Repository navigation
Consider enabling crossOriginIsolated in flutter run #127902
Description
Activity
- addedin triagePresently being triaged by the triage teamPresently being triaged by the triage teamc: new featureNothing broken; request for a new capabilityNothing broken; request for a new capabilitytoolAffects the "flutter" command-line tool. See also t: labels.Affects the "flutter" command-line tool. See also t: labels.platform-webWeb applications specificallyWeb applications specificallyc: proposalA detailed proposal for a change to FlutterA detailed proposal for a change to Flutterand removedin triagePresently being triaged by the triage teamPresently being triaged by the triage team
on May 31, 2023 - addedP2Important issues not at the top of the work listImportant issues not at the top of the work list
on Jun 1, 2023 - addedteam-webOwned by Web platform teamOwned by Web platform teamtriaged-webTriaged by Web platform teamTriaged by Web platform team
on Jul 8, 2023 This would be great.
Currently, tools such as https://github.com/fzyzcjy/flutter_rust_bridge/ provide their own web servers to allow development while interoperating with wasm files. These tools require sacrificing debugging, hot reload and the other nice features of
flutter run.I tested a simple case with https://github.com/aran/automerge-flutter/blob/main/flutters/web/cross_origin_proxy.dart — The three headers in that file are sufficient to have a basic flutter app work at least in release mode. Flutter's built-in Google CDNs already transmit the right headers so that nothing breaks.
Since this could potentially break clients—what failure modes are possible and how would they appear?- An app would break in development if it had loose usage of cross-site resources, and those resources did not provide modern headers for cross-site usage. This would show up in the developer console.
- An app could work in 'flutter run' but stop working in production if it depended on the headers but was served from a vanilla CDN/nginx/storage bucket
Is there anything else?
- added a commit that references this issue
on Oct 17, 2023 We did this, for
flutter run --wasm, right @eyebrowsoffire ?Yes. I think we can close this.
- addedr: fixedIssue is closed as already fixed in a newer versionIssue is closed as already fixed in a newer version
on Aug 13, 2024 This thread has been automatically locked since there has not been any recent activity after it was closed. If you are still experiencing a similar issue, please open a new bug, including the output of
flutter doctor -vand a minimal reproduction of the issue.- locked as resolved and limited conversation to collaborators
on Aug 27, 2024
We may want to consider some way to serve the app's HTML with
Cross-Origin-Opener-Policy: same-originandCross-Origin-Embedder-Policy: require-corpto enablecrossOriginIsolated. Since this could potentially break clients, we at least need an opt-out, or perhaps it should be opt-in, or based on your configuration. We will at least need this for skwasm, since it depends on acrossOriginIsolatedbrowser context to use multi-threaded wasm.