Skip to content

Consider enabling crossOriginIsolated in flutter run #127902

Description

@eyebrowsoffire

We may want to consider some way to serve the app's HTML with Cross-Origin-Opener-Policy: same-origin and Cross-Origin-Embedder-Policy: require-corp to enable crossOriginIsolated. Since this could potentially break clients, we at least need an opt-out, or perhaps it should be opt-in, or based on your configuration. We will at least need this for skwasm, since it depends on a crossOriginIsolated browser context to use multi-threaded wasm.

Activity

  1. added
    in triagePresently being triaged by the triage team
    c: new featureNothing broken; request for a new capability
    toolAffects the "flutter" command-line tool. See also t: labels.
    platform-webWeb applications specifically
    c: proposalA detailed proposal for a change to Flutter
    and removed
    in triagePresently being triaged by the triage team
    on May 31, 2023
  2. added
    P2Important issues not at the top of the work list
    on Jun 1, 2023
  3. aran commented on Aug 1, 2023

    @aran
    Contributor

    This would be great.

    Currently, tools such as https://github.com/fzyzcjy/flutter_rust_bridge/ provide their own web servers to allow development while interoperating with wasm files. These tools require sacrificing debugging, hot reload and the other nice features of flutter run.

    I tested a simple case with https://github.com/aran/automerge-flutter/blob/main/flutters/web/cross_origin_proxy.dart — The three headers in that file are sufficient to have a basic flutter app work at least in release mode. Flutter's built-in Google CDNs already transmit the right headers so that nothing breaks.

    Since this could potentially break clients—what failure modes are possible and how would they appear?

    1. An app would break in development if it had loose usage of cross-site resources, and those resources did not provide modern headers for cross-site usage. This would show up in the developer console.
    2. An app could work in 'flutter run' but stop working in production if it depended on the headers but was served from a vanilla CDN/nginx/storage bucket

    Is there anything else?

  4. kevmoo commented on Aug 8, 2024

    @kevmoo
    Contributor

    We did this, for flutter run --wasm, right @eyebrowsoffire ?

  5. eyebrowsoffire commented on Aug 12, 2024

    @eyebrowsoffire
    ContributorAuthor

    Yes. I think we can close this.

  6. github-actions commented on Aug 27, 2024

    @github-actions

    This thread has been automatically locked since there has not been any recent activity after it was closed. If you are still experiencing a similar issue, please open a new bug, including the output of flutter doctor -v and a minimal reproduction of the issue.

  7. locked as resolved and limited conversation to collaborators on Aug 27, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P2Important issues not at the top of the work listc: new featureNothing broken; request for a new capabilityc: proposalA detailed proposal for a change to Flutterplatform-webWeb applications specificallyr: fixedIssue is closed as already fixed in a newer versionteam-webOwned by Web platform teamtoolAffects the "flutter" command-line tool. See also t: labels.triaged-webTriaged by Web platform team

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions