Skip to content

fix: return opaque responses from file and http protocol handlers for cross-origin no-cors requests - #52822

Merged
MarshallOfSound merged 1 commit into
mainfrom
fix/protocol-nocors-opaque-sinks
Aug 16, 2026
Merged

MarshallOfSound merged 1 commit into
mainfrom
fix/protocol-nocors-opaque-sinks

Conversation

@MarshallOfSound

Copy link
Copy Markdown
Member

Custom schemes registered with supportFetchAPI: true but without corsEnabled: true should return an opaque response to a cross-origin fetch(url, { mode: 'no-cors' }), the same as protocol.handle. The response was only tagged opaque on the string/buffer/stream path — registerFileProtocol and registerHttpProtocol delivered a readable (basic) response instead.

  • Compute the opaque-response decision once in ElectronURLLoaderFactory::StartLoading and thread it into the file and http loaders.
  • Tag the delivered response head kOpaque on the file and http paths via a small URLLoaderClient interposer, so asar, the plain file loader, and URLPipeLoader all match the buffer/stream path.
  • Add protocol spec coverage for registerFileProtocol and registerHttpProtocol cross-origin no-cors fetches.

Notes: Fixed registerFileProtocol and registerHttpProtocol returning readable responses to cross-origin no-cors fetches; they now return opaque responses like protocol.handle.

… cross-origin no-cors requests

The opaque tagging added for cross-origin no-cors loads is written to a
local response head that only the string/buffer/stream sinks deliver. The
file sink (asar/file loader) and the http sink (URLPipeLoader) build or
forward their own response head, dropping the tag, so a cross-origin
mode=no-cors fetch of a registerFileProtocol or registerHttpProtocol
resource was delivered as a basic, script-readable response.

Compute the opaque decision once in StartLoading and interpose a
URLLoaderClient on the file and http sinks that re-applies the opaque tag to
the head those sinks emit, matching the behaviour of the other sinks.
@MarshallOfSound MarshallOfSound added semver/patch backwards-compatible bug fixes target/41-x-y PR should also be added to the "41-x-y" branch. target/42-x-y PR should also be added to the "42-x-y" branch. target/43-x-y PR should also be added to the "43-x-y" branch. target/44-x-y PR should also be added to the "44-x-y" branch. labels Aug 15, 2026
@electron-cation electron-cation Bot added the new-pr 🌱 PR opened recently label Aug 15, 2026
@MarshallOfSound
MarshallOfSound enabled auto-merge (squash) August 15, 2026 21:49
@MarshallOfSound
MarshallOfSound merged commit fd01d1f into main Aug 16, 2026
112 of 114 checks passed
@MarshallOfSound
MarshallOfSound deleted the fix/protocol-nocors-opaque-sinks branch August 16, 2026 10:55
@release-clerk

release-clerk Bot commented Aug 16, 2026

Copy link
Copy Markdown

Release Notes Persisted

Fixed registerFileProtocol and registerHttpProtocol returning readable responses to cross-origin no-cors fetches; they now return opaque responses like protocol.handle.

@trop

trop Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

I have automatically backported this PR to "44-x-y", please check out #52852

@trop

trop Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

I have automatically backported this PR to "43-x-y", please check out #52853

@trop trop Bot removed the target/44-x-y PR should also be added to the "44-x-y" branch. label Aug 16, 2026
@trop

trop Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

I have automatically backported this PR to "41-x-y", please check out #52854

@trop

trop Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

I have automatically backported this PR to "42-x-y", please check out #52855

@trop trop Bot added in-flight/43-x-y in-flight/41-x-y in-flight/42-x-y and removed target/43-x-y PR should also be added to the "43-x-y" branch. target/41-x-y PR should also be added to the "41-x-y" branch. labels Aug 16, 2026
@trop trop Bot added merged/43-x-y PR was merged to the "43-x-y" branch. merged/44-x-y PR was merged to the "44-x-y" branch. merged/41-x-y PR was merged to the "41-x-y" branch. merged/42-x-y PR was merged to the "42-x-y" branch. and removed target/42-x-y PR should also be added to the "42-x-y" branch. in-flight/43-x-y in-flight/44-x-y in-flight/41-x-y in-flight/42-x-y labels Aug 16, 2026
filter->receiver_.Bind(proxy.InitWithNewPipeAndPassReceiver());
filter->receiver_.set_disconnect_handler(base::BindOnce(
&OpaqueResponseFilter::DeleteThis, base::Unretained(filter)));
return proxy;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since this class is more of a proxy between URLLoaderClient remote and receiver. It would be good to also listen on destination disconnect so that the other end can early abort as well.

filter->destination_.set_disconnect_handler(base::BindOnce(
        &OpaqueResponseFilter::DeleteThis, base::Unretained(filter)));

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

45-x-y merged/41-x-y PR was merged to the "41-x-y" branch. merged/42-x-y PR was merged to the "42-x-y" branch. merged/43-x-y PR was merged to the "43-x-y" branch. merged/44-x-y PR was merged to the "44-x-y" branch. new-pr 🌱 PR opened recently semver/patch backwards-compatible bug fixes

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

4 participants