Skip to content

chore(deps): update Tauri to 2.12 and refresh core dependencies - #220

Merged
juacker merged 2 commits into
mainfrom
chore/tauri-2-12-dependencies
Sep 26, 2026
Merged

juacker merged 2 commits into
mainfrom
chore/tauri-2-12-dependencies

Conversation

@juacker

@juacker juacker commented Sep 26, 2026

Copy link
Copy Markdown
Collaborator

Summary

Bumps Tauri to 2.12.0 (stable, released 2026-09-26), keeps the Rust and npm Tauri packages on the same major.minor, and refreshes the main in-major dependencies. It also fixes an OAuth regression that the rmcp 1.8 bump introduced.

Versions

Rust: tauri 2.12.0, tauri-build 2.7.0, plugin-updater 2.12.0, plugin-dialog 2.7.3, plugin-opener 2.5.5, plugin-clipboard-manager 2.3.3, plugin-os 2.3.2, rmcp 1.8.0, aliased reqwest 0.13.5, tokio 1.53.1, axum 0.8.9. The main reqwest stays on 0.12.

npm: @tauri-apps/api, cli and plugin-updater 2.12.0; dialog 2.7.3; opener 2.5.5; clipboard 2.3.3; os 2.3.2; dompurify override 3.4.16 (security fix); @xyflow/react 12.12.0; react-router 8.4.0; mermaid 11.17.2; vega-embed 7.3.0; zustand 5.0.15; immer 11.1.18; vitest and coverage 4.1.11; jsdom 30.1.1.

Tauri 2.12 needs Rust 1.90 and no longer supports Windows 7.

OAuth fix (rmcp 1.8)

In rmcp 1.8, handle_callback passes no issuer. If the server's metadata advertises authorization_response_iss_parameter_supported, rmcp then fails the token exchange with AuthorizationServerMissingIssuer, even when the callback carried a correct iss. This PR adds exchange_authorization_code, which calls handle_callback_with_issuer(..., callback.iss). It also removes our own callback_issuer_matches: rmcp's check is at least as strict in every case.

  • New tests (local axum token endpoint on an ephemeral port): a matching iss succeeds, while a mismatched or missing iss is rejected before any token request. The success test fails if the old call is restored.
  • Behaviour change: a callback with iss is now rejected when the server's discovery metadata has no issuer. Such servers are non-compliant, since RFC 8414 requires issuer.

Verification

  • cargo check --locked, updater tests (21), MCP client tests (8), mcp::oauth::tests (2).
  • npm ci, lint, typecheck, 692 frontend tests and a production build.
  • Two review rounds: round 1 found the OAuth blocker; round 2 returned production_quality with only minor findings.

Deferred

  • React 19.3 changes behaviour (transitions, Trusted Types).
  • Major-version bumps, including rmcp 3.x and Tauri 3, which is still alpha.
  • Enabling updater requireSignedVersion is a separate security follow-up.
  • Removing the unused @tauri-apps/plugin-updater npm package and the updater:default capability.
  • Tightening the issuer-error test assertion (minor).

Suggested manual smoke test (tauri dev)

  • File dialogs (skills import, save file preview).
  • Clipboard image paste in the terminal.
  • Opening external links.
  • Update check.
  • MCP OAuth login against a real provider.

rmcp 1.8's handle_callback passes iss=None, which fails RFC 9207 servers
advertising authorization_response_iss_parameter_supported. Forward the
callback iss via handle_callback_with_issuer and drop CLAI's own issuer
check, which rmcp now enforces equally or more strictly. Refresh stale
rmcp 1.7 comments.
@juacker
juacker marked this pull request as ready for review September 26, 2026 22:57
@juacker
juacker merged commit 91cb32f into main Sep 26, 2026
2 checks passed
@juacker
juacker deleted the chore/tauri-2-12-dependencies branch September 26, 2026 23:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant