Skip to content

chore: sync upstream PR #8593 - fix(cli): load default exports from JavaScript config - #139

Open
riderx wants to merge 41 commits into
plusfrom
sync/upstream-pr-8593
Open

riderx wants to merge 41 commits into
plusfrom
sync/upstream-pr-8593

Conversation

@riderx

@riderx riderx commented Sep 9, 2026 •

Copy link
Copy Markdown
Member

Merge Conflict Review Required

The sync of upstream PR ionic-team#8593 from @jabrailkhalil encountered merge conflicts.

Original PR: ionic-team#8593

What happened

  • Git applied the upstream-preferred merge strategy
  • This PR requires CI and manual review before merging

Synced from upstream by Capacitor+ Bot


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Review in cubic

Github Workflow (on behalf of markemer) and others added 30 commits May 7, 2026 16:55
Co-authored-by: jcesarmobile <jcesarmobile@gmail.com>
Co-authored-by: Joey Pender <joey.pender@outsystems.com>
Co-authored-by: Pedro Bilro <pedro.gustavo.bilro@outsystems.com>
Co-authored-by: Mark Anderson <mark.anderson@outsystems.com>
…#8476)

Co-authored-by: jcesarmobile <jcesarmobile@gmail.com>
…am#8492)

Co-authored-by: Mark Anderson <mark.anderson@outsystems.com>
@riderx

riderx commented Sep 9, 2026

Copy link
Copy Markdown
Member Author

Git applied the upstream-preferred strategy to resolve this sync. Please review the branch carefully before merging.

@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown

Beta npm build

Maintainers can publish one Capacitor Plus workspace package from this PR to npm for fast testing.

Comment /publish-beta <package> after the PR checks are green.

Examples:

/publish-beta core
/publish-beta cli
/publish-beta @capacitor-plus/core

If exactly one workspace package changed, /publish-beta without a package will use that package.

Packages:

  • core (@capacitor-plus/core)
  • cli (@capacitor-plus/cli)
  • android (@capacitor-plus/android)
  • ios (@capacitor-plus/ios)

The workflow will:

  • publish a prerelease package on the beta tag
  • update this comment with the install command

Security note: beta publish is only enabled for branches inside this repository.

@coderabbitai

coderabbitai Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 3 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 4ae2f9b3-3cfa-4440-b2da-3632f606bb48

📥 Commits

Reviewing files that changed from the base of the PR and between 8687b31 and 65a4502.

📒 Files selected for processing (47)
  • .github/workflows/ci.yml
  • CHANGELOG.md
  • android/CHANGELOG.md
  • android/capacitor/src/androidTest/AndroidManifest.xml
  • android/capacitor/src/androidTest/java/com/getcapacitor/android/HttpInterceptorNavigationTest.java
  • android/capacitor/src/androidTest/java/com/getcapacitor/android/InterceptorAllowingPlugin.java
  • android/capacitor/src/androidTest/java/com/getcapacitor/android/TestHostActivity.java
  • android/capacitor/src/main/assets/native-bridge.js
  • android/capacitor/src/main/java/com/getcapacitor/Bridge.java
  • android/capacitor/src/main/java/com/getcapacitor/BridgeWebChromeClient.java
  • android/capacitor/src/main/java/com/getcapacitor/Plugin.java
  • android/capacitor/src/main/java/com/getcapacitor/WebViewLocalServer.java
  • android/capacitor/src/main/java/com/getcapacitor/cordova/MockCordovaWebViewImpl.java
  • android/capacitor/src/main/java/com/getcapacitor/plugin/SystemBars.java
  • android/capacitor/src/test/java/com/getcapacitor/plugin/SystemBarsTest.java
  • android/capacitor/src/test/java/com/getcapacitor/plugin/util/HttpRequestHandlerTest.java
  • android/package.json
  • cli/CHANGELOG.md
  • cli/package.json
  • cli/src/config.ts
  • cli/src/declarations.ts
  • cli/src/ios/update.ts
  • cli/src/tasks/migrate-uiscene.ts
  • cli/src/tasks/migrate.ts
  • cli/src/tasks/run.ts
  • cli/src/util/node.ts
  • cli/src/util/spm.ts
  • cli/src/util/xcode.ts
  • cli/test/config.spec.ts
  • cli/test/migrate-uiscene-plist.spec.ts
  • cli/test/migrate-uiscene-scan.spec.ts
  • cli/test/xcode.spec.ts
  • core/CHANGELOG.md
  • core/native-bridge.ts
  • core/package.json
  • core/system-bars.md
  • ios-pods-template/App/App/Info.plist
  • ios-spm-template/App/App/Info.plist
  • ios/CHANGELOG.md
  • ios/Capacitor/Capacitor.xcodeproj/project.pbxproj
  • ios/Capacitor/Capacitor/CAPSceneDelegateProxy.swift
  • ios/Capacitor/Capacitor/CapacitorBridge.swift
  • ios/Capacitor/Capacitor/WebViewAssetHandler.swift
  • ios/Capacitor/Capacitor/WebViewDelegationHandler.swift
  • ios/Capacitor/Capacitor/assets/native-bridge.js
  • ios/Capacitor/CapacitorTests/HttpInterceptorNavigationTests.swift
  • ios/package.json

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

21 issues found across 43 files

Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name=".github/workflows/ci.yml">

<violation number="1" location=".github/workflows/ci.yml:24">
P2: This PR raises `timeout-minutes` from 10 to 30 in every CI job, which contradicts the documented convention in AGENTS.md: 'Timeouts ≤10 min: `timeout-minutes: 10` or less in CI'. A hung job now burns 30 minutes of macOS/Ubuntu runner time before being killed, and the change is unrelated to the PR's stated purpose (loading default exports from JS config). Revert to `timeout-minutes: 10` unless there is a concrete need.</violation>
</file>

<file name="cli/src/util/xcode.ts">

<violation number="1" location="cli/src/util/xcode.ts:23">
P1: When the file reference already exists but is missing from the App target’s Sources phase, `project.hasFile` returns true and this guard skips registration, leaving `SceneDelegate.swift` out of the target and potentially breaking the iOS build. Restore the target-source membership check and repair the existing reference instead of treating every existing file reference as fully registered.</violation>
</file>

<file name="cli/src/tasks/migrate.ts">

<violation number="1" location="cli/src/tasks/migrate.ts:449">
P2: The merge conflict resolution dropped the `@capacitor-plus/ios` check, so users of the fork's iOS platform package no longer see the 'Capacitor 8.5 adopts UIScene on iOS' migration warning. This fork supports `@capacitor-plus/ios` as a first-class package (it is in the `libs` array here, and the same file at line 186 plus `doctor.ts` and `ios/update.ts` all handle it), so the warning must fire for it too. Restore the removed condition.</violation>
</file>

<file name="cli/src/tasks/migrate-uiscene.ts">

<violation number="1" location="cli/src/tasks/migrate-uiscene.ts:232">
P1: When a user's `AppDelegate.swift` contains `}` in a comment or string literal, this scan treats it as the class terminator. `insertBeforeAppDelegateClassEnd` then writes invalid Swift, while `hasCustomDelegateBody` can stop before the real handler; restore the Swift-aware brace scanner and reuse it in these functions.</violation>
</file>

<file name="core/CHANGELOG.md">

<violation number="1" location="core/CHANGELOG.md:6">
P3: This sync drops the @capacitor-plus/core changelog history for the versions the fork actually published (8.5.2 and 8.5.1 under Cap-go/capacitor-plus) and overwrites it with upstream's 8.5.1. The fork's release notes for those published versions are now lost from the changelog. Preserve the fork-specific 8.5.2/8.5.1 entries when applying the upstream changelog, or confirm this loss is intentional before merging.</violation>
</file>

<file name="android/capacitor/src/test/java/com/getcapacitor/plugin/SystemBarsTest.java">

<violation number="1" location="android/capacitor/src/test/java/com/getcapacitor/plugin/SystemBarsTest.java:68">
P2: This diff deletes all tests covering the hide path (setHidden(true, ...)) and the navBarVisible tracking, while SystemBars.java is unchanged and still depends on that behavior: hide() calls setHidden(true, bar), and navBarVisible controls getNavBarHeightFromResources() used for the safe-area bottom inset on API < 30. Since the PR is an unrelated CLI sync and these look like merge-conflict artifacts, please restore the removed hide/navBarVisible tests rather than dropping coverage for live production logic.</violation>
</file>

