{"_id":"@cordova-ohos/cordova-plugin-whitelist","_rev":"3-b72b9ea61d307701f67c2b020ef91909","name":"@cordova-ohos/cordova-plugin-whitelist","dist-tags":{"latest":"1.3.6"},"versions":{"1.3.5":{"name":"@cordova-ohos/cordova-plugin-whitelist","version":"1.3.5","keywords":["cordova","whitelist","ecosystem:cordova","cordova-openharmony"],"author":{"name":"Huawei Device, Inc. Ltd. and","email":"马弓手"},"license":"Apache-2.0","_id":"@cordova-ohos/cordova-plugin-whitelist@1.3.5","maintainers":[{"name":"luqi_tan","email":"295099422@qq.com"},{"name":"wanpengsz","email":"wanpengsz@163.com"},{"name":"xkh111","email":"xukaihui11@163.com"}],"bugs":{"url":"https://gitcode.com/OpenHarmony-Cordova/cordova-plugin-whitelist/issues"},"dist":{"shasum":"cba843765f10d811abb4d9173f3da7bfbb371e40","tarball":"https://registry.npmjs.org/@cordova-ohos/cordova-plugin-whitelist/-/cordova-plugin-whitelist-1.3.5.tgz","fileCount":8,"integrity":"sha512-zkG+FUyVAe2GtZpRrtd3ozkwmw+h2C8CurIOCh4cD4jE89hGaOU7Q+0vvdsp4dmu1LxQg3rcYv/AInhmdiLpMA==","signatures":[{"sig":"MEUCICWld00TKdMl7dUvA1oTDmJsg5zrpjABwN2iLDMKx90yAiEAjz0mN8IVCtOSQS03EpzmKyiFT2odMx8+i8//HcMwvjI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":34202},"cordova":{"id":"cordova-plugin-whitelist","platforms":["ohos"]},"engines":{"cordovaDependencies":{"1.3.5":{"hcordova":">=1.0.0","@cordova-ohos/ohos":">=2.0.0"}}},"gitHead":"6b208ca37c1ad8480e932c1fe71b85ee9f3ba6ab","_npmUser":{"name":"luqi_tan","email":"295099422@qq.com"},"repository":{"url":"gitcode:OpenHarmony-Cordova/cordova-plugin-whitelist","type":"git"},"_npmVersion":"10.5.1","description":"Cordova whitelist Plugin","directories":{},"_nodeVersion":"22.0.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/cordova-plugin-whitelist_1.3.5_1774228373570_0.7842773684933566","host":"s3://npm-registry-packages-npm-production"}},"1.3.6":{"name":"@cordova-ohos/cordova-plugin-whitelist","version":"1.3.6","description":"Cordova White List Plugin","cordova":{"id":"cordova-plugin-whitelist","platforms":["ohos"]},"repository":{"type":"git","url":"gitcode:CPF-Cordova/cordova-plugin-whitelist"},"bugs":{"url":"https://gitcode.com/CPF-Cordova/cordova-plugin-whitelist/issues"},"keywords":["cordova","whitelist","ecosystem:cordova","cordova-openharmony"],"engines":{"cordovaDependencies":{"1.3.6":{"@cordova-ohos/ohos":">=2.0.0","hcordova":">=1.0.0"}}},"author":{"name":"Huawei Device, Inc. Ltd. and","email":"马弓手"},"license":"Apache-2.0","_id":"@cordova-ohos/cordova-plugin-whitelist@1.3.6","gitHead":"be8f62e6176aad637993a94d2a22abdc4f59e5f7","_nodeVersion":"22.0.0","_npmVersion":"10.5.1","dist":{"integrity":"sha512-RGQNuAf36MXmUyu+Zxr2YfxYBhmA+EqAdH3RxcN5f5uggVlQgM0hdvk/OcjmPRyUR+7fWHvNfIn6CU4zd8f6ig==","shasum":"56e0a1efa1b113c0b0663a9c90547952e34bdc73","tarball":"https://registry.npmjs.org/@cordova-ohos/cordova-plugin-whitelist/-/cordova-plugin-whitelist-1.3.6.tgz","fileCount":9,"unpackedSize":48624,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIFW0s+emBE5KuzCKI3dVSWhWf72EhwIVH7809eiJ78JcAiBeJ8abr/pufiDovpt0sjmwLVrvHvsjM+vqviAtLi4dqg=="}]},"_npmUser":{"name":"luqi_tan","email":"295099422@qq.com"},"directories":{},"maintainers":[{"name":"luqi_tan","email":"295099422@qq.com"},{"name":"wanpengsz","email":"wanpengsz@163.com"},{"name":"xkh111","email":"xukaihui11@163.com"},{"name":"hcordova","email":"chenlihuiabc@163.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/cordova-plugin-whitelist_1.3.6_1785143765173_0.03983329957205006"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-23T01:12:53.460Z","modified":"2026-07-27T09:16:05.635Z","1.3.5":"2026-03-23T01:12:53.710Z","1.3.6":"2026-07-27T09:16:05.312Z"},"bugs":{"url":"https://gitcode.com/CPF-Cordova/cordova-plugin-whitelist/issues"},"author":{"name":"Huawei Device, Inc. Ltd. and","email":"马弓手"},"license":"Apache-2.0","keywords":["cordova","whitelist","ecosystem:cordova","cordova-openharmony"],"repository":{"type":"git","url":"gitcode:CPF-Cordova/cordova-plugin-whitelist"},"description":"Cordova White List Plugin","maintainers":[{"name":"luqi_tan","email":"295099422@qq.com"},{"name":"wanpengsz","email":"wanpengsz@163.com"},{"name":"xkh111","email":"xukaihui11@163.com"},{"name":"hcordova","email":"chenlihuiabc@163.com"}],"readme":"# <center>cordova-plugin-whitelist</center>\r\n\r\n[![zh-CN](https://img.shields.io/badge/lang-中文-blue.svg)](README.md)\r\n[![en](https://img.shields.io/badge/lang-English-blue.svg)](README.en.md)\r\n\r\n本项目基于 [cordova-plugin-whitelist@1.3.5](https://npmjs.com/package/cordova-plugin-whitelist/v/1.3.5) 开发，本文档重点阐述其在 OpenHarmony（OHOS）系统中的具体应用。\r\n\r\n- [cordova-plugin-whitelist](#cordova-plugin-whitelist)\r\n  - [简介](#简介)\r\n  - [支持平台](#支持平台)\r\n  - [下载安装](#下载安装)\r\n    - [从 npm 安装（推荐）](#从-npm-安装推荐)\r\n    - [从 GitCode 仓库安装](#从-gitcode-仓库安装)\r\n    - [离线安装（本地包）](#离线安装本地包)\r\n    - [安装后验证](#安装后验证)\r\n    - [卸载](#卸载)\r\n  - [约束与限制](#约束与限制)\r\n    - [兼容性](#兼容性)\r\n  - [使用示例](#使用示例)\r\n    - [1. 网络请求白名单配置示例](#1-网络请求白名单配置示例)\r\n    - [2. 导航白名单配置示例](#2-导航白名单配置示例)\r\n  - [使用说明](#使用说明)\r\n    - [核心功能说明](#核心功能说明)\r\n    - [详细配置说明](#详细配置说明)\r\n      - [1. 网络请求白名单（ 标签）](#1-网络请求白名单-标签)\r\n      - [2. 导航白名单（ 标签）](#2-导航白名单-标签)\r\n  - [目录结构](#目录结构)\r\n  - [贡献代码](#贡献代码)\r\n  - [许可证](#许可证)\r\n  - [官方资源](#官方资源)\r\n\r\n\r\n## 简介\r\n\r\ncordova-plugin-whitelist 是 Cordova 官方核心插件，用于控制应用对外部资源的访问权限，包括网络请求、外部应用跳转和 WebView 导航。它通过白名单机制有效防范跨站请求伪造（CSRF）、恶意 URL 跳转等安全风险，是保障 Cordova 应用安全性的关键组件。\r\n\r\n**重要提示：** 该插件在 Cordova 10.0 开始，已在 Android 和 iOS 中废弃，插件已失效，因此该插件也在 OHOS 系统中功能失效，但保留插件接口，主要兼容老版本的 Android 或 iOS 项目移植使用，如果您是新项目，无需安装该插件。\r\n\r\n## 支持平台\r\n\r\n- **Android**：API 19 及以上（Android 4.4+）\r\n\r\n- **iOS**：10.0 及以上\r\n\r\n- **OHOS**：5.0+\r\n\r\n## 下载安装\r\n\r\n### 从 npm 安装（推荐）\r\n\r\n```bash\r\n# 安装 hcordova\r\nnpm install -g hcordova\r\n\r\n# 全平台安装插件\r\nhcordova plugin add cordova-plugin-whitelist\r\n\r\n# 指定 OHOS 平台\r\nhcordova plugin add cordova-plugin-whitelist --platform ohos\r\n\r\n# 安装指定版本（OHOS 平台）\r\nhcordova plugin add cordova-plugin-whitelist@1.0.0 --platform ohos\r\n```\r\n\r\n### 从 GitCode 仓库安装\r\n\r\n```bash\r\n# 仅安装到 OHOS 平台（开发版）\r\nhcordova plugin add https://gitcode.com/CPF-Cordova/cordova-plugin-whitelist.git --platform ohos\r\n\r\n# 指定标签/分支安装\r\nhcordova plugin add https://gitcode.com/CPF-Cordova/cordova-plugin-whitelist.git@develop --platform ohos\r\n```\r\n\r\n### 离线安装（本地包）\r\n\r\n适用于无网络环境，先下载插件包到本地，再执行离线安装：\r\n\r\n```bash\r\n# 下载插件包到本地（示例路径：~/Downloads/cordova-plugin-whitelist）\r\n# 执行离线安装\r\nhcordova plugin add ~/Downloads/cordova-plugin-whitelist --platform ohos\r\n```\r\n\r\n### 安装后验证\r\n\r\n安装完成后，可通过以下命令验证插件是否成功添加到项目中：\r\n\r\n```bash\r\n# 查看已安装的插件列表，若包含本插件 ID 则表示插件已成功安装\r\nhcordova plugin list\r\n```\r\n\r\n### 卸载\r\n\r\n```bash\r\n# Cordova CLI 全平台卸载\r\nhcordova plugin remove cordova-plugin-whitelist \r\n\r\n# 指定平台卸载\r\nhcordova plugin remove cordova-plugin-whitelist --platform ohos\r\n```\r\n## 约束与限制\r\n### 兼容性\r\n\r\n支持：\r\n\r\n| 项目 | 版本/信息 |\r\n|-----|--------|\r\n| SDK | API12+ |\r\n| IDE | DevEco Studio: 5.0+ |\r\n| ROM | 5.1+ |\r\n| Emulator | OpenHarmony 6.0+ |\r\n\r\n在以下版本中已测试通过：\r\n\r\n| 项目 | 版本/信息 |\r\n|-----|--------|\r\n| @cordova-ohos/ohos | 14.0.1-ohos-14.0.1 |\r\n| SDK | 5.0.0(12) |\r\n| IDE | DevEco Studio: 6.0.13.200 |\r\n| ROM | 5.1.0.120 SP3 |\r\n| Emulator | OpenHarmony 6.0.1(21) |\r\n\r\n## 使用示例\r\n\r\n### 1. 网络请求白名单配置示例\r\n\r\n控制应用所有网络资源加载，支持通配符、协议限制和子域名匹配，配置在项目根目录的 config.xml 中。\r\n\r\n```xml\r\n<!-- 推荐配置 -->\r\n<access origin=\"*\" />\r\n\r\n<!-- 允许访问指定域名 -->\r\n<access origin=\"https://api.example.com\" />\r\n\r\n<!-- 允许访问指定域名及其所有子域名 -->\r\n<access origin=\"https://*.example.com\" />\r\n\r\n<!-- 允许访问所有 HTTPS/WSS 安全域名（推荐） -->\r\n<access origin=\"https://*\" />\r\n\r\n<!