta.5
May 30, 2024
  • 9d7ae45b(#1354) Include headers created by browser if not declared by user, which fixes missing headers like Content-Type when using FormData.
  • 430bd6f4(#1363) Update to tauri beta.20.
  • Upgraded to fs@2.0.0-beta.4
May 1, 2024
  • bd1ed590(#1237) Update to tauri beta.17.

  • c873e4d(#1059) Fixes scope not allowing subpaths, query parameters and hash when those values are empty.

  • a04ea2f(#1071) The global API script is now only added to the binary when the withGlobalTauri config is true.

  • 753c7be(#1050) Add unsafe-headers cargo feature flag to allow using forbidden headers.

  • Upgraded to fs@2.0.0-beta.3
Mar 7, 2024
Feb 21, 2024
Feb 3, 2024
  • d198c01(#862) Update to tauri beta.
  • 1a34720(#858) Fix http fetch client option init with parameter connectTimeout
Dec 28, 2023
  • Upgraded to fs@2.0.0-alpha.7
Dec 20, 2023
  • bfa87da(#824) Add proxy field to fetch options to configure proxy.
Dec 20, 2023
  • 387c2f9(#802) Update to @tauri-apps/api v2.0.0-alpha.13.
Dec 14, 2023
  • 387c2f9(#802) Update to @tauri-apps/api v2.0.0-alpha.12.
Oct 29, 2023
  • Upgraded to fs@2.0.0-alpha.2
Oct 23, 2023
  • 5c13736(#673) Update to @tauri-apps/api v2.0.0-alpha.9.

  • aec17a9(#558) Improve response performance by using the new IPC streaming data.

Aug 14, 2023
  • 7d9df72(#428) Multipart requests are now handled in JavaScript by the Request JavaScript class so you just need to use a FormData body and not set the content-type header to multipart/form-data. application/x-www-form-urlencoded requests must be done manually.
  • 7d9df72(#428) The http plugin has been rewritten from scratch and now only exposes a fetch function in Javascript and Re-exports reqwest crate in Rust. The new fetch method tries to be as close and compliant to the fetch Web API as possible.
  • d74fc0a(#555) Update to alpha.11.
May 24, 2023

© 2026 Tauri Contributors. CC-BY / MIT