feat: disable specific built-in feature (or change it's config)
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 55/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- typescript
Research direction
Start by tracing the builtinDevTools configuration and the configResolved hook to find where built-in features, especially terminal, are registered. Compare that path with terminalsVite({ shell: '/usr/bin/nologin' }); done means users can keep other built-in or package devtools enabled while excluding terminal through configuration.
Written by the indexing model from the issue text.
Description
Clear and concise description of the problem
Hello and thanks to everyone!
I would like to disable the terminal feature. As of today, the only way to do so is by set
devtools: {
builtinDevTools: false,
},
but this disables all the vite devtools entirely (even the ones from @vitejs/devtools-vite package).
I understand terminal is not active if no authentication is provided, but once it is (and I may want to open devtools for other reasons) I still feel like having it it's a security hole that must be closed. (such terminal is capable of doing too much thing, everything actually - install packages, sudo, reading envs and .bash_history as well as ssh into other machines).
I understand every hole I described can be done in many different way just with a bad package, but at least I would not like to have a terminal in my browser window and potentially accessibile in the network.
I tried to write a custom plugin that hook into the configResolved function to intercept the configuration, but I only managed to entirely disable the tools and I could not manage to reach the configuration.
Suggested solution
From a config perspective, it may be done in different ways, the one I prefer is something like
devtools: {
builtinDevTools: true,
excludeBuiltIn: ['terminal']
},
Alternative
Another way can be to override that specific plugin configuration
import { terminalsVite } from '@devframes/plugin-terminals/vite'
//...
plugins: [
...terminalsVite({
shell: '/usr/bin/nologin'
}),
]
Additional context
I never went that deep into vite: I never needed that (and that thanks to your awesome work, btw!), so I don't know that much of vite internal structure, but if the leading team decides this can be a feature, I can get my hands on it and try to prepare a PR (I feel like it's a small if somewhere, just I don't know where this "somewhere" is)
Validations
- Follow our Code of Conduct
- Read the Contributing Guide.
- Check that there isn't already an issue that request the same feature to avoid creating a duplicate.
- Dominant language
- TypeScript
- Stars
- 1.2k
- Forks
- 92
- Avg merge
- 1d 15h
- Merged PRs (30d)
- 22
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from vitejs/devtools
-
docs: manual client injection examples reference removed exportsPossibly taken @MFA-G claimed this 3 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
vitejs/devtools#589 · 1 comment ·
Maintainers usually reply within 1 day
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
vitejs/devtools#261 · 1 comment ·
Maintainers usually reply within 1 day
-
Compare module sizes between build sessionsPossibly taken @webfansplz claimed this 1 day ago. Openenhancement
vitejs/devtools#601 · 1 assignee ·
Maintainers usually reply within 1 day
-
feat(oxc): add rule timing stats to the lint inspectorPossibly taken @yuyinws claimed this 14 days ago. Openenhancement
vitejs/devtools#584 · 1 assignee ·
Maintainers usually reply within 1 day
-
pending triage
Difficulty 3/5 1-2 days Newbie friendliness 58/100
Maintainers usually reply within 1 day
Similar issues
-
needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
LucasSantana-Dev/Lucky#2637 ·
Maintainers usually reply within 1 day
-
Show the error reference on the error pagePossibly taken A pull request linked to this issue is open or already merged. Openenhancement
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
tomjn/coilbox-hub#454 ·
Maintainers usually reply within 1 day
-
frontend
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
icssc/peterportal-client#1224 · 1 comment ·
-
testplan-item
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Maintainers usually reply within 1 day
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Maintainers usually reply within 1 day