fix(desktop): route fetch + WebSocket through native Tauri plugins (mixed-content)
Build desktop / desktop (push) Successful in 4m33s
Build & push images / images (push) Successful in 2m50s
CI / check (push) Successful in 43s
Release desktop / bundle (push) Successful in 5m13s

Fixing VITE_API_BASE got login to build a correct absolute URL, but it still
failed with WebKit's generic "Load failed" — WebKitGTK treats tauri://localhost
as a secure origin, so http://127.0.0.1:3000 (and ws://) from inside it is
blocked as mixed content, a WebKit limitation CSP's connect-src can't override.

Added tauri-plugin-http (genuine fetch() drop-in, wired via a new
platformFetch() in origin.ts, used by api.ts + logger.ts) and
tauri-plugin-websocket (not a drop-in — adapted behind a native-WebSocket-
shaped interface in the new platform-ws.ts so use-live-feed.ts needed no
changes). Both route through Tauri's Rust side instead of the webview's own
fetch/WebSocket. Capabilities scoped to 127.0.0.1:3000/localhost:3000, matching
the existing CSP allowlist.
This commit is contained in:
2026-09-03 14:57:45 +02:00
parent 276b048fa9
commit 439b11d16d
13 changed files with 776 additions and 16 deletions
+7 -3
View File
@@ -14,6 +14,7 @@
// high-signal sources (failed requests, uncaught errors) are always captured.
import { LOG_LEVEL_ORDER, type ClientLogInput, type LogLevel } from "@parking/shared";
import { apiUrl, platformFetch } from "./origin.js";
const ENDPOINT = "/api/logs";
const FLUSH_MS = 4000;
@@ -76,7 +77,7 @@ async function flush(): Promise<void> {
const headers: Record<string, string> = { "content-type": "application/json" };
const csrf = readCookie(CSRF_COOKIE);
if (csrf) headers[CSRF_HEADER] = csrf;
await fetch(ENDPOINT, {
await platformFetch(apiUrl(ENDPOINT), {
method: "POST",
headers,
credentials: "include",
@@ -90,7 +91,10 @@ async function flush(): Promise<void> {
}
}
/** Best-effort synchronous flush on page hide (sendBeacon survives unload). */
/** Best-effort synchronous flush on page hide (sendBeacon survives unload). Browser
* only — sendBeacon is a native browser API with no Tauri-HTTP-plugin equivalent,
* so this drops silently in the desktop shell (unload is rare there; the regular
* 4s-interval flush above covers the common case). */
function flushBeacon(): void {
if (queue.length === 0) return;
const entries = queue.splice(0, queue.length);
@@ -99,7 +103,7 @@ function flushBeacon(): void {
// sendBeacon can't set the CSRF header; the server accepts the ingest for any
// signed-in session (cookie sent automatically). If CSRF later guards it strictly,
// this path degrades to "lost on unload" — acceptable for diagnostics.
navigator.sendBeacon(ENDPOINT, blob);
navigator.sendBeacon(apiUrl(ENDPOINT), blob);
} catch {
/* ignore */
}