fix(node): bind dashboard to loopback by default (HOST to opt into all-interfaces)
The Node proxy called server.listen(port) with no host, so it bound all interfaces (0.0.0.0/::) while the startup log printed http://127.0.0.1. The dashboard is unauthenticated and serves captured request context (/api/image-source returns the source text rendered into images) plus a compression kill switch, with access-control-allow-origin: *. On a shared network that context was readable by anyone who could reach the port. Bind to 127.0.0.1 by default; add a HOST env to explicitly opt into all-interfaces exposure (container/host-access use cases), with a startup warning when bound off-loopback. IPv6 handled: ::1/localhost count as loopback (no warning) and the startup URL is bracket-formatted. The one README client example that used localhost is pinned to 127.0.0.1 to match the IPv4 loopback default on IPv6-first hosts. Verified: default refuses off-host connections; HOST=0.0.0.0 restores the previous behavior + warns; HOST=::1 binds IPv6 loopback with a valid bracketed URL and no warning. typecheck + build pass.
S
Sutha Kamal committed
75263d64c3eacf32836bdd0903cd0e360d4e9aaa
Parent: ea7d526
Committed by Steven <25894545+teamchong@users.noreply.github.com>
on 7/4/2026, 1:46:55 AM