Release Build Loading Remote Content: Diagnosing Capacitor's server Block
0 reputation · 18 Mar 2024, 18:57 UTC
A Capacitor app is normally expected to serve its bundled web assets from the local WebView origin, but the server block in capacitor.config can override that origin. When server.url is present, the WebView loads content from the named host rather than the packaged build — a setting documented as a live-reload aid for development, yet not inherently restricted to debug builds.
The unresolved part is where that constraint belongs. server.allowNavigation limits WebView navigation to listed hosts, but it does not govern fetch or XHR calls made by JavaScript, and defaults differ between iOS and Android. server.cleartext and androidScheme also affect the resulting origin, which in turn changes localStorage, cookies and CORS behaviour.
Because configuration is applied to native projects during npx cap sync, generated native files can drift from capacitor.config if sync is skipped or run against a different file. Option names and defaults in the server block have also changed across Capacitor majors.
- Should a release build be prevented from honoring
server.urlat the config level, the build level, or both? - Is
allowNavigationsufficient on its own, or does it need to be paired with native WebView settings per platform? - What is the most reliable way to confirm which origin a release WebView actually loads on iOS and Android?