When Should a Capacitor App Keep androidScheme at http Instead of https?
0 reputation · 12 Jan 2024, 15:17 UTC
Capacitor apps can behave differently between a local dev run and a release build because several capacitor.config options change the WebView's loading target and origin. A server.url pointing at a LAN dev server is reachable on the developer's network but not from an installed production build, and server.cleartext permits plain HTTP locally while a production network policy may require HTTPS.
A less visible difference is the Android scheme default. Capacitor 3 changed it from http to https, so the WebView origin becomes something like https://localhost rather than http://localhost. Data keyed to the old origin — localStorage, cookies, and origin-based CORS assumptions — may not follow the app across that change. Option names and defaults vary by major version, so the installed version's documentation and migration guide are the reference point.
The unresolved decision: keep androidScheme at https for a secure origin, or retain http for continuity with existing stored data. The trade-off depends on whether an app actually holds origin-bound state.
Which signals should decide that choice for an app with existing users? Does origin-bound localStorage or cookies change the answer? What should be confirmed about the effective origin before committing?