From a0ff60250dc7eb9ddb99d005d6dee933fc91b689 Mon Sep 17 00:00:00 2001 From: abhigyanpatwari Date: Mon, 6 Apr 2026 11:11:06 +0530 Subject: [PATCH] fix(serve): use localhost as default host instead of :: Per reviewer feedback, bind to 'localhost' and let the OS decide IPv4 vs IPv6 resolution, rather than hardcoding '::' (dual-stack). Also updates the stale 127.0.0.1 comment in api.ts and removes a redundant ternary in the CORS origin callback. Co-Authored-By: Claude Sonnet 4.6 --- gitnexus/src/cli/serve.ts | 9 ++++----- gitnexus/src/server/api.ts | 4 ++-- 2 files changed, 6 insertions(+), 7 deletions(-) diff --git a/gitnexus/src/cli/serve.ts b/gitnexus/src/cli/serve.ts index 1c142a248..9f0379306 100644 --- a/gitnexus/src/cli/serve.ts +++ b/gitnexus/src/cli/serve.ts @@ -14,11 +14,10 @@ process.on('unhandledRejection', (reason: any) => { export const serveCommand = async (options?: { port?: string; host?: string }) => { const port = Number(options?.port ?? 4747); - // Default to '::' (dual-stack) so the server is reachable via both 127.0.0.1 - // and ::1. Browsers may resolve 'localhost' to either address; binding only - // to 127.0.0.1 breaks IPv6-first systems and causes spurious CORS errors - // when the hosted frontend at gitnexus.vercel.app connects to localhost. - const host = options?.host ?? '::'; + // Default to 'localhost' so the OS decides whether to bind to 127.0.0.1 or + // ::1 based on system configuration, avoiding spurious CORS errors when the + // hosted frontend at gitnexus.vercel.app connects to localhost. + const host = options?.host ?? 'localhost'; try { await createServer(port, host); diff --git a/gitnexus/src/server/api.ts b/gitnexus/src/server/api.ts index b71f55c22..8422af6ba 100644 --- a/gitnexus/src/server/api.ts +++ b/gitnexus/src/server/api.ts @@ -4,7 +4,7 @@ * REST API for browser-based clients to query the local .gitnexus/ index. * Also hosts the MCP server over StreamableHTTP for remote AI tool access. * - * Security: binds to 127.0.0.1 by default (use --host to override). + * Security: binds to localhost by default (use --host to override). * CORS is restricted to localhost, private/LAN networks, and the deployed site. */ @@ -282,7 +282,7 @@ export const createServer = async (port: number, host: string = '127.0.0.1') => app.use( cors({ origin: (origin, callback) => { - callback(null, isAllowedOrigin(origin) ? true : false); + callback(null, isAllowedOrigin(origin)); }, }), );