Security News
pnpm 10.0.0 Blocks Lifecycle Scripts by Default
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
@1j01/live-server
Advanced tools
live-server fork that adds Content-Security-Policy (CSP) support (a simple development http server with live reload capability)
This fork adds support for Content Security Policy (CSP).
If the Content-Security-Policy header is set in a <meta>
tag, the server will modify it to allow loading the script that live-server injects, as well as the web socket connection it uses for stylesheet updates.
Example:
<meta http-equiv="Content-Security-Policy" content="default-src 'none'; style-src 'self'">
becomes:
<meta http-equiv="Content-Security-Policy" content="default-src 'nonce-53c70de06ed2ca9452aa092bdfd6d0fc' ; connect-src ws: wss: http: https: ; style-src 'self'">
It's not perfect, there's plenty of edge cases to consider, but I tried to make it leave your CSP reasonably in tact.
It adds a nonce for the injected script tag, to script-src-elem
directive if it exists, otherwise script-src
, or default-src
if neither exist.
(If all three do not exist, it doesn't need to be added, but the CSP is insecure, allowing arbitrary inline scripts.)
If the connect-src
directive has to be added, it inherits from default-src
so that it won't confusingly restrict the connect-src
. It should only extend what's allowed.
This is a little development server with live reload capability. Use it for hacking your HTML/JavaScript/CSS files, but not for deploying the final site.
There are two reasons for using this:
file://
protocol due to security restrictions, i.e. you need a server if your site fetches content through JavaScript.You don't need to install any browser plugins or manually add code snippets to your pages for the reload functionality to work, see "How it works" section below for more information. If you don't want/need the live reload, you should probably use something even simpler, like the following Python-based one-liner:
python -m SimpleHTTPServer
You need node.js and npm. You should probably install this globally.
Npm way
npm install -g @1j01/live-server
Manual way
git clone https://github.com/1j01/live-server
cd live-server
npm install # Local dependencies if you want to hack
npm install -g # Install globally
Issue the command live-server
in your project's directory. Alternatively you can add the path to serve as a command line parameter.
This will automatically launch the default browser. When you make a change to any file, the browser will reload the page - unless it was a CSS file in which case the changes are applied without a reload.
Command line parameters:
--port=NUMBER
- select port to use, default: PORT env var or 8080--host=ADDRESS
- select host address to bind to, default: IP env var or 0.0.0.0 ("any address")--no-browser
- suppress automatic web browser launching--browser=BROWSER
- specify browser to use instead of system default--quiet | -q
- suppress logging--verbose | -V
- more logging (logs all requests, shows all listening IPv4 interfaces, etc.)--open=PATH
- launch browser to PATH instead of server root--watch=PATH
- comma-separated string of paths to exclusively watch for changes (default: watch everything)--ignore=PATH
- comma-separated string of paths to ignore (anymatch-compatible definition)--ignorePattern=REGEXP
- Regular expression of files to ignore (ie .*\.jade
) (DEPRECATED in favor of --ignore
)--no-css-inject
- reload page on CSS change, rather than injecting changed CSS--middleware=PATH
- path to .js file exporting a middleware function to add; can be a name without path nor extension to reference bundled middlewares in middleware
folder--entry-file=PATH
- serve this file (server root relative) in place of missing files (useful for single page apps)--mount=ROUTE:PATH
- serve the paths contents under the defined route (multiple definitions possible)--spa
- translate requests from /abc to /#/abc (handy for Single Page Apps)--wait=MILLISECONDS
- (default 100ms) wait for all changes, before reloading--htpasswd=PATH
- Enables http-auth expecting htpasswd file located at PATH--cors
- Enables CORS for any origin (reflects request origin, requests with credentials are supported)--https=PATH
- PATH to a HTTPS configuration module--https-module=MODULE_NAME
- Custom HTTPS module (e.g. spdy
)--proxy=ROUTE:URL
- proxy all requests for ROUTE to URL--help | -h
- display terse usage hint and exit--version | -v
- display version and exitDefault options:
If a file ~/.live-server.json
exists it will be loaded and used as default options for live-server on the command line. See "Usage from node" for option names.
var liveServer = require("@1j01/live-server");
var params = {
port: 8181, // Set the server port. Defaults to 8080.
host: "0.0.0.0", // Set the address to bind to. Defaults to 0.0.0.0 or process.env.IP.
root: "/public", // Set root directory that's being served. Defaults to cwd.
open: false, // When false, it won't load your browser by default.
ignore: 'scss,my/templates', // comma-separated string for paths to ignore
file: "index.html", // When set, serve this file (server root relative) for every 404 (useful for single-page applications)
wait: 1000, // Waits for all changes, before reloading. Defaults to 0 sec.
mount: [['/components', './node_modules']], // Mount a directory to a route.
logLevel: 2, // 0 = errors only, 1 = some, 2 = lots
middleware: [function(req, res, next) { next(); }] // Takes an array of Connect-compatible middleware that are injected into the server middleware stack
};
liveServer.start(params);
In order to enable HTTPS support, you'll need to create a configuration module.
The module must export an object that will be used to configure a HTTPS server.
The keys are the same as the keys in options
for tls.createServer.
For example:
var fs = require("fs");
module.exports = {
cert: fs.readFileSync(__dirname + "/server.cert"),
key: fs.readFileSync(__dirname + "/server.key"),
passphrase: "12345"
};
If using the node API, you can also directly pass a configuration object instead of a path to the module.
To get HTTP/2 support one can provide a custom HTTPS module via --https-module
CLI parameter (httpsModule
option for Node.js script). Be sure to install the module first.
HTTP/2 unencrypted mode is not supported by browsers, thus not supported by live-server
. See this question and can I use page on HTTP/2 for more details.
For example from CLI(bash):
live-server \
--https=path/to/https.conf.js \
--https-module=spdy \
my-app-folder/
--wait=MS
option. Where MS
is time in milliseconds to wait before issuing a reload.The server is a simple node app that serves the working directory and its subdirectories. It also watches the files for changes and when that happens, it sends a message through a web socket connection to the browser instructing it to reload. In order for the client side to support this, the server injects a small piece of JavaScript code to each requested html file. This script establishes the web socket connection and listens to the reload requests. CSS files can be refreshed without a full page reload by finding the referenced stylesheets from the DOM and tricking the browser to fetch and parse them again.
We welcome contributions! See CONTRIBUTING.md for details.
default-src 'none'
for connect-src
in CSP (it should drop 'none'
, to avoid a warning) (@1j01)nonce
in connect-src
inherited from modified default-src
(it now inherits the original default-src
) (@1j01)connect-src
is defined (@1j01)live-server.js
, index.js
, injected.html
, and middleware/
(@1j01)--https-module=MODULE_NAME
to specify custom HTTPS module (e.g. spdy
) (@pavel)--no-css-inject
to reload page on css change instead of injecting the changes (@kylecordes)--middleware
parameter to use external middlewaresmiddleware
API parameter now also accepts strings similar to --middleware
--ignore
now accepts regexps and globs, --ignorePattern
deprecated (@pavel)--verbose
cli option (logLevel 3) (@pavel)
--spa
to a bundled middleware filespa-no-assets
middleware that works like spa
but ignores requests with extension--open
arguments (@PirtleShell)head
if body
not found (@pmd1991)--spa
cli option for single page apps, translates requests from /abc to /#/abc (@evanplaice)IP
env var for default host (@dotnetCarpenter)ignorePattern
from config file (@cyfersystems)--quiet
now silences warning about injection failure--watch
paths now disables adding mounted paths to watching--ignorePattern=REGEXP
exclude files from watching by regexp (@psi-4ward)--watch=PATH
cli option to only watch given paths--mount=ROUTE:PATH
cli option to specify alternative routes to paths (@pmentz)--browser=BROWSER
cli option to specify browser to use (@sakiv)~/.live-server.json
if exists (@mikker)--port=0
to select random port (@viqueen)--version / -v
command line flags to display version--host
cli option to mirror the API parameter--ignore=PATH
cli option to not watch given server root relative paths (@richardgoater)--entry-file=PATH
cli option to specify file to use when request is not found (@izeau)--wait=MILLISECONDS
cli option to wait specified time before reloading (@leolower, @harrytruong)</body>
logLevel
parameter in library to control amount of console spam--quiet
cli option to suppress console spam--open=PATH
cli option to launch browser in specified path instead of root (@richardgoater)noBrowser: true
option is deprecated in favor of open: false
--no-browser
command line flag to suppress browser launch--help
command line flag to display usagelive-server --port=3000
(@Pomax)send
watchr
> 2.3.3Uses MIT licensed code from Connect and Roots.
(MIT License)
Copyright (c) 2012 Tapio Vierros
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
FAQs
live-server fork that adds Content-Security-Policy (CSP) support (a simple development http server with live reload capability)
The npm package @1j01/live-server receives a total of 15 weekly downloads. As such, @1j01/live-server popularity was classified as not popular.
We found that @1j01/live-server demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.
Research
Security News
Socket researchers have discovered multiple malicious npm packages targeting Solana private keys, abusing Gmail to exfiltrate the data and drain Solana wallets.