-- 允许访问指定端口（需完整指定协议+域名+端口） -->\r\n<access origin=\"https://api.example.com:8443\" />\r\n```\r\n\r\n### 2. 导航白名单配置示例\r\n\r\n控制 WebView 可直接导航的 URL，未配置的 URL 会触发系统浏览器打开（或被拦截），配置在项目根目录的 config.xml 中。\r\n\r\n```xml\r\n<!-- 推荐配置 -->\r\n<allow-navigation href=\"*\" />\r\n\r\n<!-- 允许导航到应用主域名下所有路径 -->\r\n<allow-navigation href=\"https://app.example.com/*\" />\r\n\r\n<!-- 允许导航到子域名 -->\r\n<allow-navigation href=\"https://*.app.example.com\" />\r\n```\r\n\r\n## 使用说明\r\n\r\n### 核心功能说明\r\n\r\n插件通过三类白名单规则实现精细化权限控制，所有配置均在项目根目录的 config.xml 中完成\r\n\r\n| 白名单类型 | 控制范围 | 配置标签 | 适用平台 |\r\n|---|---|---|---|\r\n| 网络请求白名单 | 控制应用发起的 XMLHttpRequest、WebSocket、图片/脚本/字体等资源加载请求 | <access> | 所有支持平台 |\r\n| 导航白名单 | 控制应用内 WebView 可直接导航到的外部 URL（不跳转外部浏览器） | <allow-navigation> | 所有支持平台 |\r\n### 详细配置说明\r\n\r\n#### 1. 网络请求白名单（<access> 标签）\r\n\r\n控制应用所有网络资源加载，支持通配符、协议限制和子域名匹配，具体配置示例见「使用示例」章节。\r\n\r\n#### 2. 导航白名单（<allow-navigation> 标签）\r\n\r\n控制 WebView 可直接导航的 URL，未配置的 URL 会触发系统浏览器打开（或被拦截），具体配置示例见「使用示例」章节。\r\n\r\n## 目录结构\r\n\r\n```\r\ncordova-plugin-whitelist             # [根目录] 网络白名单安全策略插件项目根目录\r\n├── src                              # [源码目录] 存放原生平台代码\r\n│   └── main                         # [主目录] 主代码目录\r\n│       └── cpp                      # [C++ 目录] C++ 原生代码目录\r\n│           └── Whitelist            # [C++ 模块] 白名单功能 C++ 模块文件夹\r\n│               ├── Whitelist.h      # [C++ 声明] 白名单规则匹配逻辑的头文件\r\n│               ├── WhitelistPlugin.cpp # [C++ 实现] 插件主逻辑，负责读取配置并拦截网络请求\r\n│               └── WhitelistPlugin.h   # [C++ 声明] 插件接口的头文件\r\n├── .gitignore                       # [配置] Git 版本控制忽略文件配置\r\n├── LICENSE                          # [文本] 开源许可证文件\r\n├── OAT.xml                          # [配置] 门禁配置文件\r\n├── package.json                     # [配置] npm 包描述文件，包含插件版本、依赖等信息\r\n├── plugin.xml                       # [配置] Cordova 插件核心配置文件，定义插件 ID、文件映射等\r\n└── README.md                        # [文档] 项目说明文档，介绍如何安装和使用白名单插件\r\n```\r\n\r\n## 贡献代码\r\n\r\n使用过程中发现任何问题都可以提 [Issue](https://gitcode.com/CPF-Cordova/cordova-plugin-whitelist/issues) ，当然也非常欢迎发 [PR](https://gitcode.com/CPF-Cordova/cordova-plugin-whitelist/pulls) 共建。\r\n\r\n## 许可证\r\n\r\n本插件基于 **Apache License 2.0** 开源，详见 [LICENSE](LICENSE) 文件。\r\n\r\n## 官方资源\r\n\r\n- **OHOS**：[https://gitcode.com/CPF-Cordova/cordova-plugin-whitelist](https://gitcode.com/CPF-Cordova/cordova-plugin-whitelist)\r\n\r\n- **Android、iOS 插件说明**：[https://www.npmjs.com/package/cordova-plugin-whitelist](https://www.npmjs.com/package/cordova-plugin-whitelist)\r\n","readmeFilename":"README.md"}