Repository navigation
fix(http): stop SSR fault rules once their devtools server closes - #219
Conversation
Server rules live on globalThis so they survive a Vite restart, but if a config edit removed the plugin the disposed hub left them applying to every SSR request. The interceptor now applies server rules only while a devtools server owns the registry, so a normal restart keeps them and a closed server stops them. Refs pangular-inspector#69
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe HTTP interceptor now reads server-side rules only when the HTTP registry has a record callback. New tests cover server-rule behavior during server restarts and closure. The SSR HTTP documentation now states when those rules apply. ChangesSSR HTTP rule lifecycle
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to SSR fault rules should remain active through a server restart and stop after the owning server closes. No actionable merge-blocking risk is identified. Security Architecture ReviewSecurity architecture risk: ⚪ Minimal · up to The change prevents stale SSR fault rules from affecting new requests after the owning development server closes, while preserving normal restart behavior. No material security risk was found in this scoped change. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
What and why
Most of #69 was fixed by #184: turning the http inspector off clears stored client rules, setup clears server rules when http or its actions are off, and the panel is seeded with the registry's rules after a restart.
One server gap was left. Rules live on
globalThisso they survive a Vite restart, but if a config edit removes the plugin, the old hub is disposed, no new setup runs, and the rules kept failing SSR requests throughwithPangular(). Clearing them indisposeisn't safe, because Vite creates the new server before closing the old one.http.ts: SSR rules apply only while a devtools server owns the registry (registry.record), so a normal restart keeps them and a closed server stops them.inspectors/ssr-http.md: says SSR rules stop when the devtools server closes.Refs #69
How it was verified
pnpm commit:check,pnpm format:check,pnpm typecheck,pnpm skills:checkpnpm test:devtools(1168) andpnpm test:panelpnpm docs:build,pnpm test:axevite-restart.test.ts: rules keep applying when a new server takes over in the same process, and stop once the owning server closes (fails without the fix)/dashboardandwithPangular()), with a server rule returning 503 for/api/v1/orders:Removing the plugin pauses server rules rather than deleting them: put the plugin back and the rule applies again, and the panel lists it.
Notes for reviewers
Still open in #69: after turning the http inspector off and reloading the same tab, requests made before the overlay connects still use the rules saved in
sessionStorage. Options are to hold matching requests until the overlay connects, inject the http flag into the page before bootstrap, or stop saving client rules. That needs a decision, so it's left out here.Summary by CodeRabbit