fix(serve): use localhost as default host instead of ::

Per reviewer feedback, bind to 'localhost' and let the OS decide
IPv4 vs IPv6 resolution, rather than hardcoding '::' (dual-stack).

Also updates the stale 127.0.0.1 comment in api.ts and removes a
redundant ternary in the CORS origin callback.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
abhigyanpatwari 2026-04-06 11:11:06 +05:30
parent 6b86b10a97
commit a0ff60250d
2 changed files with 6 additions and 7 deletions

View file

@ -14,11 +14,10 @@ process.on('unhandledRejection', (reason: any) => {
export const serveCommand = async (options?: { port?: string; host?: string }) => {
const port = Number(options?.port ?? 4747);
// Default to '::' (dual-stack) so the server is reachable via both 127.0.0.1
// and ::1. Browsers may resolve 'localhost' to either address; binding only
// to 127.0.0.1 breaks IPv6-first systems and causes spurious CORS errors
// when the hosted frontend at gitnexus.vercel.app connects to localhost.
const host = options?.host ?? '::';
// Default to 'localhost' so the OS decides whether to bind to 127.0.0.1 or
// ::1 based on system configuration, avoiding spurious CORS errors when the
// hosted frontend at gitnexus.vercel.app connects to localhost.
const host = options?.host ?? 'localhost';
try {
await createServer(port, host);

View file

@ -4,7 +4,7 @@
* REST API for browser-based clients to query the local .gitnexus/ index.
* Also hosts the MCP server over StreamableHTTP for remote AI tool access.
*
* Security: binds to 127.0.0.1 by default (use --host to override).
* Security: binds to localhost by default (use --host to override).
* CORS is restricted to localhost, private/LAN networks, and the deployed site.
*/
@ -282,7 +282,7 @@ export const createServer = async (port: number, host: string = '127.0.0.1') =>
app.use(
cors({
origin: (origin, callback) => {
callback(null, isAllowedOrigin(origin) ? true : false);
callback(null, isAllowedOrigin(origin));
},
}),
);