ionic-team / ionic-team/ionic-docs

content: Android Capacitor origin is `https://localhost` by default, not `http://localhost`

オープン
#4,546 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
triage
主要言語
MDX
スター
621
フォーク
3.2k
平均マージ
1日 2時間
マージ済み PR(30日)
86

説明

### URL

https://ionicframework.com/docs/troubleshooting/cors#what-is-cors

### Issue Description

## Summary

The CORS docs state that the Android origin is `http://localhost`. On current Capacitor this is `https://localhost` by default, because `server.androidScheme` defaults to `https`. The current wording leads people to whitelist the wrong origin and get blocked requests on Android.

## What the docs say

From the CORS page:

> An origin is the combination of the protocol, domain, and port from which your Ionic app or the external resource is served. For example, apps running in Capacitor have capacitor://localhost (iOS) or http://localhost (Android) as their origin.

## What actually happens

On a default Capacitor app (no `androidScheme` set), the Android webview origin is `https://localhost`, not `http://localhost`.

Tested on Capacitor 7 with a production backend. The server logged the incoming `Origin` header per platform:

```
Android origin = https://localhost
iOS / iPadOS origin = capacitor://localhost
```

The CORS allowlist only started working on Android after adding `https://localhost`. Adding `http://localhost` had no effect.

## Why

Since [Capacitor 6 made `https` the default `androidScheme`](https://capacitorjs.com/docs/updating/6-0#update-androidscheme), the default Android origin is `https://localhost`. Per the [config reference](https://capacitorjs.com/docs/config), the origin is `androidScheme` + `hostname`. It is `http://localhost` only if you set `androidScheme: 'http'`. Also raised in [#3639](https://github.com/ionic-team/ionic-docs/issues/3639).

## Suggested wording

> Apps running in Capacitor have `capacitor://localhost` (iOS) or `https://localhost` (Android) as their origin by default. The Android scheme follows `server.androidScheme`, which defaults to `https`. It is `http://localhost` only if you set `androidScheme: 'http'`.

If this looks right, I am happy to open a PR with the change.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。