{"record":{"id":"30a60b1d98c59b6f","repo":"tauri-apps/tauri","slug":"invalid-ipc-request-url","errorCode":null,"errorMessage":"invalid IPC request URL","messagePattern":"invalid IPC request URL","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"crates/tauri/src/ipc/protocol.rs","lineNumber":305,"sourceCode":"      );\n    }\n  }\n\n  let message = invoke_message.unwrap_or_else(|| {\n    #[cfg(feature = \"tracing\")]\n    let _span = tracing::trace_span!(\"ipc::request::deserialize\").entered();\n    serde_json::from_str::<Message>(request.body()).map_err(Into::into)\n  });\n\n  match message {\n    Ok(message) => {\n      let options = message.options.unwrap_or_default();\n\n      let request = InvokeRequest {\n        cmd: message.cmd,\n        callback: message.callback,\n        error: message.error,\n        url: Url::parse(&request.uri().to_string()).expect(\"invalid IPC request URL\"),\n        body: message.payload.into(),\n        headers: options.headers.0,\n        invoke_key: message.invoke_key,\n      };\n\n      #[cfg(feature = \"tracing\")]\n      let request_span = tracing::trace_span!(\"ipc::request::handle\", cmd = request.cmd);\n\n      webview.on_message(\n        request,\n        Box::new(move |webview, cmd, response, callback, error| {\n          use crate::ipc::Channel;\n\n          #[cfg(feature = \"tracing\")]\n          let _respond_span = tracing::trace_span!(\n            parent: &request_span,\n            \"ipc::request::respond\"\n          )","sourceCodeStart":287,"sourceCodeEnd":323,"githubUrl":"https://github.com/tauri-apps/tauri/blob/460ec35447493200d64290dd7f015d5a91d0fd58/crates/tauri/src/ipc/protocol.rs#L287-L323","documentation":"Tauri's IPC protocol handler parses the raw request URI of every incoming IPC message into a `Url`. If the URI cannot be parsed, this panic fires, meaning the IPC endpoint received a malformed request URL that should never happen from Tauri's own webview plumbing.","triggerScenarios":"An IPC request reaches the custom protocol handler with a URI that `Url::parse` rejects (malformed/empty scheme-relative URI), typically from a tampered or non-standard client posting directly to the IPC endpoint.","commonSituations":"Custom webview runtimes or tests issuing hand-crafted IPC requests; proxies or embedded HTTP stacks mangling the request URI; fuzzing/automated tools hitting the IPC handler.","solutions":["Verify the request is issued through the standard Tauri IPC invoke path, not a hand-built URL.","Check any proxy/custom protocol layer that rewrites request URIs and preserve a valid absolute origin URI.","Upgrade tauri — newer versions convert this to a proper error response instead of panicking.","If you reproduce it in tests, capture the offending URI and validate it with `Url::parse` before sending."],"exampleFix":"// before\nfetch(\"/__TAURI_INTERNALS__\" + badSuffix, ...)\n// after\nconst url = new URL(window.location.origin + \"/__TAURI_INTERNALS__\");\nfetch(url, { ...invokePayload })","handlingStrategy":"validation","validationCode":"function isValidIpcUrl(u) {\n  try { return new URL(u).origin !== 'null'; } catch { return false; }\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Only invoke IPC through window.__TAURI_INTERNALS__, never hand-built fetch URLs","Avoid proxies/rewriters on the tauri:// IPC endpoint","Keep tauri updated so panics become error responses"],"tags":["ipc","url","panic","protocol"],"backgroundTag":"invalid-url-format","analyzedSha":"460ec35447493200d64290dd7f015d5a91d0fd58","analyzedAt":"2026-09-18T23:55:51.277Z","contentChangedAt":"2026-09-18T23:55:51.277Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}