feat(dev-server): add https option to serve TLS over HTTP/1.1 - #3165
Open
fredrikbernholm wants to merge 1 commit into
Open
fredrikbernholm wants to merge 1 commit into
fredrikbernholm wants to merge 1 commit into
Conversation
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
🦋 Changeset detectedLatest commit: 9a0b28f The changes in this PR will be included in the next version bump. This PR includes changesets to release 2 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What I did
Added an
httpsboolean option to@web/dev-server-coreand@web/dev-server. It serves over TLS with HTTP/1.1 through Node'shttps.createServer. HTTP/2 does not need to be on.Why
At the moment the only way to get TLS is
http2: true. That useshttp2.createSecureServerwithallowHTTP1: true. Ifhttp2is off,sslKey/sslCertare ignored and the server speaks plain HTTP.Node's http2 server drops streams when a browser loads a large unbundled ES module graph over a single session. Chrome reports
ERR_HTTP2_PROTOCOL_ERRORand the server logsERR_HTTP2_ERROR. We hit this on an app with about 2,400 modules: reloads hang and dozens of module requests fail. The same app loads reliably when Chrome runs with--disable-http2, which means HTTP/1.1 over the same certificate.Some apps need HTTPS in local development, for example for secure cookies, service workers, OAuth redirect URIs or HSTS domains. Today they have to use HTTP/2 and they run into these failures. We work around it with a patch-package patch that swaps
http2.createSecureServerforhttps.createServer, and we'd like to drop that patch.Changes
createServer: whenhttp2orhttpsis set, the server is built from the same TLS branch. It readssslKey/sslCertand falls back to the bundled self-signed pair if they are not given. It also sets up the same HTTP→HTTPS redirect wrapper as before. The only difference is the server constructor:http2still useshttp2.createSecureServerwithallowHTTP1andmaxSessionMemory, andhttpsuseshttps.createServer.http2wins if both are set.http2: trueis unchanged, and with neither option the server is still plain HTTP.DevServerCoreConfig.https, config validation (booleanSettings), and the logged and opened URLs (https://) are handled the same way ashttp2. There is no--http2CLI flag, so I did not add--httpseither.cli-and-configuration.md. A changeset adds a minor bump for both packages.http2to the dev server, and supportinghttpsthere can be a separate change.Testing
dev-server-core/test/server/DevServer.test.ts: starts the server withhttps: true, requestsindex.htmlwithhttps.get(rejectUnauthorized: false), and checks that the socket is TLS,res.httpVersion === '1.1', the status is 200, and the body is correct.npm run buildpasses.@web/dev-server-coretest:node: 98/98 pass.@web/dev-servertest:node: 6/6 pass.