<file name="android/capacitor/src/main/java/com/getcapacitor/WebViewLocalServer.java">

<violation number="1" location="android/capacitor/src/main/java/com/getcapacitor/WebViewLocalServer.java:190">
P1: A script subresource can bypass this check because it is not a main-frame request and normally has no `Upgrade-Insecure-Requests` header, so the proxy serves attacker-controlled JavaScript in the app origin. Restrict the proxy to bridge-marked fetch/XHR requests or explicitly reject executable subresource destinations instead of treating every non-document request as safe.</violation>
</file>

<file name="cli/src/tasks/run.ts">

<violation number="1" location="cli/src/tasks/run.ts:124">
P2: The catch (error) path of runCommand no longer reverts the Android manifest after a failed live-reload run, while the SIGINT path still does (lines 111-112). When `run` throws after writeCordovaAndroidManifest(..., true) at line 102, revertCapConfigForLiveReload restores only the config, leaving the merged cordova plugin entries and cleartext setting in the manifest — a half-reverted, inconsistent project state. This removal is unrelated to the PR's stated purpose (config default exports), so restore the manifest revert in the error path unless the drop was intentional.</violation>
</file>

<file name="cli/CHANGELOG.md">

<violation number="1" location="cli/CHANGELOG.md:6">
P2: The conflict resolution drops this fork's own changelog entries for `@capacitor-plus/cli` 8.5.2 (2026-08-26) and 8.5.1 (2026-08-25), replacing the top of the file with upstream's 8.5.1 entry. Those two entries were "Version bump only for package @capacitor-plus/cli" — the actual release history for this package — so this PR erases the documented releases of the fork package. Keep the fork's 8.5.2/8.5.1 records above the upstream entries instead of deleting them.</violation>

<violation number="2" location="cli/CHANGELOG.md:8">
P3: Changing the section headings under the minor-release headers from `##` to `###` breaks the markdown heading hierarchy. `# [8.5.0]` and `# [8.4.0]` are `#` (h1) headers, so their `Bug Fixes`/`Features` sections should be `##` (h2); they are now `###` (h3), skipping a level. Patch releases use `##` headers with `###` sections, so this change makes the minor releases inconsistent with the rest of the file. Restore `## Bug Fixes` / `## Features` under the `#` minor-release headers.</violation>
</file>

<file name="cli/test/config.spec.ts">

<violation number="1" location="cli/test/config.spec.ts:31">
P2: This test requires the compiled `../dist/config.js`, which only exists after `bun run build`. The `test` script is just `jest -i` and does not build, and `cli/dist/` is gitignored, so running `npm test`/`jest` in `cli/` on a fresh checkout fails with "Cannot find module '../dist/config.js'". CI happens to build first, but every other spec in this suite imports from `../src/*` and works without a build. Add a `build` step to the `test` script (or a beforeAll that builds) so the documented test command runs standalone.</violation>
</file>

<file name="cli/src/ios/update.ts">

<violation number="1" location="cli/src/ios/update.ts:62">
P2: This newly added block duplicates the Package.swift version-patching logic that already exists a few lines below in the same function (the `if (validSPMPackages.length > 0)` block). Both read each plugin's Package.swift, compare the capacitor-swift-pm dependency major against the installed platform major, and rewrite the `from:` constraint via `setAllStringIn` + `writeFile`. Running the new block means every plugin's Package.swift is patched twice per sync, and the same non-trivial regex/rewrite logic is maintained in two places. Remove this added block and keep the existing, better-guarded one.</violation>
</file>

