Skip to content

fix: use setGlobalProxyFromEnv to enable proxy - #1577

Merged
danielroe merged 2 commits into
mainfrom
fix/fetch-proxy
Sep 29, 2026
Merged

danielroe merged 2 commits into
mainfrom
fix/fetch-proxy

Conversation

@danielroe

Copy link
Copy Markdown
Member

🔗 Linked issue

📚 Description

use node's built in setGlobalProxyFromEnv where it's available to enable proxy without the need for a user to set an env variable

@pkg-pr-new

pkg-pr-new Bot commented Sep 29, 2026

Copy link
Copy Markdown
  • nuxt-cli-playground

    npm i https://pkg.pr.new/create-nuxt@1577
    
    npm i https://pkg.pr.new/nuxi@1577
    
    npm i https://pkg.pr.new/@nuxt/cli@1577
    

commit: f00edcf

@github-actions

Copy link
Copy Markdown
Contributor

CLI benchmark

@nuxt/cli v4.0.0-alpha.1 (baseline) vs v4.0.0-alpha.1 (this PR)

Metric baseline v4.0.0-alpha.1 head v4.0.0-alpha.1 Delta
nuxt --version wall time (median) 69 ms 91 ms +32.9%
nuxt --help wall time (median) 149 ms 148 ms -0.7%
nuxt dev --help wall time (median) 108 ms 107 ms -0.7%
nuxt --version modules loaded 36 37 +2.8%
nuxt --help modules loaded 143 143 0.0%
nuxt dev --help modules loaded 62 62 0.0%
Installed node_modules 2.40 MB 2.40 MB +0.0%
Published tarball (packed) 238.0 kB 238.1 kB +0.0%
Full report

@nuxt/cli v4.0.0-alpha.1 (baseline) vs v4.0.0-alpha.1 (head)

Setting Value
Baseline ref:8babb655c5f6ca4359eda60a7ea8871b1befa4cb (v4.0.0-alpha.1)
Head local packages/nuxt-cli at 42e78ae (v4.0.0-alpha.1)
Node v24.21.0
OS Linux 6.17.0 (kernel 6.17.0-1022-azure)
CPU AMD EPYC 7763 64-Core Processor x 4
Memory 15.6 GB
Load average at start 0.95, 0.28, 0.10
Run started 2026-09-29T03:26:46.193Z

Cold CLI startup

Median of 15 interleaved runs per command, one warmup discarded.

Command baseline v4.0.0-alpha.1 median head v4.0.0-alpha.1 median Delta baseline v4.0.0-alpha.1 min / p95 head v4.0.0-alpha.1 min / p95
nuxt --version 69 ms 91 ms +32.9% 66 ms / 73 ms 88 ms / 95 ms
nuxt --version (first output byte) 64 ms 86 ms +33.4% 61 ms / 68 ms 82 ms / 89 ms
nuxt --help 149 ms 148 ms -0.7% 146 ms / 154 ms 146 ms / 155 ms
nuxt --help (first output byte) 144 ms 142 ms -1.1% 141 ms / 149 ms 140 ms / 149 ms
nuxt dev --help 108 ms 107 ms -0.7% 104 ms / 113 ms 103 ms / 111 ms
nuxt dev --help (first output byte) 102 ms 102 ms -0.2% 98 ms / 108 ms 98 ms / 106 ms
nuxt <unknown-command> (no-op) 158 ms 160 ms +1.2% 155 ms / 160 ms 156 ms / 163 ms
nuxt <unknown-command> (no-op) (first output byte) 152 ms 154 ms +1.3% 150 ms / 154 ms 150 ms / 157 ms

Module load cost

Counted with a module.registerHooks load hook, compile cache disabled. Counts every JS module actually evaluated on that code path (built-ins excluded, native addons excluded).

Command baseline v4.0.0-alpha.1 modules head v4.0.0-alpha.1 modules Delta baseline v4.0.0-alpha.1 source bytes head v4.0.0-alpha.1 source bytes Delta
nuxt --version 36 37 +2.8% 296.6 kB 296.8 kB +0.1%
nuxt --help 143 143 0.0% 960.2 kB 960.4 kB +0.0%
nuxt dev --help 62 62 0.0% 451.3 kB 451.5 kB +0.0%

Install footprint and published tarball

Each version installed on its own into an empty project with nothing but @nuxt/cli as a dependency, so the tree is exactly the CLI and its transitive dependencies. npm cache is warm and the registry is only consulted for metadata, so install wall time is indicative, not a network benchmark.

Metric baseline v4.0.0-alpha.1 head v4.0.0-alpha.1 Delta
Direct dependencies of @nuxt/cli 22 22 0.0%
Packages in the installed tree (unique name@version) 38 38 0.0%
Unique package names 38 38 0.0%
Package directories on disk (cross-check) 31 31 0.0%
Installed node_modules on disk 2.40 MB 2.40 MB +0.0%
Installed files 421 421 0.0%
Install wall time (warm npm cache, median of 3) 1.33 s 1.32 s -0.8%
Published tarball (packed) 238.0 kB 238.1 kB +0.0%
Published tarball (unpacked) 775.2 kB 775.4 kB +0.0%
Files in tarball 98 98 0.0%

Interleaved runs on a shared runner: trust the deltas, not the absolute timings. The dev, restart and build suites run locally via pnpm bench:cli.

@codspeed

codspeed Bot commented Sep 29, 2026

Copy link
Copy Markdown

Merging this PR will not alter performance

✅ 2 untouched benchmarks


Comparing fix/fetch-proxy (f00edcf) with main (8babb65)

Open in CodSpeed

@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 527cbfa2-b86a-493d-85c6-e62829e667ee

📥 Commits

Reviewing files that changed from the base of the PR and between 8babb65 and f00edcf.

📒 Files selected for processing (7)
  • packages/create-nuxt/src/main.ts
  • packages/create-nuxt/test/unit/proxy.spec.ts
  • packages/nuxi/src/main.ts
  • packages/nuxt-cli/src/main.ts
  • packages/nuxt-cli/src/utils/network.ts
  • packages/nuxt-cli/test/unit/utils/network.spec.ts
  • packages/nuxt-cli/test/utils/proxy.ts
💤 Files with no reviewable changes (1)
  • packages/nuxt-cli/src/main.ts

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

setupProxySupport now enables Node global proxying when the API is available and the environment permits it. The create-nuxt and nuxi entry points call the setup function during module initialization. Tests cover tunnel routing, NO_PROXY bypass, disabled proxying, and requests through both entry points.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~12 minutes

Merge Risk: ⚪ Minimal · up to f00ed

The change enables environment-based proxy support in create-nuxt and nuxi, and it is respected when explicitly disabled. No merge-blocking risk was identified.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to f00ed

Proxy settings inherited by the CLI can now route its own network requests, including update checks, through a configured proxy. Explicit opt-out and proxy bypass settings limit that change, but the broader routing deserves review.

Retained concerns

  • Medium · security · inferred: On supported Node versions, inherited proxy variables now implicitly select a route for current-process CLI requests. That expands the trust placed in the proxy for request destinations and availability, including authenticated registry update checks; credential disclosure would additionally depend on transport and proxy trust conditions not established here.
Security review details

Security Blast Radius

  • inferred — The new default affects eligible current-process network requests across the three CLI entry points, rather than only requests in child processes. The established scope is those CLI processes, not a server-side tenant or service boundary.

Security Findings and Attack Paths

  • inferred — A party able to influence a CLI process’s proxy environment could influence its newly proxied request path. The reviewed evidence does not establish such attacker control or demonstrate interception of authenticated traffic.

Trust Boundaries and Controls

  • observed — Proxy environment variables become a current-process routing input only when Node supports environment proxies; NODE_USE_ENV_PROXY=0 prevents new activation, and the routing test confirms NO_PROXY behavior for a local target.

Resilience and Maintainability Implications

  • observed — Production setup does not retain a restoration callback from global activation; the test proxy utility does retain and invoke one. The supplied source does not establish a production need for in-process reversal or its behavior after a later opt-out.

Hardening Proposals

  • proposed — Document that inherited proxy settings can affect credential-bearing CLI requests, and define whether an embedded or long-lived CLI process must support restoring its previous proxy state.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 66.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 6 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description check ✅ Passed The description accurately states that the change uses Node's built-in setGlobalProxyFromEnv to enable proxy support without requiring users to set an environment variable.
Title check ✅ Passed The title clearly and concisely identifies the main change: using setGlobalProxyFromEnv to enable proxy support.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@danielroe
danielroe added this pull request to the merge queue Sep 29, 2026
Merged via the queue into main with commit 588fa8b Sep 29, 2026
24 checks passed
@danielroe
danielroe deleted the fix/fetch-proxy branch September 29, 2026 03:39
@github-actions github-actions Bot mentioned this pull request Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant