NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev · #3247 most downloaded on pub.dev
macOS implementation of the zikzak_inappwebview plugin.
Last release today
07 Oct 2026
Ships on a steady schedule
a new release about every 1 weeks
Nearly every release is documented
notes for 58 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
2 years old
84 releases · first in 2024
publish.sh runs dart format lib/ per package, and this if-case pattern introduced by #346 was left wrapped unconventionally. Pure formatting — no sema
publish.sh runs dart format lib/ per package, and this if-case pattern
introduced by #346 was left wrapped unconventionally. Pure formatting — no
semantic change. Fixes it ahead of the release so the publish step does not
dirty the tree mid-run.
zorphy / zorphy_annotation to ^2.4.3 (from ^2.4.0). The 2.4.3 generators add a copyWithField<T>(Field<TEntity, T> field, T value) method to every entity family, which delegates to copyWith and never mutates the receiver. Entity JSON output is unchanged — regenerating produced no .g.dart diffs. The two hand-written TrustedWebActivityDisplayMode implementations (TrustedWebActivityDefaultDisplayMode, TrustedWebActivityImmersiveDisplayMode) now satisfy the widened interface: the fieldless default mode rejects every field name, and the immersive mode routes displayCutoutMode / isSticky through its parameterless copyWithnavigator.credentials.create / .get with publicKey options are intercepted by an injected shim (PasskeysJS.swift, installed as a WKUserScript at documentStart in every frame) and forwarded over the plugin's JS-handler channel to a native PasskeyBridge.swift driving ASAuthorizationController, which hands a WebAuthn-shaped PublicKeyCredential back to JS. This bypasses WebKit's in-page WKWebView mediation, which is broken for entitled custom-browser apps — ASCAgent dies with AuthorizationError Code=1 ~2 ms after "Allowing request from web browser." and no sheet is ever shown. WebAuthn options map onto platform registration/authentication requests (rpId defaulting to location.hostname, COSE algorithm identifiers, excludeCredentials/allowCredentials, attestation, userVerification, residentKey on macOS 14.4+); results serialize back as base64url and failures surface as real DOMExceptions — NotAllowedError for user cancel / timeout / no credentials, TypeError for malformed options, SecurityError for a non-domain rpId. Headless webviews fail fast with NotAllowedError, PublicKeyCredential.isUserVerifyingPlatformAuthenticatorAvailable() bridges to native availability, and non-publicKey credentials fall through to the platform default implementation (#358)contentBlockers no longer silently drops the initial navigation. The first load was issued only from inside the WKContentRuleListStore.compileContentRuleList completion, so a compilation error, a (nil, nil) completion, or an undelivered completion left the webview blank with no onLoadStart and no onLoadError — no error, no logs. iOS now mirrors the macOS #338 machinery: a shared applyContentBlockers funnel (stale-completion token, guarded add, main-thread completion) plus a loadAfterContentRuleLists gate that holds the initial load until compilation settles on success and on error; the content-rule store identifier is now derived from a SHA-256 of the rule content instead of a fixed ContentBlockingRules identifier that was recompiled across launches and webviews. Wired through makeInitialLoad, InAppBrowserWebViewController.viewDidLoad and setSettings. URLRequest(fromPluginMap:) now logs the rejected url before the about:blank fallback (#349)URLResponse.suggestedFilename is String? on macOS, so the empty-filename → nil mapping added for #345 did not compile and broke the build. The property is now bound to a non-optional local with ?? "" before the emptiness check — the idiom already used throughout InAppWebView.swift — so a nil name unwraps to "" and still maps to nil, preserving both the intended behavior and the pinned X.isEmpty ? nil : X shape (#346)onDownloadStartRequest drops a malformed download event instead of throwing out of the decode (#346)build-macos job (macos-15) builds the example app from this checkout via a pubspec_overrides.yaml path override, taking the matrix from 15 to 17 jobs. This closes a real gap: the macOS package's tests are source-contract tests that read the .swift files as text and assert on their shape, so they pass on Swift that does not compile — before this job landed, all 73 of them passed while nothing compiled the package at all. A green macOS test run is a floor, not evidence of compilation (#347)scripts/publish.sh analyzes with --no-fatal-infos, matching the CI gate. Bare flutter analyze exits 1 on every package's tolerated info baseline, which under set -e aborted the release before the first package shippedPasskeyBridge compiles against the macOS SDK surface rather than the iOS one: ASCOSEAlgorithmIdentifier on macOS (ASAuthorizationCOSEAlgorithmIdentifier is iOS-only), the excluded-credentials protocol guarded to macOS 13.5+, no residentKeyPreference on the platform registration request (it exists only on the security-key request, already guarded at macOS 14.4), and ASAuthorizationController.cancel() guarded to macOS 13.0+PasskeyOptionError struct instead of a (String, String) tuple — Swift's Result requires its Failure to conform to Error and tuples do not (same shape as ProxyManager's private ProxyConfigurationError)content_blockers_initial_load_test) and the passkey bridge (passkey_bridge_test); the macOS bridge also clears a real compile gate (flutter build macos --debug)worktrees extension removed, putting the triage/assess workflow on the default branch so a fresh clone already has speckit-bug-assess / speckit-chore-assess / speckit-gh-triage. Installed: spec-stats; already present: bug, chore, gh-triage, gym, tdd, git. No source files changeOne column per month.
