Skip to content

Feature/implement host check - #225

Open
ayyrickay wants to merge 2 commits into
mainfrom
feature/implement-host-check
Open

ayyrickay wants to merge 2 commits into
mainfrom
feature/implement-host-check

Conversation

@ayyrickay

@ayyrickay ayyrickay commented Sep 10, 2026 •

Copy link
Copy Markdown
Collaborator

Implement host check

Contributing to Twilio

All third-party contributors acknowledge that any contributions they provide will be made under the same open-source license that the open-source project is provided under.

  • I acknowledge that all my contributions will be made under the project's license.

@ayyrickay ayyrickay added enhancement New feature or request plugin-backend labels Sep 10, 2026
@ayyrickay
ayyrickay requested a lite review from Copilot September 10, 2026 11:48

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Warning

Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.

Pull request overview

Implements a loopback-only binding and Host-header validation for the dev-phone local server to mitigate unauthenticated LAN access and DNS-rebinding attacks.

Changes:

  • Bind the Express server to 127.0.0.1 instead of all interfaces.
  • Add isLoopbackHost() helper + middleware to reject non-loopback Host headers.
  • Add unit tests, a decision record, and a changeset describing the security hardening.

Reviewed changes

Copilot reviewed 5 out of 5 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
packages/plugin-dev-phone/test/utils/helpers.test.js Adds unit tests covering isLoopbackHost() allow/deny cases.
packages/plugin-dev-phone/src/utils/helpers.ts Introduces isLoopbackHost() helper used by the server middleware.
packages/plugin-dev-phone/src/commands/dev-phone.ts Enforces loopback-only requests via bind address + Host-header middleware.
decisions/loopback-only.md Documents rationale and tradeoffs for loopback-only + Host check.
.changeset/busy-doors-lock.md Publishes a patch-level release note describing the security fix.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +27 to +28
- **A `--host` flag or `TWILIO_DEV_PHONE_HOST` env var**, mirroring how port is configurable (see [ports.md](./ports.md)). Rejected: the whole reason non-loopback binding was a vulnerability is that this server acts on the developer's real account with no per-request auth. Making it opt-outable puts a foot-gun in every user's hand and would likely re-appear in tutorials and blog posts. Developers who genuinely need to expose the running Dev Phone to another machine can use ngrok, an SSH port forward, or localtunnel — all of which connect *to* `127.0.0.1` from the dev machine and don't require the server itself to be reachable from the network.
- **The LAN-sharing use case hinted at in [ports.md](./ports.md)** ("letting a boss peek at the Dev Phone using ngrok or sharing on the local network"). The ngrok half still works fine — ngrok tunnels to localhost. The "sharing on the local network" half is the exact thing this decision retires, on purpose.
const isHeadless = () => !!this.flags.headless;

app.listen(this.port, () => {
app.listen(this.port, '127.0.0.1', () => {

const LOOPBACK_HOSTNAMES = new Set(['localhost', '127.0.0.1', '[::1]']);

export function isLoopbackHost (host: string | undefined) {
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request plugin-backend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants