Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion crates/tauri-runtime-wry/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -1715,7 +1715,7 @@ impl<T: UserEvent> WebviewDispatch<T> for WryWebviewDispatcher<T> {
Message::Webview(
*self.window_id.lock().unwrap(),
self.webview_id,
WebviewMessage::DeleteCookie(cookie.clone().into_owned()),
WebviewMessage::SetCookie(cookie.into_owned()),

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Action required

5. Delete_cookie sets cookie 🐞 Bug ✓ Correctness

• delete_cookie now dispatches WebviewMessage::SetCookie instead of DeleteCookie, so the
  cookie is not removed.
• This silently breaks expected behavior (e.g., logout/session cleanup) and can leave sensitive
  session cookies behind.
• The runtime message loop still has a DeleteCookie branch, so this looks like an accidental
  wiring regression.
Agent prompt
### Issue description
`WryWebviewDispatcher::delete_cookie` currently sends `WebviewMessage::SetCookie`, which causes the cookie to be set instead of deleted.

### Issue Context
The runtime message loop treats `SetCookie` and `DeleteCookie` differently (`webview.set_cookie` vs `webview.delete_cookie`).

### Fix Focus Areas
- crates/tauri-runtime-wry/src/lib.rs[1712-1721]
- crates/tauri-runtime-wry/src/lib.rs[3731-3741]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

),
)?;
Ok(())
Expand Down
5 changes: 3 additions & 2 deletions crates/tauri/src/webview/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,6 @@
pub(crate) mod plugin;
mod webview_window;

use cookie::Cookie;
pub use webview_window::{WebviewWindow, WebviewWindowBuilder};

/// Cookie crate used for [`Webview::set_cookie`] and [`Webview::delete_cookie`].
Expand All @@ -20,6 +19,8 @@ use http::HeaderMap;
use serde::Serialize;
use tauri_macros::default_runtime;
pub use tauri_runtime::webview::{NewWindowFeatures, PageLoadEvent};
// Remove this re-export in v3
pub use tauri_runtime::Cookie;
Comment on lines +22 to +23

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Action required

1. cookie re-export lacks docs 📘 Rule violation ✓ Correctness

• pub use tauri_runtime::Cookie; is a public API surface but is preceded only by a non-doc
  comment, so it will not appear in generated docs.
• This violates the requirement that public API elements include /// documentation comments,
  reducing discoverability and increasing downstream confusion.
Agent prompt
## Issue description
A public re-export (`pub use tauri_runtime::Cookie;`) was added without Rust doc comments (`///`), which violates the requirement that public APIs be documented.

## Issue Context
`//` comments do not become API documentation and will not show up in rustdoc output for downstream users.

## Fix Focus Areas
- crates/tauri/src/webview/mod.rs[21-23]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

#[cfg(desktop)]
use tauri_runtime::{
dpi::{PhysicalPosition, PhysicalSize, Position, Size},
Expand Down Expand Up @@ -521,7 +522,7 @@ tauri::Builder::default()
"opened-window",
tauri::WebviewUrl::External("about:blank".parse().unwrap()),
)
.with_window_features(features)
.window_features(features)
.on_document_title_changed(|window, title| {
window.set_title(&title).unwrap();
})
Expand Down
12 changes: 6 additions & 6 deletions crates/tauri/src/webview/webview_window.rs
Original file line number Diff line number Diff line change
Expand Up @@ -297,7 +297,7 @@ impl<'a, R: Runtime, M: Manager<R>> WebviewWindowBuilder<'a, R, M> {
/// "opened-window",
/// tauri::WebviewUrl::External("about:blank".parse().unwrap()),
/// )
/// .with_window_features(features)
/// .window_features(features)
/// .on_document_title_changed(|window, title| {
/// window.set_title(&title).unwrap();
/// })
Expand Down Expand Up @@ -1312,13 +1312,13 @@ impl<R: Runtime, M: Manager<R>> WebviewWindowBuilder<'_, R, M> {
target_os = "netbsd",
target_os = "openbsd"
))]
pub fn with_window_features(mut self, features: NewWindowFeatures) -> Self {
if let Some(position) = features.position() {
self.window_builder = self.window_builder.position(position.x, position.y);
pub fn window_features(mut self, features: NewWindowFeatures) -> Self {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Action required

6. Semver-breaking api rename 🐞 Bug ⛯ Reliability

• WebviewWindowBuilder::with_window_features was removed/renamed to window_features without
  keeping a deprecated alias.
• In tauri v2.7.0, removing a public method in a minor release is a semver-breaking change that
  will break downstream crates at compile time.
• If this rename is intentional, it should be introduced via a deprecated wrapper and removed in v3,
  not v2.x.
Agent prompt
### Issue description
A public method rename (`with_window_features` → `window_features`) was done without a compatibility shim, which is semver-breaking for v2.x.

### Issue Context
The crate version is 2.7.0, and downstream code using the old method will fail to compile.

### Fix Focus Areas
- crates/tauri/src/webview/webview_window.rs[1304-1351]
- crates/tauri/Cargo.toml[1-4]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

if let Some(size) = features.size() {
self.window_builder = self.window_builder.inner_size(size.width, size.height);
}

if let Some(size) = features.size() {
self.window_builder = self.window_builder.inner_size(size.width, size.height);
if let Some(position) = features.position() {
self.window_builder = self.window_builder.position(position.x,position.y);
}
Comment on lines +1315 to 1322

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Action required

2. window_features rustfmt violations 📘 Rule violation ✓ Correctness

• The new implementation contains spacing inconsistencies (extra spaces and missing spaces after
  commas) that cargo fmt would rewrite.
• This likely causes cargo fmt --all -- --check to fail, violating formatting compliance and
  creating noisy diffs.
Agent prompt
## Issue description
The new `window_features` implementation has formatting that does not match rustfmt (extra spaces and missing spaces after commas), so `cargo fmt --check` will likely fail.

## Issue Context
Formatting compliance is enforced repository-wide; changes that rustfmt would rewrite should be committed in rustfmt-compliant form.

## Fix Focus Areas
- crates/tauri/src/webview/webview_window.rs[1315-1322]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


#[cfg(target_os = "macos")]
Expand Down
48 changes: 23 additions & 25 deletions examples/api/src-tauri/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -8,8 +8,6 @@ mod menu_plugin;
#[cfg(desktop)]
mod tray;

use std::sync::atomic::AtomicUsize;

use serde::Serialize;
use tauri::{
ipc::Channel,
Expand Down Expand Up @@ -68,40 +66,40 @@ pub fn run_app<R: Runtime, F: FnOnce(&App<R>) + Send + 'static>(
.build()?,
));

let app_ = app.handle().clone();

let mut created_window_count = AtomicUsize::new(0);
let mut window_builder = WebviewWindowBuilder::new(app, "main", WebviewUrl::default())
.on_new_window(move |url, features| {
println!("new window requested: {url:?} {features:?}");

let number = created_window_count.fetch_add(1, std::sync::atomic::Ordering::Relaxed);

let builder = tauri::WebviewWindowBuilder::new(
&app_,
format!("new-{number}"),
tauri::WebviewUrl::External("about:blank".parse().unwrap()),
)
.with_window_features(features)
.on_document_title_changed(|window, title| {
window.set_title(&title).unwrap();
})
.title(url.as_str());

let window = builder.build().unwrap();
tauri::webview::NewWindowResponse::Create { window }
})
.on_document_title_changed(|_window, title| {
println!("document title changed: {title}");
});

#[cfg(all(desktop, not(test)))]
{
let app_ = app.handle().clone();
let mut created_window_count = std::sync::atomic::AtomicUsize::new(0);

window_builder = window_builder
.title("Tauri API Validation")
.inner_size(1000., 800.)
.min_inner_size(600., 400.)
.menu(tauri::menu::Menu::default(app.handle())?);
.menu(tauri::menu::Menu::default(app.handle())?)
.on_new_window(move |url, features| {
println!("new window requested: {url:?} {features:?}");

Comment on lines 70 to +86

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remediation recommended

4. println! logs url/title 📘 Rule violation ⛨ Security

• The new code logs url, features, and document title using println!, which is unstructured
  and may include sensitive or user-controlled data.
• This violates the secure logging requirement (structured logging and no sensitive data in logs),
  and also makes log ingestion/monitoring harder.
Agent prompt
## Issue description
The example app uses `println!` to log potentially user-controlled values (URL/title) in an unstructured way.

## Issue Context
Compliance requires structured logs and avoiding sensitive/user data leakage in logs; `println!` bypasses normal logging configuration and formatting.

## Fix Focus Areas
- examples/api/src-tauri/src/lib.rs[69-86]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

let number = created_window_count.fetch_add(1, std::sync::atomic::Ordering::Relaxed);

let builder = tauri::WebviewWindowBuilder::new(
&app_,
format!("new-window-{number}"),
tauri::WebviewUrl::External("about:blank".parse().unwrap()),
)
.window_features(features)
.on_document_title_changed(|window, title| {
window.set_title(&title).unwrap();
})
.title(url.as_str());

let window = builder.build().unwrap();
tauri::webview::NewWindowResponse::Create { window }
Comment on lines +89 to +101

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Action required

3. builder.build() uses unwrap() 📘 Rule violation ⛯ Reliability

• The new on_new_window handler uses multiple unwrap() calls (parse().unwrap(),
  set_title(...).unwrap(), builder.build().unwrap()), which can panic at runtime.
• This violates the requirement to avoid panicking for fallible operations and to handle errors with
  meaningful context and graceful behavior.
Agent prompt
## Issue description
New code introduces `unwrap()` on fallible operations inside `on_new_window`, which can panic in production-like runs.

## Issue Context
This code path includes URL parsing, window creation, and title setting—each can fail depending on platform/runtime conditions.

## Fix Focus Areas
- examples/api/src-tauri/src/lib.rs[89-101]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

});
}

let webview = window_builder.build()?;
Expand Down