When the page tries to leave https://localhost, through a link, a form or location.href, cordova-android checks two allow lists. <allow-navigation> names URLs the WebView itself may load; it is empty by default, so only the app's own code ever gets bridge access. <allow-intent> names URLs the app may hand to the system as an Android intent, which opens the browser, dialer or store. Anything else is blocked. Type two navigations into the WebView console, one at a time:
location.href = 'tel:5550100';
location.href = 'https://example.com/';Logcat (adb and Logcat) records what happened; emulator-5558 is just this emulator's serial:
adb -s emulator-5558 logcat -d -v brief | grep -E "CordovaWebViewImpl|START u0"W/CordovaWebViewImpl( 2512): Blocked (possibly sub-frame) navigation to non-allowed URL:
tel:5550100
D/CordovaWebViewImpl( 2512): showWebPage(https://example.com/, true, false, HashMap)
I/ActivityTaskManager( 648): START u0 {act=android.intent.action.VIEW
cat=[android.intent.category.BROWSABLE] dat=https://example.com/... xflg=0x4
cmp=com.android.chrome/com.google.android.apps.chrome.IntentDispatcher} ...tel: is on neither list, so the page stays put (<allow-intent href="tel:*" /> would open the dialer). The https: URL matched https://*/*, so Chrome 1 opened over the app, which is right for external links: the user's browser has their passwords, and your bridge never meets the foreign page. To show web content inside the app, use cordova-plugin-inappbrowser (Dialogs and InAppBrowser), never <allow-navigation href="*" />.