<file name="core/package.json">

<violation number="1" location="core/package.json:2">
P0: The merge-conflict resolution reverted the fork's package names from `@capacitor-plus/*` to the official `@capacitor/*` scope and downgraded the version 8.5.2 -> 8.5.1 across lerna.json and all four package.json files. This is the upstream metadata being taken in place of the Capacitor+ customizations. Publishing under `@capacitor/*` collides with the real npm packages, and the CLI's own source resolves `@capacitor-plus/${platform}` (cli/src/common.ts), so installed `@capacitor-plus` packages can no longer be found. Restore the `@capacitor-plus/*` names and 8.5.2 version in all four package.json files and lerna.json, keeping the actual upstream code change (#8593) only.</violation>
</file>

<file name="cli/src/util/spm.ts">

<violation number="1" location="cli/src/util/spm.ts:140">
P1: On Windows, the symlink branch of `relPath` is no longer normalized. Previously `symlinkFolder` was passed through `convertToUnixPath` (which replaces `\` with `/`); after this refactor the `symlink ? symlinkFolder` branch returns `join('symlinks', plugin.name)` raw, which on Windows contains backslashes. That value is written verbatim into `Package.swift` as `path: "..."`, producing an invalid non-Unix path in the Swift Package manifest. Wrap the symlink branch (or the whole expression) in `convertToUnixPath`.</violation>

<violation number="2" location="cli/src/util/spm.ts:278">
P2: Adding both `UISceneDelegateClassName` and `UISceneStoryboardFile: 'Main'` makes iOS auto-instantiate the storyboard's initial view controller and set it as the scene root *before* `SceneDelegate.willConnectTo` runs. In the shipped template that initial VC is `CAPBridgeViewController`, so a second bridge/view controller is created and its view loaded, then replaced by the one `willConnectTo` creates — and if a migrated app's `Main` storyboard is missing or has no designated entry point, the app crashes at launch ('Failed to instantiate the default view controller for UIMainStoryboardFile Main'). This is applied unconditionally by the migration without checking the target app actually has a usable `Main` storyboard. Consider omitting `UISceneStoryboardFile` (the new scene architecture sets the root controller programmatically) or guarding on the storyboard's existence/entry point.</violation>
</file>

<file name="android/capacitor/src/main/java/com/getcapacitor/BridgeWebChromeClient.java">

<violation number="1" location="android/capacitor/src/main/java/com/getcapacitor/BridgeWebChromeClient.java:416">
P1: Removing the static pending state in showImageCapturePicker breaks camera file selection when the Activity is recreated mid-capture. handlePendingFileChooserResult still branches on FileChooserType.IMAGE_CAPTURE and pendingImageFileUri, but with these statics no longer set, the recreation path (activityListener == null, pendingFilePathCallback == null) drops the result and the web file-input callback never fires, leaving the picker hanging. VIDEO_CAPTURE and FILE_PICKER still set the same statics, so IMAGE_CAPTURE is now inconsistent. Restore the stored state (or add a dedicated recreation path for image capture) so captured images are delivered after recreation.</violation>
</file>

<file name="ios/Capacitor/Capacitor/CapacitorBridge.swift">

<violation number="1" location="ios/Capacitor/Capacitor/CapacitorBridge.swift:267">
P2: Each matching scene lifecycle notification now dispatches the `resume` or `pause` document event twice because this pair duplicates the registrations immediately below. Remove one foreground/background observer pair so application listeners run once per lifecycle transition.</violation>
</file>

<file name="cli/test/migrate-uiscene-scan.spec.ts">

<violation number="1" location="cli/test/migrate-uiscene-scan.spec.ts:155">
P2: The `.build` directory skip filter is still active in `migrate-uiscene.ts` (line 96), but this change drops the only test that covered it. A future regression in that filter would go undetected. Keep the `dotBuildDir` setup/assertion and the original test title so the `.build` exclusion stays covered.</violation>
</file>

<file name="ios/Capacitor/Capacitor/CAPSceneDelegateProxy.swift">

<violation number="1" location="ios/Capacitor/Capacitor/CAPSceneDelegateProxy.swift:24">
P2: After this observer fires, the closure retains its observer token because `token = nil` was removed. That creates a retain cycle after `removeObserver(token)` and leaks one observer and its captured scene per connection; clear `token` after removing the observer.</violation>

<violation number="2" location="ios/Capacitor/Capacitor/CAPSceneDelegateProxy.swift:24">
P1: When multiple scenes connect, the first global `capacitorViewDidAppear` invokes every pending observer, including observers for scenes whose bridges are not ready. Keep a scene-specific bridge-readiness check, or otherwise filter this notification by scene, before forwarding the connection options.</violation>
</file>

<file name="android/capacitor/src/main/java/com/getcapacitor/Bridge.java">

<violation number="1" location="android/capacitor/src/main/java/com/getcapacitor/Bridge.java:399">
P2: When an external or configured allowed URL has a path beginning with `CAPACITOR_HTTP_INTERCEPTOR_START`, this early return bypasses the host/scheme and allow-navigation policy and aborts the navigation. Restrict the proxy guard to the app origin before returning `true`.</violation>
</file>

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread core/package.json
"description": "Capacitor+: Enhanced Capacitor with automated upstream sync - Cross-platform apps with JavaScript and the web",
"homepage": "https://capgo.app/docs/plugins/capacitor-plus/",
"author": "Capgo Team <support@capgo.app> (https://capgo.app)",
"name": "@capacitor/core",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P0: The merge-conflict resolution reverted the fork's package names from @capacitor-plus/* to the official @capacitor/* scope and downgraded the version 8.5.2 -> 8.5.1 across lerna.json and all four package.json files. This is the upstream metadata being taken in place of the Capacitor+ customizations. Publishing under @capacitor/* collides with the real npm packages, and the CLI's own source resolves @capacitor-plus/${platform} (cli/src/common.ts), so installed @capacitor-plus packages can no longer be found. Restore the @capacitor-plus/* names and 8.5.2 version in all four package.json files and lerna.json, keeping the actual upstream code change (ionic-team#8593) only.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At core/package.json, line 2:

<comment>The merge-conflict resolution reverted the fork's package names from `@capacitor-plus/*` to the official `@capacitor/*` scope and downgraded the version 8.5.2 -> 8.5.1 across lerna.json and all four package.json files. This is the upstream metadata being taken in place of the Capacitor+ customizations. Publishing under `@capacitor/*` collides with the real npm packages, and the CLI's own source resolves `@capacitor-plus/${platform}` (cli/src/common.ts), so installed `@capacitor-plus` packages can no longer be found. Restore the `@capacitor-plus/*` names and 8.5.2 version in all four package.json files and lerna.json, keeping the actual upstream code change (#8593) only.</comment>

<file context>
@@ -1,9 +1,9 @@
-  "description": "Capacitor+: Enhanced Capacitor with automated upstream sync - Cross-platform apps with JavaScript and the web",
-  "homepage": "https://capgo.app/docs/plugins/capacitor-plus/",
-  "author": "Capgo Team <support@capgo.app> (https://capgo.app)",
+  "name": "@capacitor/core",
+  "version": "8.5.1",
+  "description": "Capacitor: Cross-platform apps with JavaScript and the web",
</file context>
Suggested change
"name": "@capacitor/core",
"name": "@capacitor-plus/core",

Comment thread cli/src/util/xcode.ts

const targetUuid = project.getFirstTarget().uuid;
if (project.hasFile(fileRelPath) && isSwiftFileInTargetSources(project, fileRelPath, targetUuid)) {
if (project.hasFile(fileRelPath)) {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1: When the file reference already exists but is missing from the App target’s Sources phase, project.hasFile returns true and this guard skips registration, leaving SceneDelegate.swift out of the target and potentially breaking the iOS build. Restore the target-source membership check and repair the existing reference instead of treating every existing file reference as fully registered.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At cli/src/util/xcode.ts, line 23:

<comment>When the file reference already exists but is missing from the App target’s Sources phase, `project.hasFile` returns true and this guard skips registration, leaving `SceneDelegate.swift` out of the target and potentially breaking the iOS build. Restore the target-source membership check and repair the existing reference instead of treating every existing file reference as fully registered.</comment>

<file context>
@@ -21,8 +20,7 @@ export function addSwiftFileToAppTarget(
 
-  const targetUuid = project.getFirstTarget().uuid;
-  if (project.hasFile(fileRelPath) && isSwiftFileInTargetSources(project, fileRelPath, targetUuid)) {
+  if (project.hasFile(fileRelPath)) {
     return { added: false };
   }
</file context>

let i = openIdx + 1;
while (i < appDelegateSource.length && depth > 0) {
const ch = appDelegateSource[i];
if (ch === '{') depth++;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1: When a user's AppDelegate.swift contains } in a comment or string literal, this scan treats it as the class terminator. insertBeforeAppDelegateClassEnd then writes invalid Swift, while hasCustomDelegateBody can stop before the real handler; restore the Swift-aware brace scanner and reuse it in these functions.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At cli/src/tasks/migrate-uiscene.ts, line 232:

<comment>When a user's `AppDelegate.swift` contains `}` in a comment or string literal, this scan treats it as the class terminator. `insertBeforeAppDelegateClassEnd` then writes invalid Swift, while `hasCustomDelegateBody` can stop before the real handler; restore the Swift-aware brace scanner and reuse it in these functions.</comment>

<file context>
@@ -329,11 +225,18 @@ function extractConfigurationForConnecting(appDelegateSource: string): string |
+  let i = openIdx + 1;
+  while (i < appDelegateSource.length && depth > 0) {
+    const ch = appDelegateSource[i];
+    if (ch === '{') depth++;
+    else if (ch === '}') depth--;
+    i++;
</file context>

var token: NSObjectProtocol?
token = NotificationCenter.default.addObserver(forName: .capacitorViewDidAppear, object: nil, queue: .main) { [weak self] _ in
guard let self, Self.isBridgeReady(for: scene) else { return }
token = NotificationCenter.default.addObserver(forName: .capacitorViewDidAppear, object: nil, queue: .main) { _ in

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1: When multiple scenes connect, the first global capacitorViewDidAppear invokes every pending observer, including observers for scenes whose bridges are not ready. Keep a scene-specific bridge-readiness check, or otherwise filter this notification by scene, before forwarding the connection options.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At ios/Capacitor/Capacitor/CAPSceneDelegateProxy.swift, line 24:

<comment>When multiple scenes connect, the first global `capacitorViewDidAppear` invokes every pending observer, including observers for scenes whose bridges are not ready. Keep a scene-specific bridge-readiness check, or otherwise filter this notification by scene, before forwarding the connection options.</comment>

<file context>
@@ -22,12 +21,10 @@ public class SceneDelegateProxy: NSObject, UISceneDelegate {
         var token: NSObjectProtocol?
-        token = NotificationCenter.default.addObserver(forName: .capacitorViewDidAppear, object: nil, queue: .main) { [weak self] _ in
-            guard let self, Self.isBridgeReady(for: scene) else { return }
+        token = NotificationCenter.default.addObserver(forName: .capacitorViewDidAppear, object: nil, queue: .main) { _ in
             if let token {
                 NotificationCenter.default.removeObserver(token)
</file context>

if (null != loadingUrl.getPath() && loadingUrl.getPath().startsWith(Bridge.CAPACITOR_HTTP_INTERCEPTOR_START)) {
// Only fetch/XHR should reach the proxy; a document would run remote content at the app origin.
boolean httpEnabled = bridge.getConfig().getPluginConfiguration("CapacitorHttp").getBoolean("enabled", false);
if (!httpEnabled || isDocumentRequest(request)) {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1: A script subresource can bypass this check because it is not a main-frame request and normally has no Upgrade-Insecure-Requests header, so the proxy serves attacker-controlled JavaScript in the app origin. Restrict the proxy to bridge-marked fetch/XHR requests or explicitly reject executable subresource destinations instead of treating every non-document request as safe.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At android/capacitor/src/main/java/com/getcapacitor/WebViewLocalServer.java, line 190:

<comment>A script subresource can bypass this check because it is not a main-frame request and normally has no `Upgrade-Insecure-Requests` header, so the proxy serves attacker-controlled JavaScript in the app origin. Restrict the proxy to bridge-marked fetch/XHR requests or explicitly reject executable subresource destinations instead of treating every non-document request as safe.</comment>

<file context>
@@ -185,6 +185,11 @@ public WebResourceResponse shouldInterceptRequest(WebResourceRequest request) {
         if (null != loadingUrl.getPath() && loadingUrl.getPath().startsWith(Bridge.CAPACITOR_HTTP_INTERCEPTOR_START)) {
+            // Only fetch/XHR should reach the proxy; a document would run remote content at the app origin.
+            boolean httpEnabled = bridge.getConfig().getPluginConfiguration("CapacitorHttp").getBoolean("enabled", false);
+            if (!httpEnabled || isDocumentRequest(request)) {
+                return null;
+            }
</file context>

Comment thread cli/src/util/spm.ts
{
UISceneConfigurationName: 'Default Configuration',
UISceneDelegateClassName: '$(PRODUCT_MODULE_NAME).SceneDelegate',
UISceneStoryboardFile: 'Main',

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2: Adding both UISceneDelegateClassName and UISceneStoryboardFile: 'Main' makes iOS auto-instantiate the storyboard's initial view controller and set it as the scene root before SceneDelegate.willConnectTo runs. In the shipped template that initial VC is CAPBridgeViewController, so a second bridge/view controller is created and its view loaded, then replaced by the one willConnectTo creates — and if a migrated app's Main storyboard is missing or has no designated entry point, the app crashes at launch ('Failed to instantiate the default view controller for UIMainStoryboardFile Main'). This is applied unconditionally by the migration without checking the target app actually has a usable Main storyboard. Consider omitting UISceneStoryboardFile (the new scene architecture sets the root controller programmatically) or guarding on the storyboard's existence/entry point.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At cli/src/util/spm.ts, line 278:

<comment>Adding both `UISceneDelegateClassName` and `UISceneStoryboardFile: 'Main'` makes iOS auto-instantiate the storyboard's initial view controller and set it as the scene root *before* `SceneDelegate.willConnectTo` runs. In the shipped template that initial VC is `CAPBridgeViewController`, so a second bridge/view controller is created and its view loaded, then replaced by the one `willConnectTo` creates — and if a migrated app's `Main` storyboard is missing or has no designated entry point, the app crashes at launch ('Failed to instantiate the default view controller for UIMainStoryboardFile Main'). This is applied unconditionally by the migration without checking the target app actually has a usable `Main` storyboard. Consider omitting `UISceneStoryboardFile` (the new scene architecture sets the root controller programmatically) or guarding on the storyboard's existence/entry point.</comment>

<file context>
@@ -275,6 +275,7 @@ export async function addSceneManifestIfNeeded(config: Config): Promise<void> {
         {
           UISceneConfigurationName: 'Default Configuration',
           UISceneDelegateClassName: '$(PRODUCT_MODULE_NAME).SceneDelegate',
+          UISceneStoryboardFile: 'Main',
         },
       ],
</file context>

Comment thread cli/src/ios/update.ts
await generateCordovaPackageFiles(cordovaPlugins, config);

const validSPMPackages = await checkPluginsForPackageSwift(config, plugins);
await Promise.all(

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2: This newly added block duplicates the Package.swift version-patching logic that already exists a few lines below in the same function (the if (validSPMPackages.length > 0) block). Both read each plugin's Package.swift, compare the capacitor-swift-pm dependency major against the installed platform major, and rewrite the from: constraint via setAllStringIn + writeFile. Running the new block means every plugin's Package.swift is patched twice per sync, and the same non-trivial regex/rewrite logic is maintained in two places. Remove this added block and keep the existing, better-guarded one.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At cli/src/ios/update.ts, line 62:

<comment>This newly added block duplicates the Package.swift version-patching logic that already exists a few lines below in the same function (the `if (validSPMPackages.length > 0)` block). Both read each plugin's Package.swift, compare the capacitor-swift-pm dependency major against the installed platform major, and rewrite the `from:` constraint via `setAllStringIn` + `writeFile`. Running the new block means every plugin's Package.swift is patched twice per sync, and the same non-trivial regex/rewrite logic is maintained in two places. Remove this added block and keep the existing, better-guarded one.</comment>

<file context>
@@ -59,6 +59,30 @@ async function updatePluginFiles(config: Config, plugins: Plugin[], deployment:
     await generateCordovaPackageFiles(cordovaPlugins, config);
 
     const validSPMPackages = await checkPluginsForPackageSwift(config, plugins);
+    await Promise.all(
+      validSPMPackages.map(async (plugin) => {
+        const iosPlatformVersion = await getCapacitorPackageVersion(config, config.ios.name);
</file context>

Comment thread core/CHANGELOG.md
**Note:** Version bump only for package @capacitor-plus/core


## [8.5.1](https://github.com/ionic-team/capacitor/compare/8.5.0...8.5.1) (2026-08-31)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P3: This sync drops the @capacitor-plus/core changelog history for the versions the fork actually published (8.5.2 and 8.5.1 under Cap-go/capacitor-plus) and overwrites it with upstream's 8.5.1. The fork's release notes for those published versions are now lost from the changelog. Preserve the fork-specific 8.5.2/8.5.1 entries when applying the upstream changelog, or confirm this loss is intentional before merging.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At core/CHANGELOG.md, line 6:

<comment>This sync drops the @capacitor-plus/core changelog history for the versions the fork actually published (8.5.2 and 8.5.1 under Cap-go/capacitor-plus) and overwrites it with upstream's 8.5.1. The fork's release notes for those published versions are now lost from the changelog. Preserve the fork-specific 8.5.2/8.5.1 entries when applying the upstream changelog, or confirm this loss is intentional before merging.</comment>

<file context>
@@ -3,21 +3,11 @@
-**Note:** Version bump only for package @capacitor-plus/core
-
-
+## [8.5.1](https://github.com/ionic-team/capacitor/compare/8.5.0...8.5.1) (2026-08-31)
 
+### Bug Fixes
</file context>

Comment thread cli/CHANGELOG.md

## [8.5.1](https://github.com/ionic-team/capacitor/compare/8.5.0...8.5.1) (2026-08-31)

### Bug Fixes

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P3: Changing the section headings under the minor-release headers from ## to ### breaks the markdown heading hierarchy. # [8.5.0] and # [8.4.0] are # (h1) headers, so their Bug Fixes/Features sections should be ## (h2); they are now ### (h3), skipping a level. Patch releases use ## headers with ### sections, so this change makes the minor releases inconsistent with the rest of the file. Restore ## Bug Fixes / ## Features under the # minor-release headers.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At cli/CHANGELOG.md, line 8:

<comment>Changing the section headings under the minor-release headers from `##` to `###` breaks the markdown heading hierarchy. `# [8.5.0]` and `# [8.4.0]` are `#` (h1) headers, so their `Bug Fixes`/`Features` sections should be `##` (h2); they are now `###` (h3), skipping a level. Patch releases use `##` headers with `###` sections, so this change makes the minor releases inconsistent with the rest of the file. Restore `## Bug Fixes` / `## Features` under the `#` minor-release headers.</comment>

<file context>
@@ -3,29 +3,19 @@
-
+## [8.5.1](https://github.com/ionic-team/capacitor/compare/8.5.0...8.5.1) (2026-08-31)
 
+### Bug Fixes
 
+- **cli:** use POSIX paths in CapApp-SPM Package.swift ([#8549](https://github.com/ionic-team/capacitor/issues/8549)) ([5e5bb3b](https://github.com/ionic-team/capacitor/commit/5e5bb3befc312477900252ab07e23b596f8cb0d1))
</file context>

Comment thread android/capacitor/src/main/java/com/getcapacitor/plugin/SystemBars.java Outdated
@riderx
riderx force-pushed the sync/upstream-pr-8593 branch from 50688e2 to 2ad9d2d Compare September 16, 2026 06:04
@riderx

riderx commented Sep 16, 2026

Copy link
Copy Markdown
Member Author

Git applied the upstream-preferred strategy to resolve this sync. Please review the branch carefully before merging.

@riderx
riderx force-pushed the sync/upstream-pr-8593 branch from 2ad9d2d to 65a4502 Compare September 26, 2026 06:04
@riderx

riderx commented Sep 26, 2026

Copy link
Copy Markdown
Member Author

Git applied the upstream-preferred strategy to resolve this sync. Please review the branch carefully before merging.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.