Repository navigation
Expand file tree
/
Copy pathvite.config.ts
More file actions
44 lines (39 loc) · 1.89 KB
/
Copy pathvite.config.ts
File metadata and controls
44 lines (39 loc) · 1.89 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
import { sveltekit } from '@sveltejs/kit/vite';
import { defineConfig, type Connect, type Plugin } from 'vite';
import {
get_host_header_hostname,
is_local_hostname,
local_host_refusal
} from './src/lib/utils/local_hosts';
// `vite dev` and `vite preview` (the Docker image) serve local Syntax Auth. They answer health
// checks and built files before src/hooks.server.ts runs, and Vite's own host check lets through
// any IP address and *.localhost, so this refuses every other host first, with the hook's text.
// Deploys run on Cloudflare Workers without Vite; the hook still checks every other request.
function refuse_other_hosts(): Plugin {
const refuse: Connect.NextHandleFunction = (request, response, next) => {
const hostname = get_host_header_hostname(request.headers.host);
if (is_local_hostname(hostname)) return next();
response.writeHead(403, { 'content-type': 'text/plain; charset=utf-8' });
response.end(local_host_refusal(hostname, `http://localhost:${request.socket.localPort}`));
};
// Vite adds its host check before any plugin's middleware, so this goes in front of it.
const add_first = (middlewares: Connect.Server) =>
middlewares.stack.unshift({ route: '', handle: refuse });
return {
name: 'syntax-auth-refuse-other-hosts',
configureServer: (server) => void add_first(server.middlewares),
configurePreviewServer: (server) => void add_first(server.middlewares)
};
}
export default defineConfig({
// Consumer apps point at this exact port; keep it in sync with packages/auth-local.
server: {
// IPv4 like the Docker container, so the two can never both hold the port.
host: '127.0.0.1',
port: 37960,
strictPort: true
},
// Syntax Auth is the shared local Syntax Auth itself, so it needs neither the container nor the
// development proxy from packages/auth-local; scripts/local_server.js stands in for the container.
plugins: [refuse_other_hosts(), sveltekit()]
});