Skip to content

feat(dev-server): add https option to serve TLS over HTTP/1.1 - #3165

Open
fredrikbernholm wants to merge 1 commit into
modernweb-dev:masterfrom
fredrikbernholm:feat/dev-server-https-http1
Open

fredrikbernholm wants to merge 1 commit into
modernweb-dev:masterfrom
fredrikbernholm:feat/dev-server-https-http1

Conversation

@fredrikbernholm

Copy link
Copy Markdown

What I did

Added an https boolean option to @web/dev-server-core and @web/dev-server. It serves over TLS with HTTP/1.1 through Node's https.createServer. HTTP/2 does not need to be on.

Why

At the moment the only way to get TLS is http2: true. That uses http2.createSecureServer with allowHTTP1: true. If http2 is off, sslKey/sslCert are ignored and the server speaks plain HTTP.

Node's http2 server drops streams when a browser loads a large unbundled ES module graph over a single session. Chrome reports ERR_HTTP2_PROTOCOL_ERROR and the server logs ERR_HTTP2_ERROR. We hit this on an app with about 2,400 modules: reloads hang and dozens of module requests fail. The same app loads reliably when Chrome runs with --disable-http2, which means HTTP/1.1 over the same certificate.

Some apps need HTTPS in local development, for example for secure cookies, service workers, OAuth redirect URIs or HSTS domains. Today they have to use HTTP/2 and they run into these failures. We work around it with a patch-package patch that swaps http2.createSecureServer for https.createServer, and we'd like to drop that patch.

Changes

  • createServer: when http2 or https is set, the server is built from the same TLS branch. It reads sslKey/sslCert and falls back to the bundled self-signed pair if they are not given. It also sets up the same HTTP→HTTPS redirect wrapper as before. The only difference is the server constructor: http2 still uses http2.createSecureServer with allowHTTP1 and maxSessionMemory, and https uses https.createServer. http2 wins if both are set.
  • Existing configs behave the same. http2: true is unchanged, and with neither option the server is still plain HTTP.
  • DevServerCoreConfig.https, config validation (booleanSettings), and the logged and opened URLs (https://) are handled the same way as http2. There is no --http2 CLI flag, so I did not add --https either.
  • The docs list the option in cli-and-configuration.md. A changeset adds a minor bump for both packages.
  • I did not change the test runner. It only forwards http2 to the dev server, and supporting https there can be a separate change.

Testing

  • New test in dev-server-core/test/server/DevServer.test.ts: starts the server with https: true, requests index.html with https.get (rejectUnauthorized: false), and checks that the socket is TLS, res.httpVersion === '1.1', the status is 200, and the body is correct.
  • npm run build passes.
  • @web/dev-server-core test:node: 98/98 pass.
  • @web/dev-server test:node: 6/6 pass.
  • ESLint and Prettier are clean on the touched files.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@changeset-bot

changeset-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 9a0b28f

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
Name Type
@web/dev-server-core Minor
@web/dev-server Minor

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant