feat: disable specific built-in feature (or change it's config)
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 55/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- typescript
Direzione di ricerca
Start by tracing the builtinDevTools configuration and the configResolved hook to find where built-in features, especially terminal, are registered. Compare that path with terminalsVite({ shell: '/usr/bin/nologin' }); done means users can keep other built-in or package devtools enabled while excluding terminal through configuration.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Clear and concise description of the problem
Hello and thanks to everyone!
I would like to disable the terminal feature. As of today, the only way to do so is by set
devtools: {
builtinDevTools: false,
},
but this disables all the vite devtools entirely (even the ones from @vitejs/devtools-vite package).
I understand terminal is not active if no authentication is provided, but once it is (and I may want to open devtools for other reasons) I still feel like having it it's a security hole that must be closed. (such terminal is capable of doing too much thing, everything actually - install packages, sudo, reading envs and .bash_history as well as ssh into other machines).
I understand every hole I described can be done in many different way just with a bad package, but at least I would not like to have a terminal in my browser window and potentially accessibile in the network.
I tried to write a custom plugin that hook into the configResolved function to intercept the configuration, but I only managed to entirely disable the tools and I could not manage to reach the configuration.
Suggested solution
From a config perspective, it may be done in different ways, the one I prefer is something like
devtools: {
builtinDevTools: true,
excludeBuiltIn: ['terminal']
},
Alternative
Another way can be to override that specific plugin configuration
import { terminalsVite } from '@devframes/plugin-terminals/vite'
//...
plugins: [
...terminalsVite({
shell: '/usr/bin/nologin'
}),
]
Additional context
I never went that deep into vite: I never needed that (and that thanks to your awesome work, btw!), so I don't know that much of vite internal structure, but if the leading team decides this can be a feature, I can get my hands on it and try to prepare a PR (I feel like it's a small if somewhere, just I don't know where this "somewhere" is)
Validations
- Follow our Code of Conduct
- Read the Contributing Guide.
- Check that there isn't already an issue that request the same feature to avoid creating a duplicate.
- Lingua principale
- TypeScript
- Stelle
- 1.2k
- Fork
- 92
- Merge medio
- 1g 23h
- PR unite (30g)
- 18
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di vitejs/devtools
-
docs: manual client injection examples reference removed exportsForse già presa @MFA-G l’ha presa 4 giorni fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
vitejs/devtools#589 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
vitejs/devtools#261 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
pending triage
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
I maintainer di solito rispondono entro 1 giorno
-
pending triage
Difficoltà 3/5 1-2 giorni Idoneità per principianti 58/100
I maintainer di solito rispondono entro 1 giorno
-
Compare module sizes between build sessionsForse già presa @webfansplz l’ha presa 2 giorni fa. Apertaenhancement
vitejs/devtools#601 · 1 assegnatario ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di vitejs/devtools
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 67/100
ehmpathy/rhachet-roles-bhrain#586 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
OHDSI/Data2Evidence#3496 ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
apache/rocketmq-dashboard#5594 ·
I maintainer di solito rispondono entro 3 giorni
-
react-doctor severity:warning tech-debt
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
digidem/comapeo-cloud-app#418 ·
I maintainer di solito rispondono entro 1 giorno