[macOS] InAppWebViewSettings.contentBlockers is now actually applied. The setting was declared and decoded on macOS but never consumed — no WKContentR
InAppWebViewSettings.contentBlockers is now actually applied. The setting was declared and decoded on macOS but never consumed — no WKContentRuleList was ever compiled or added, so ad/tracker blocking was silently inert while the identical setting works on iOS. setSettings now removes all content rule lists, serializes the decoded blockers, compiles them through WKContentRuleListStore under the shared ContentBlockingRules identifier, and adds the result to configuration.userContentController; an empty list clears blocking without compiling. Compilations are serialized with a token so a stale completion can no longer re-add rules a newer update removed, and a single applyContentBlockers funnel serves platform views, InAppBrowser, headless webviews and runtime updates (#338)useOnDownloadStart / onDownloadStartRequest are now wired. macOS declared the setting and accepted the Dart callback, but no Swift code read the flag and no WKDownload plumbing existed, so the documented support could never fire. The package now adopts WKDownloadDelegate, returns .download from the navigation-response policy when the MIME type cannot be shown (with an iOS-style main-frame/non-text-mime fallback that dispatches the event and cancels), dispatches the event and cancels the native download from the destination callback so Dart streams the bytes, maps Dart policy DOWNLOAD to .download in shouldOverrideUrlLoading, bridges through WebViewChannelDelegate, and routes the event in the Dart controller. The action-stage handoff now reports a real contentLength and derives suggestedFilename from the URL path (#339, #340, #344)InAppBrowser forwards onDownloadStartRequest to its event handler — downloads started in the browser never surfaced an event before (#344)clipsToBounds is set unconditionally at view setup; on macOS layer.masksToBounds = true is pinned at construction time (after wantsLayer, so the pin cannot be a silent no-op) and re-asserted after the web view is embedded. An NSView does not clip by default, so a native layer could paint over sibling Flutter content on a mis-clipped compositing path (#331, #336, #337)shouldOverrideUrlLoading. Payment and authentication deep links such as weixin:// were cancelled by the native pre-navigation gate before the host navigation delegate ran, so a host could not intercept them and open the URL externally. The gate now blocks only what URLValidationManager already treats as dangerous (blocked schemes, failing scheme-specific checks, schemeless URLs, a rejecting custom validator); a custom scheme that no host policy handles is still cancelledEXC_BREAKPOINT crash on macOS 15.x. WKNavigationAction.sourceFrame is declared non-optional by the Swift overlay, but WebKit can deliver a nil runtime object, and member access then traps in the unconditional Objective-C bridge. Navigation source frame and request/security origin are now read through a KVC-based accessor that yields nil for a nil runtime frame, at both the shouldOverrideUrlLoading and onCreateWindow call sites. With a present frame the emitted map is unchanged; with a nil frame Dart receives sourceFrame: null, which NavigationAction/CreateWindowAction already model as nullable (#327)onDownloadStartRequest tolerates a null arguments map and drops a URL-less payload instead of throwing out of DownloadStartRequest.fromJson (#344)URLValidationManager no longer evaluate a custom scheme twice — one scheme policy returns an explicit block / defer-to-host / allow decision that is reused as the delegate fallback, so a host custom validator runs once per navigation. The fallback stays fail-closedcontent_blockers_parity_test, content_blockers_rule_list_test, download_start_request_parity_test, swift_sourceframe_kvc_test, swift_platform_view_clipping_test, ios_custom_scheme_navigation_test)InAppWebView/WebViewChannelDelegate param-listener tests hardened: handleMethod now proves a decoded download event reaches the params callback and that a malformed one is dropped.specify/bugs/, with TDD cycle logs and verification reportsapple-app-site-association host, document-focus gotcha) in INSIGHTS.md.specify/bugs/flutter347-platformview-rendering/fix: revert zuraffa_session to ^1.1.0 (6.3.0 not on pub.dev)
