Networking docs appear outdated: credentials: 'omit' works on RN 0.86

Aberta Para iniciantes
#57,786 1 comentário 0 reações 0 responsáveis Ver no GitHub

Ninguém assumiu esta issue ainda.

Avaliação

Dificuldade
1/5
Tempo estimado
1-3 horas
Facilidade para iniciantes
78/100
Tipo de issue
Documentação
Clareza
Claramente especificada
Status de atividade
Pouca atividade
Stack de tecnologia
react-native
Domínio
documentation

Direção de pesquisa

Comece pela seção da documentação de Networking vinculada no relatório, especialmente pelo texto sobre os problemas conhecidos de fetch e autenticação baseada em cookies. Atualize a afirmação sobre as credenciais: «omit» para corresponder ao comportamento relatado do React Native 0.86, mantendo a limitação redirect: 'manual' fora do escopo; considera-se concluído quando o aviso desatualizado for removido ou devidamente restringido.

Escrita pelo modelo de indexação a partir do texto da issue.

Descrição

Needs: Attention Needs: Repro

Summary

The Networking docs list credentials: 'omit' as currently not working with fetch:

https://reactnative.dev/docs/network#known-issues-with-fetch-and-cookie-based-authentication

On React Native 0.86, the built-in global fetch respects credentials: 'omit' in all cookie scenarios tested on both iOS and Android:

  • existing cookies are not sent on direct requests;
  • existing cookies are not sent after an automatically followed 302;
  • Set-Cookie from a direct response is not persisted;
  • Set-Cookie from a 302 response is neither sent to the redirected request nor persisted.

Equivalent credentials: 'include' controls all behave in the opposite way, confirming that the cookie store and test server are working.

The other documented limitation, redirect: 'manual', is outside the scope of this report.

Environment

  • react-native package: 0.86.2
  • Native runtime reported by Platform.constants.reactNativeVersion: 0.86.0
  • Expo: 57.0.9, Expo Go
  • iOS: 26.5 simulator
  • Android: API 37 emulator
  • Fetch implementation: React Native built-in global fetch
    • EXPO_PUBLIC_USE_RN_FETCH=1
    • confirmed global fetch !== expo/fetch

Expo SDK 57 documents EXPO_PUBLIC_USE_RN_FETCH=1 as the switch that keeps React Native's built-in fetch as the global implementation:

https://docs.expo.dev/versions/v57.0.0/sdk/expo/#expofetch-api

Reproduction

The test server provides these endpoints:

  • /api/set-cookie — responds with Set-Cookie: session=abc123 and theme=dark;
  • /api/cookies — returns the received Cookie header;
  • /api/redirect-to-cookies302 to /api/cookies;
  • /api/redirect-set-cookie — responds with both 302 and Set-Cookie, redirecting to /api/cookies;
  • /api/clear-test-cookies — expires all cookies used by the test.

The relevant client checks are equivalent to:

// Existing cookies: direct requests and automatic 302 follow
await clearTestCookies();
await fetch(`${API}/api/set-cookie`, { credentials: 'include' });

assert((await readCookies('include')).cookieHeader ===
  'session=abc123; theme=dark');
assert((await readCookies('omit')).cookieHeader === null);

assert((await fetchRedirect('include')).cookieHeader ===
  'session=abc123; theme=dark');
assert((await fetchRedirect('omit')).cookieHeader === null);

// A direct Set-Cookie response must be ignored with omit
await clearTestCookies();
await fetch(`${API}/api/set-cookie?scenario=direct-omit-response`, {
  credentials: 'omit',
});
assert((await readCookies('include')).cookieHeader === null);

// Control: the same operation with include persists the cookie
await clearTestCookies();
await fetch(`${API}/api/set-cookie?scenario=direct-include-response`, {
  credentials: 'include',
});
assert((await readCookies('include')).cookieHeader ===
  'direct_include_response=should_persist');

// Set-Cookie received on a 302 must also be ignored with omit
await clearTestCookies();
const redirectedOmit = await fetch(
  `${API}/api/redirect-set-cookie?scenario=redirect-omit-response`,
  { credentials: 'omit' },
);
assert((await redirectedOmit.json()).cookieHeader === null);
assert((await readCookies('include')).cookieHeader === null);

// Control: include sends the new cookie on the redirected request and persists it
await clearTestCookies();
const redirectedInclude = await fetch(
  `${API}/api/redirect-set-cookie?scenario=redirect-include-response`,
  { credentials: 'include' },
);
assert((await redirectedInclude.json()).cookieHeader ===
  'redirect_include_response=should_persist');
assert((await readCookies('include')).cookieHeader ===
  'redirect_include_response=should_persist');

Results

All 10/10 checks passed independently on each platform.

Behavior Expected include control Expected omit behavior iOS Android
Existing cookies, direct request sent not sent PASS PASS
Existing cookies, followed 302 sent not sent PASS PASS
Direct response Set-Cookie persisted ignored PASS PASS
302 response Set-Cookie on redirected request sent not sent PASS PASS
302 response Set-Cookie after the request persisted ignored PASS PASS

Implementation context

The current request path also appears to implement this behavior explicitly:

The native withCredentials wiring landed in 2017 (iOS, Android); the current Known Issues text was added later in react-native-website#769 in 2019. This history alone does not establish which edge cases were broken in 2019, but the unconditional wording does not match the current tested behavior.

Related older reports describe omit failing rather than the documentation being stale: #12956 and #30885. Neither documents a current remaining failure mode.

Request

Please remove credentials: 'omit' from the list of unsupported options in the current / 0.86 Networking docs. If a specific remaining edge case is known, please narrow the warning to that platform, version, or scenario and link the corresponding report.

Linguagem predominante
C++
Estrelas
127k
Forks
25.3k
Métricas de merge de PRs
Nenhum PR com merge em 30d

Guia de contribuição

Abrir o guia de contribuição

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de react/react-native

Todas as issues de react/react-native

Issues semelhantes

Mais issues de C++

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.