Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

feat: disable specific built-in feature (or change it's config)

Aperta
#597 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
55/100
Tipo di issue
Funzionalità
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
typescript
Ambito
devtools, security

Direzione di ricerca

Start by tracing the builtinDevTools configuration and the configResolved hook to find where built-in features, especially terminal, are registered. Compare that path with terminalsVite({ shell: '/usr/bin/nologin' }); done means users can keep other built-in or package devtools enabled while excluding terminal through configuration.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

enhancement
Clear and concise description of the problem

Hello and thanks to everyone!

I would like to disable the terminal feature. As of today, the only way to do so is by set

devtools: {
      builtinDevTools: false,
},

but this disables all the vite devtools entirely (even the ones from @vitejs/devtools-vite package).

I understand terminal is not active if no authentication is provided, but once it is (and I may want to open devtools for other reasons) I still feel like having it it's a security hole that must be closed. (such terminal is capable of doing too much thing, everything actually - install packages, sudo, reading envs and .bash_history as well as ssh into other machines).

I understand every hole I described can be done in many different way just with a bad package, but at least I would not like to have a terminal in my browser window and potentially accessibile in the network.

I tried to write a custom plugin that hook into the configResolved function to intercept the configuration, but I only managed to entirely disable the tools and I could not manage to reach the configuration.

Suggested solution

From a config perspective, it may be done in different ways, the one I prefer is something like

devtools: {
  builtinDevTools: true,
  excludeBuiltIn: ['terminal']
},
Alternative

Another way can be to override that specific plugin configuration

import { terminalsVite } from '@devframes/plugin-terminals/vite'
//...
plugins: [
  ...terminalsVite({
    shell: '/usr/bin/nologin'
  }),
]
Additional context

I never went that deep into vite: I never needed that (and that thanks to your awesome work, btw!), so I don't know that much of vite internal structure, but if the leading team decides this can be a feature, I can get my hands on it and try to prepare a PR (I feel like it's a small if somewhere, just I don't know where this "somewhere" is)

Validations
Lingua principale
TypeScript
Stelle
1.2k
Fork
92
Merge medio
1g 23h
PR unite (30g)
18

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di vitejs/devtools

Tutte le issue di vitejs/devtools

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.