http@2.7.0
ae3c808e(#3602) The plugin's global API script (used withapp.withGlobalTauri) now resolves the core API fromwindow.__TAURI__instead of bundling its own copy of@tauri-apps/api. Values created with the core API are now accepted by plugin APIs in global mode (e.g. anImagefromwindow.__TAURI__.imagepassed toclipboardManager.writeImage, which previously failed theinstanceofcheck against the plugin's private copy), and the script is considerably smaller.9b29b601Update MSRV to 1.90 to match tauri.a87a3c7dUpdate documentation.
Dependencies
Section titled “Dependencies”-
Upgraded to
fs-js@2.6.0 -
1198a524Security: Added thescopeRedirectsplugin configuration option, which checks the URL scope on every hop of a redirect chain instead of only on the URL requested by the frontend. Without it, a server on an allowed origin can redirect the request to any other origin - includinglocalhostservices, internal hosts and cloud metadata endpoints - and the plugin follows it, returning the response to the webview.{"plugins": {"http": {"scopeRedirects": true}}}It is opt-in because a redirect to a URL that is not allowed by the scope now fails with
url not allowed on the configured scopeinstead of being followed, so applications that rely on being redirected outside of their scope must add the redirect target to the scope. This will become the default in v3.Note that
tauri_plugin_http::init()now returnsTauriPlugin<R, Option<Config>>instead ofTauriPlugin<R>.
© 2026 Tauri Contributors. CC-BY / MIT