fix: revert zuraffa_session to ^1.1.0 (6.3.0 not on pub.dev)
zorphy / zorphy_annotation to ^2.4.0zuraffa_session to ^1.1.0tool/versions.dart, tool/update_readmes.dart) so all package and dependency versions are defined in one place and README snippets stay in sync automatically^4.6.0 install snippet in root README and umbrella README to ^6.0.2evaluateJavaScript override to stop a SIGBUS on first evaluationbuild-ios CI job when a runner stops compiling its ARM armevaluateJavaScript arms compile[iOS] Make InAppWebView.evaluateJavaScript(_:completionHandler:) portable across Xcode versions. Its completion handler was declared @MainActor @Senda
InAppWebView.evaluateJavaScript(_:completionHandler:) portable across Xcode versions. Its completion handler was declared @MainActor @Sendable (Any?, (any Error)?) -> Void, which only matches the SDK bundled with recent Xcode. On older SDKs the method stopped overriding its superclass and the extra overload it left behind made every single-argument evaluateJavaScript(...) call ambiguous — 10 compile errors, meaning consumers on older Xcode could not build the iOS plugin at allconsoleLogEnabled: false now actually disables console interception. The guard read params.webviewParams?.settings, a field that does not exist on PlatformWebViewCreationParams — it is initialSettings — so the web implementation did not compile eitherdataStoreWasSelected in the scope shared by the iOS 9 and iOS 11 availability blocks in preWKWebViewConfiguration; it was declared inside the iOS 9 block but read by the later cookie-setup block, so the file did not compile (#316, #329)!= null guards in HttpAuthCredentialsDatabase and an unused dart:typed_data import in its screenshot/PDF delegation testflutter analyze runs with --no-fatal-infos: compile errors and warnings fail the build, style-level infos do notzikzak_inappwebview_ios joined the analyze and test matrices, and a build-ios job compiles its Swift sources from this checkout — that job is what surfaced the evaluateJavaScript breakage aboveconstant_identifier_names in zikzak_inappwebview_platform_interface/analysis_options.yaml — linter: rules: accepts only booleans, so ignore left the rule enabled and produced 558 findingsdependency_overrides, so CI exercises this checkout rather than the published artifactsSession layer renamed: zikzak_session → zuraffa_session (^1.1.0). WebViewSessions and the portable-session APIs now consume zuraffa_session types — co
zikzak_session → zuraffa_session (^1.1.0). WebViewSessions and the portable-session APIs now consume zuraffa_session types — consumers passing zikzak_session session stores must migrate their imports (package:zikzak_session/zikzak_session.dart → package:zuraffa_session/zuraffa_session.dart) or stay on 5.x.zuraffa_session).[iOS] Fix #available usage and minimum platform version mismatch — resolves iOS build failures ( #316 , #319 )
[macOS] Sanitize non-cloneable objects (DOMException, Error, RegExp, Promise, etc.) in console bridge JS before postMessage — prevents WebKit SIGSEGV
userContentController public access to satisfy WKScriptMessageHandler protocol conformance (#314)consoleLogEnabled setting (default true) — when false, the console override script is not injected and console.log/error/warn messages are NOT forwarded to Dart. Wired on all 4 platforms that intercept console: macOS, iOS, Android, Web[Windows] Add missing kDebugMode import — fixes build error in 5.3.1
kDebugMode import — fixes build error in 5.3.1 (#315)[macOS] Restore public access on userContentController(_:didReceive:) to satisfy WKScriptMessageHandler protocol conformance — fixes build breakage in
[Windows] WebView2 environment reuse is now observable and regression-tested ( #300 , #303 )
[macOS] Defensive deserialization of WKScriptMessage.body — prevents SIGSEGV crash when JS posts DOMException or other non-cloneable objects through t
[macOS] Per-profile proxy support via WKWebsiteDataStore.proxyConfigurations
docs: improve 5.1.2 changelog with pressKey fix details
docs: improve 5.1.2 changelog with pressKey fix details
pressKey in the macOS platform controller so the PlatformInAppWebViewController.pressKey API works on macOS (previously referenced but never implemented at the platform level).pressKey method on PlatformInAppWebViewController. 5.1.1 shipped zikzak_inappwebview and zikzak_inappwebview_macos calling platform.pressKey(...), but the published platform_interface 5.1.1 lacked the method, which broke compilation for consumers. This release adds pressKey to platform_interface (and its macOS implementation) so the 5.1.1 references now resolve.feat: persistent per-account website data store via persistentStoreId…
feat: persistent per-account website data store via persistentStoreId…
fix(macos): thread webViewId through cookie manager and headless/webv…
fix(macos): thread webViewId through cookie manager and headless/webv…
WebSettingsCompat.setRequestedWithHeaderOriginAllowList / getRequestedWithHeaderOriginAllowList calls (marked for removal in androidx.webkit). Eliminates the [removal] build warnings introduced in 5.0.0. The Dart requestedWithHeaderOriginAllowList setting is retained for API compatibility (#235)in_app_webview_settings.dart import in PlatformSettingsDelegate — the published 5.0.1 artifact shipped a broken relative import that broke every consumer; the source on master is corrected (in_app_webview_settings moved to lib/src/domain/entities/) (#249, #255, #257)window.zikzak_inappwebview (was window.flutter_inappwebview) in the migration guide (#258)Fixed Android ClassCastException failures when enum settings were serialized as string names instead of their expected integer wire values. Added the
ClassCastException failures when enum settings were serialized as string names instead of their expected integer wire values. Added the missing enum wire converters and corrected affected platform-interface JSON mappings.Migrated the entire platform_interface model layer to Zorphy entities — every model class is now a Zorphy entity instead of a hand-written @Exchangeab
platform_interface model layer to Zorphy entities — every model class is now a Zorphy entity instead of a hand-written @ExchangeableObject-style class (Phases 1–3j). This changes the public API surface of the platform interface (class structure, toJson/fromJson, equality) and may require updates to custom platform implementations.InAppBrowserMenuItem, tracing settings, user script, image/rect/screenshot config, in-app webview settings, and script HTML tag attributes@ExchangeableObject codegen toolchainfix(publish): convert example pubspec sibling deps to versioned for 4…
fix(publish): convert example pubspec sibling deps to versioned for 4…
HeadlessInAppWebView.run() on web-process readiness — the first real loadUrl after run() could be silently dropped by WKWebView while its content process was still booting, surfacing as "Unable to fetch data" on the very first request. run() now completes only after the initial navigation reaches a terminal state (didFinish/didFail); signal-driven, no timeout constantrun() against a missing web view (no silent hang)run() completes only after onPageFinished or a main-frame error (both InAppWebViewClient and InAppWebViewClientCompat)run() completes only after didFinish/didFailWEBKIT_LOAD_FINISHEDloadUrl, 10 sequential attempts)Session recipe — record and replay user sessions in the WebView: JS tap-listener injection, selector-candidate extraction, scripted click replay, and
keepNavigationInWebView helper that keeps user-tappedwindow.open / target=_blank now load their URLWKUIDelegate createWebViewWith off-screen-window support, reparentedonCreateWindow is handled (#182, #183, #187)onNetworkRequest / onNetworkResponse /onNetworkLoadingFinished reach Dart (#182)GtkOffscreenWindow + software rendering, plus openDevTools support (#184)takeScreenshot stringflutter_inappwebview residuals tozikzak_inappwebview (JS bridge name, method channel, platform view type id) (#186)[macOS] Use WKWebpagePreferences.allowsContentJavaScript instead of deprecated WKPreferences.javaScriptEnabled ( #212 , fixes #200 )
