Skip to content
File

Blob: worker/dev/hosts.ts

typescript48 lines
1const loopbackHosts = ['localhost', '127.0.0.1', '[::1]'];
2 
3/** Explicit extra hostnames/IPs shared by Vite and the live API proxy. */
4export function developmentHosts(value = ''): string[] {
5 const additional = value
6 .split(',')
7 .map((host) => host.trim().toLowerCase())
8 .filter(Boolean);
9 for (const host of additional) {
10 let url: URL;
11 try {
12 url = new URL(`http://${host}`);
13 } catch {
14 throw new Error('RADIO_DEV_HOSTS must contain comma-separated hostnames or IPs.');
15 }
16 if (
17 host.startsWith('.') ||
18 host.includes('*') ||
19 url.port ||
20 url.host !== host ||
21 url.username ||
22 url.password ||
23 url.pathname !== '/' ||
24 url.search ||
25 url.hash
26 ) {
27 throw new Error(
28 'RADIO_DEV_HOSTS entries must be exact hostnames or IPs, without schemes, ports, paths, or wildcards.',
29 );
30 }
31 }
32 return [...new Set([...loopbackHosts, ...additional])];
33}
34 
35export function allowedProxyRequest(
36 host: string,
37 origin: string | undefined,
38 fetchSite: string | undefined,
39 allowed: readonly string[],
40): boolean {
41 const hostname = host.replace(/:\d+$/, '').toLowerCase();
42 return (
43 allowed.includes(hostname) &&
44 (!origin || origin === `http://${host}`) &&
45 fetchSite !== 'cross-site'
46 );
47}