Repository navigation
Conversation
There was a problem hiding this comment.
Warning
Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.
Pull request overview
Implements a loopback-only binding and Host-header validation for the dev-phone local server to mitigate unauthenticated LAN access and DNS-rebinding attacks.
Changes:
- Bind the Express server to
127.0.0.1instead of all interfaces. - Add
isLoopbackHost()helper + middleware to reject non-loopbackHostheaders. - Add unit tests, a decision record, and a changeset describing the security hardening.
Reviewed changes
Copilot reviewed 5 out of 5 changed files in this pull request and generated 3 comments.
Show a summary per file
| File | Description |
|---|---|
| packages/plugin-dev-phone/test/utils/helpers.test.js | Adds unit tests covering isLoopbackHost() allow/deny cases. |
| packages/plugin-dev-phone/src/utils/helpers.ts | Introduces isLoopbackHost() helper used by the server middleware. |
| packages/plugin-dev-phone/src/commands/dev-phone.ts | Enforces loopback-only requests via bind address + Host-header middleware. |
| decisions/loopback-only.md | Documents rationale and tradeoffs for loopback-only + Host check. |
| .changeset/busy-doors-lock.md | Publishes a patch-level release note describing the security fix. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+27
to
+28
| - **A `--host` flag or `TWILIO_DEV_PHONE_HOST` env var**, mirroring how port is configurable (see [ports.md](./ports.md)). Rejected: the whole reason non-loopback binding was a vulnerability is that this server acts on the developer's real account with no per-request auth. Making it opt-outable puts a foot-gun in every user's hand and would likely re-appear in tutorials and blog posts. Developers who genuinely need to expose the running Dev Phone to another machine can use ngrok, an SSH port forward, or localtunnel — all of which connect *to* `127.0.0.1` from the dev machine and don't require the server itself to be reachable from the network. | ||
| - **The LAN-sharing use case hinted at in [ports.md](./ports.md)** ("letting a boss peek at the Dev Phone using ngrok or sharing on the local network"). The ngrok half still works fine — ngrok tunnels to localhost. The "sharing on the local network" half is the exact thing this decision retires, on purpose. |
| const isHeadless = () => !!this.flags.headless; | ||
|
|
||
| app.listen(this.port, () => { | ||
| app.listen(this.port, '127.0.0.1', () => { |
|
|
||
| const LOOPBACK_HOSTNAMES = new Set(['localhost', '127.0.0.1', '[::1]']); | ||
|
|
||
| export function isLoopbackHost (host: string | undefined) { |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Implement host check
Contributing to Twilio