disableContextMenu / disableLongPressContextMenuOnLinks settings now honored, onCreateContextMenu event fired (#208, fixes #196)setInsetsForWebContentToIgnore equivalent) (#206, fixes #198)UIScrollView bouncesHorizontally / bouncesVertically (iOS 17.4+) (#209, fixes #199)InAppWebViewController into domain-specific controllers (#176)getUserMedia() — no longer silently denied (#204, fixes #195)webViewWebContentProcessDidTerminate — no more blank/unrecoverable WebView after content-process kill (#203, fixes #194)shouldOverrideUrlLoading response so cancellations are honored (#202, fixes #192)WKWebpagePreferences.allowsContentJavaScript instead of deprecated WKPreferences.javaScriptEnabled (#212, fixes #200)javaScriptEnabled read in getSelectedText (#213)Util.swift, iOS-only APIs, init ordering (#215)onPageCommitVisible / onDidReceiveServerRedirectForProvisionalNavigation method-channel handlers (#217)additionalBrowserArguments to WebView2 (#214, fixes #178)addJavaScriptHandler + JS bridge (fixes #177)androidx.core.view.OnApplyWindowInsetsListener type directly (#217)Added iOS proxy support (iOS 17.0+) — set process-wide proxy for WKWebView
HeadlessInAppWebViewWeb.dispose() missingisKeepAlive parameter that was added to PlatformHeadlessInAppWebView.disposedart2wasm and dart2js compile errorselse clause in ProxyManager guard statementProxyManager<iostream> includes and call load_initial increateHeadlessin_app_webview.ccDisposable interface on PlatformProxyController.clangd and compile_flags.txt for Linux Flutter header resolutionFixed: Web/WASM build failure — HeadlessInAppWebViewWeb.dispose() missing isKeepAlive parameter that was added to PlatformHeadlessInAppWebView.dispose
HeadlessInAppWebViewWeb.dispose() missingisKeepAlive parameter that was added to PlatformHeadlessInAppWebView.disposedart2wasm and dart2js compile errorsFixed: Web/WASM compilation broken by unconditional dart:io import in platform interface — replaced with conditional export if (dart.library.io) to co
dart:io import in platformif (dart.library.io) to compileHttpServer-based implementation on nativeFixed: iOS InAppBrowser crash after SPM migration — storyboard now loaded via Bundle.module instead of main bundle, resolving "Could not find a storyb
Bundle.module instead of main bundle, resolving "Could not find a storyboard
named 'WebView'" exception when opening the in-app browseronFlutterViewDetached() now properly
destroys the WebView (guarded against keepAlive)WebSettingsCompat.*
calls wrapped in try/catch for Huawei/Honor/OnePlus deviceswebViewWebContentProcessDidTerminate now auto-reloads after
500ms with isDisposed guardURLValidationManager wired into navigation flow — blocks
javascript:, vbscript:, jar, wyciwyg schemes at native levelInAppLocalhostServer race condition — added Completer gate to
prevent SocketException: Address already in use on rapid start/closePullToRefreshController — added _isDisposed guard with
MissingPluginException catchstopLoading() and script
removal in deinit/dispose across iOS, Android, and Dart layersaddJavaScriptHandler/removeJavaScriptHandler/
hasJavaScriptHandler via postMessage bridgeWebViewEnvironmentSettings.userDataFolder into
WebView2 initialization with writability verificationURLValidationManagerLock.synchronized() for
thread-safe concurrent accessFixed: iOS InAppBrowser crash after SPM migration — storyboard now loaded via Bundle.module instead of main bundle, resolving "Could not find a storyb
Bundle.module instead of main bundle, resolving "Could not find a storyboard
named 'WebView'" exception when opening the in-app browserany version constraints from dev/example pubspec filesFixed: Generator no longer produces InvalidType for fields referencing other generated types (e.g. PrintJobColorMode?) — the exchangeable_object_gener
InvalidType for fields referencing
other generated types (e.g. PrintJobColorMode?) — the exchangeable_object_generator
now falls back to AST source text when the analyzer can't resolve a typeSCREAMING_SNAKE_CASE
enum constants (e.g. UserScriptInjectionTime.atDocumentStart,
Sandbox.allowPopups, ConsoleMessageLevel.warning)exchangeable_enum_generator no longer attempts to generate getters
for Dart reserved words (default, switch, etc.) or @ExchangeableEnumCustomValue
fields with non-standard typesGENERATOR_NOTES.md documenting the console_message.g.dart
null-safety hand-edit and regeneration workflowFixed: macOS addJavaScriptHandler bridge now uses postMessage with a JSON string instead of structured clone — eliminates EXC_BAD_ACCESS crash in WebC
addJavaScriptHandler bridge now uses postMessage with a JSON
string instead of structured clone — eliminates EXC_BAD_ACCESS crash in
WebCore's wrap<DOMException> when passing large or complex data through
callHandlerevaluateJavascript now returns null to Dart instead of
throwing PlatformException when WKWebView returns nil (e.g., for
undefined, void, or Promise expressions)initialUserScripts parameter was silently ignored — WKWebView
now properly injects user scripts during initializationUserScriptInjectionTime.atDocumentStart and atDocumentEnd
convenience getters (in addition to existing AT_DOCUMENT_START / AT_DOCUMENT_END)Feature: Added addJavaScriptHandler / removeJavaScriptHandler / hasJavaScriptHandler support on macOS — the JavaScript bridge (window.flutter_inappweb
addJavaScriptHandler / removeJavaScriptHandler /
hasJavaScriptHandler support on macOS — the JavaScript bridge
(window.flutter_inappwebview.callHandler()) is now fully functional,
enabling bidirectional communication between Dart and JavaScript in
macOS WKWebViewConsoleMessage.fromMap crash when receiving null message
or messageLevel values from JavaScript — fixed at the Swift native layer
(coerces null to empty string), Dart macOS controller (null-safe constructor)
and shared ConsoleMessage.fromMap (null-safe defaults for all platforms)addJavaScriptHandler lifecycle)
and platform interface (ConsoleMessage.fromMap null safety)Fixed: macOS InAppWebView no longer returns WKWebView directly as the platform view — it now wraps it in a container NSView with proper autoresizing m
com.apple.security.network.client to both DebugProfile and Release
entitlements, granting WKWebView's networking process outgoing access so it
can load remote web pages under App SandboxFixed: macOS headless WebView now uses a dedicated off-screen NSWindow instead of attaching to the main window with alphaValue = 0.01 — eliminates pot
NSWindow instead
of attaching to the main window with alphaValue = 0.01 — eliminates potential
mouse event interception behind the Flutter surface while still providing the
view hierarchy WKWebView needs for rendering and JS executionFixed: iOS JavaScript handler error messages with newlines, backslashes, or carriage returns are now properly escaped via JSONSerialization instead of
JSONSerialization instead of
single-quote interpolation that produced SyntaxError: Unexpected EOF and
left JS promises pending forever — matches Android's JSONObject.quote()Fixed: Windows and Linux onWebViewCreated type mismatch — platform controllers (InAppWebViewWindowsController, LinuxInAppWebViewController) are now wr
onWebViewCreated type mismatch — platform controllers
(InAppWebViewWindowsController, LinuxInAppWebViewController) are now wrapped through
controllerFromPlatform to return proper InAppWebViewController instancesFixed: Android build failure — URLRequest constructor calls in InAppWebViewClient, InAppWebViewClientCompat, and InAppWebViewChromeClient now pass the
URLRequest constructor calls in InAppWebViewClient,
InAppWebViewClientCompat, and InAppWebViewChromeClient now pass the 5th timeoutInterval
parameter to match the updated constructor signatureFeature: Android URLRequest now supports timeoutInterval — the InAppWebView will stop loading after the specified interval, making rendered HTML avail
timeoutInterval — the InAppWebView will stop
loading after the specified interval, making rendered HTML available for extraction via
getHtml() even if the page hasn't fully loadedURLRequest native extension with full property support —
init(fromPluginMap:) and toMap() covering method, body, headers, cache policy,
network service type, timeout interval, and moreInAppWebView uses the new URLRequest(fromPluginMap:) extension
for cleaner URL loading in both initial load and loadUrl()prepare_for_publish.sh no longer attempts to update CocoaPods podspecs
(migrated to Swift Package Manager)fixed macos setting and removed pods from example
Remove debugPrint dealloc statements from Swift deinit blocks
Merge pull request #147 from arrrrny/fix/issue144-stuck-loading
Fixed: Linux build failure with WebKitGTK 2.52+ — migrated deprecated webkit_web_view_run_javascript → webkit_web_view_evaluate_javascript and replace…
} that closed the InAppWebView class prematurely,
leaving WKNavigationDelegate/WKUIDelegate methods outside the class scope. Also removed
dead result variable reference from shouldOverrideUrlLoading (#145)getDefaultProguardFile('proguard-android.txt')
with getDefaultProguardFile('proguard-android-optimize.txt') in android/build.gradle (#143)webkit_web_view_run_javascript → webkit_web_view_evaluate_javascript and replaced
removed synchronous webkit_web_view_get_snapshot with async version (#142)pluginClass from pubspec.yaml; the Windows plugin
is Dart-only (uses webview_windows package), so no native CMake project is needed (#142)INTERFACE to PUBLIC
so the plugin can find its own headers (#142)Fixed: iOS type 'int' is not a subtype of type 'WebAuthenticationSupport?' crash in getHtml()/getSettings() — InAppWebViewSettings.fromMap() now conve
type 'int' is not a subtype of type 'WebAuthenticationSupport?' crash in
getHtml()/getSettings() — InAppWebViewSettings.fromMap() now converts
webAuthenticationSupport via WebAuthenticationSupport.fromNativeValue() instead of
assigning the raw int value from the platform channel map-
fix: use KVC for webAuthenticationSupport to avoid SDK availability issue
Fixed: iOS Passkey/WebAuthn support — wired webAuthenticationSupport setting into native WKWebViewWebAuthenticationSupport.boundKeychainForPasskeys on
webAuthenticationSupport setting into
native WKWebViewWebAuthenticationSupport.boundKeychainForPasskeys on iOS 16.4+ (#131)isClosing guard and window?.delegate = nil before teardown (#87)layout() to explicitly sync frame from superview bounds (#93)shouldOverrideUrlLoading deadlock when adding custom headers — added
isNavigatingWithCustomAction flag to prevent re-entrant navigation callbacks (#132)InAppLocalhostServer fails after app resumes from background — added
AppLifecycleListener to close and reset server state on resume (#113)build_runner fails due to missing generators package — added as dev_dependency
in platform_interface pubspec (#139)WebAuthenticationSession now supports additionalHeaderFields for custom
HTTP headers — available on iOS 17.4+ (#100)Fixed: iOS onCreateWindow not respecting client return value — now returns nil when the client handles the window creation, preventing WebKit from cre
onCreateWindow not respecting client return value — now returns nil when
the client handles the window creation, preventing WebKit from creating an unused
window WebView (#107)InAppWebView.dispose() when KVO observers fire after disposal —
added isDisposed guard to observeValue, made dispose() idempotent with
isDisposed = true, added dispose() call in deinit (#120, #129)callAsyncJavaScript — added isDisposed guard to
observeValue, added optional chaining on channel?.invokeMethod calls (#126)Feature: WebAuthn (passkey) support — added webAuthenticationSupport setting + WebAuthenticationSupport enum for native passkey authentication in WebV
webAuthenticationSupport setting +
WebAuthenticationSupport enum for native passkey authentication in WebViews
(Upstream PR #2743 @susemeee)paymentRequestEnabled setting for
WebViewFeature.PAYMENT_REQUEST (Upstream PR #2722 @AzarouAmine)getAudioIntent() for
<input type="file" accept="audio/*"> support (Upstream PR #2823 @PrimozRatej)request.response instead of undefined blob
variable (Upstream PR #2099 @EArminjon)onCustomTabsConnected in
try-catch with onBrowserNotSupported callback (Upstream PR #2070 @luckyhandler).g.dart files after build_runner regenerationandroidx.webkit:webkit from 1.13.0 to 1.14.0generators dependency to platform_interface for proper code generationFixed: CVE-2020-6563 — sandbox file access protection in file picker (PR #2243 @AlexV525)
Prepare for publishing version 4.2.2
Prepare for publishing version 4.2.1
Prepare for publishing version 4.2.0
Prepare for publishing version 4.1.0
Prepare for publishing version 4.0.10
Prepare for publishing version 4.0.9
Prepare for publishing version 4.0.8
Fixed: GetHtml is tested on mac/web
Fix: updated missing linux package reference
Fix: updated missing linux package reference
Updated dependencies to use hosted references
Nothing published for this version
Fixed: EdgeInsets conversion issue on getHtml
Fixed: EdgeInsets conversion issue on getHtml
Fix: Added getHtml method for macos,windows,web,linux platforms
Updated dependencies to use hosted references
Prepare for publishing version 4.0.2
Nothing published for this version
Updated dependencies to use hosted references
Updated dependencies to use hosted references
Your coding agent can read these notes before it upgrades. Set up the MCP server →