Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Allow custom URI schemes for CORS allowed origins

Abierto
#452 0 comentarios 2 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
55/100
Tipo de issue
Nueva funcionalidad
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
ios

Línea de trabajo

Start by tracing validation and matching for cors_allowed_origins on custom domains, then compare it with the redirect URL handling implemented for issue #331. Done means custom URI schemes such as capacitor:// are accepted with exact matching, while existing http and https behavior remains unchanged; verify the preflight behavior and relevant validation tests.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

feat
Preflight checklist
Ory Network Project

https://thirsty-wozniak-lyfkkuj3wq.projects.oryapis.com

Describe your problem

The CORS allowed-origins validator on a custom domain accepts http and https only. Any other scheme is rejected with:

'capacitor://app.example.com' is not a valid CORS origin. Use '<scheme>://<hostname>:<port>'.

The message points at the format, but the format is not the issue — the scheme is. Tested on our project, on Branding → Custom domains → Allowed origins:

origin result
https://app.example.com accepted
http://app.example.com accepted
capacitor://app.example.com rejected
capacitor://app.example.com:443 rejected, same message — so it is not about the port
myscheme://app.example.com rejected — so it is not about capacitor specifically

This locks out hybrid mobile apps on iOS.

A Capacitor/Ionic app serves its bundled WebView from a custom scheme, and that is the Origin the WebView sends: capacitor://localhost by default, or capacitor://<your-hostname> once server.hostname is configured. Since that origin cannot be allow-listed, a plain fetch() from the app to Ory is impossible on iOS (the preflight is never granted).

The scheme is not negotiable on our side either. Capacitor's iosScheme cannot be set to http or https, because WebKit raises on it.

So there is no scheme that satisfies both Ory and iOS.

Android is unaffected :androidScheme defaults to https, and after adding https://<our-host> to the custom domain's allowed origins, the full flow works (preflight 204 with access-control-allow-headers: authorization, then GET /sessions/whoami returning 200 with the tokenized session). Only iOS is stuck.

Describe your ideal solution

Allow custom URI schemes in cors_allowed_origins on custom domains, with exact matching only (no wildcard support needed for them).

There is a direct precedent: #331 raised the same limitation for redirect URLs and was implemented. The same reasoning applies here, for the same class of application.

Workarounds or alternatives
  1. Bypass the browser with a native HTTP plugin. This is what Capacitor's own documentation recommends when CORS blocks you, and it is what we do today. It works, but it moves the request out of the WebView's network stack and into the platform's raw HTTP client, losing Happy Eyeballs, the browser's DNS resolver, connection pooling and coalescing.

  2. Run a backend proxy that forwards to Ory server-side, so the app talks to an origin we control. This works, and it is our fallback, but it means standing up and maintaining a service whose only purpose is to relay auth calls (which rather defeats the point of a managed identity provider).

Version

Ory Network (managed), as of 2026-09-30

Additional Context

No response

Lenguaje dominante
Shell
Estrellas
96
Forks
8
Métricas de merge de PR
Sin PR fusionados en 30 d

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de ory/network

Todos los issues de ory/network

Issues similares

Más issues de Shell/Bash

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.