Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Allow custom URI schemes for CORS allowed origins

オープン
#452 コメント 0 件 リアクション 2 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
55/100
issue の種類
機能追加
明瞭さ
おおむね明確
活発さ
活発
技術スタック
ios

調査の方向性

Start by tracing validation and matching for cors_allowed_origins on custom domains, then compare it with the redirect URL handling implemented for issue #331. Done means custom URI schemes such as capacitor:// are accepted with exact matching, while existing http and https behavior remains unchanged; verify the preflight behavior and relevant validation tests.

索引モデルが issue の本文から書いたものです。

説明

feat
Preflight checklist
Ory Network Project

https://thirsty-wozniak-lyfkkuj3wq.projects.oryapis.com

Describe your problem

The CORS allowed-origins validator on a custom domain accepts http and https only. Any other scheme is rejected with:

'capacitor://app.example.com' is not a valid CORS origin. Use '<scheme>://<hostname>:<port>'.

The message points at the format, but the format is not the issue — the scheme is. Tested on our project, on Branding → Custom domains → Allowed origins:

origin result
https://app.example.com accepted
http://app.example.com accepted
capacitor://app.example.com rejected
capacitor://app.example.com:443 rejected, same message — so it is not about the port
myscheme://app.example.com rejected — so it is not about capacitor specifically

This locks out hybrid mobile apps on iOS.

A Capacitor/Ionic app serves its bundled WebView from a custom scheme, and that is the Origin the WebView sends: capacitor://localhost by default, or capacitor://<your-hostname> once server.hostname is configured. Since that origin cannot be allow-listed, a plain fetch() from the app to Ory is impossible on iOS (the preflight is never granted).

The scheme is not negotiable on our side either. Capacitor's iosScheme cannot be set to http or https, because WebKit raises on it.

So there is no scheme that satisfies both Ory and iOS.

Android is unaffected :androidScheme defaults to https, and after adding https://<our-host> to the custom domain's allowed origins, the full flow works (preflight 204 with access-control-allow-headers: authorization, then GET /sessions/whoami returning 200 with the tokenized session). Only iOS is stuck.

Describe your ideal solution

Allow custom URI schemes in cors_allowed_origins on custom domains, with exact matching only (no wildcard support needed for them).

There is a direct precedent: #331 raised the same limitation for redirect URLs and was implemented. The same reasoning applies here, for the same class of application.

Workarounds or alternatives
  1. Bypass the browser with a native HTTP plugin. This is what Capacitor's own documentation recommends when CORS blocks you, and it is what we do today. It works, but it moves the request out of the WebView's network stack and into the platform's raw HTTP client, losing Happy Eyeballs, the browser's DNS resolver, connection pooling and coalescing.

  2. Run a backend proxy that forwards to Ory server-side, so the app talks to an origin we control. This works, and it is our fallback, but it means standing up and maintaining a service whose only purpose is to relay auth calls (which rather defeats the point of a managed identity provider).

Version

Ory Network (managed), as of 2026-09-30

Additional Context

No response

主要言語
Shell
スター
96
フォーク
8
PR マージ指標
30日以内にマージされた PR はありません

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

ory/network のほかの issue

ory/network の issue をすべて見る

似ている issue

Shell/Bash の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。