Skip to content

fix(vite): share an https dev server for the hub WebSocket - #419

Merged
antfu merged 7 commits into
devframes:mainfrom
erkamyaman:fix/vite-hub-https-upgrade
Oct 2, 2026
Merged

antfu merged 7 commits into
devframes:mainfrom
erkamyaman:fix/vite-hub-https-upgrade

Conversation

@erkamyaman

@erkamyaman erkamyaman commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Description

viteDevframeHub only shares Vite's server for the WebSocket upgrade when server.httpServer instanceof http.Server. With server.https (or @vitejs/plugin-basic-ssl), Vite creates an Http2SecureServer with allowHTTP1, or an https.Server when server.proxy is set. Neither passes the check, so the plugin falls back to a plain ws side-car on its own port.

__connection.json then advertises { port: 9777, path: '__ws' }. On an https page the client resolves that to wss://localhost:9777/__ws, but the side-car does not speak TLS, so the handshake fails. The client picks the WebSocket whenever one is advertised, so it never falls back to SSE and the hub stays stuck connecting.

Both server types emit upgrade for HTTP/1.1 requests (Vite's own HMR socket depends on this), and the ws transport already accepts an https server. This change passes server.httpServer through whenever it exists, like devframeViteBridge in single.ts already does. The side-car is still used for a pinned port and for middleware mode (no httpServer).

angular-devtools had the same instanceof check in its own Vite plugin and fixed it by attaching handleUpgrade to the dev server's upgrade event, which is what this change does for the hub.

Reproduction

  1. Add viteDevframeHub() to a Vite app and enable server.https (for example with @vitejs/plugin-basic-ssl).
  2. Open the app over https.
  3. __devframes/__connection.json advertises a side-car port, and the socket to wss://localhost:<port>/__ws fails. wss://localhost:<vite port>/__devframes/__ws returns 404 because nothing listens for the upgrade there.

How I tested

  • New packages/vite/test/hub.test.ts: a fake Vite server whose httpServer is http2.createSecureServer({ allowHTTP1: true }). It checks that __connection.json advertises { path: '/__devframes/__ws' } and that the hub attached an upgrade listener. Before the fix it fails with expected { port: 9777, path: '__ws' } to deeply equal { path: '/__devframes/__ws' }.
  • By hand, with a self-signed cert on a real Http2SecureServer and the built plugin: a ws client to wss://127.0.0.1:<port>/__devframes/__ws opens after the fix and gets Unexpected server response: 404 before it.
  • vitest run --project @devframes/vite (11 passed), eslint on the changed files, and tsc --noEmit for the package.

Follow-up from review

  • instance-shell.ts now advertises wss:// and an https:// origin when the shared server is a TLS server, so remote docks on an https host get a secure endpoint (tested in initiate.test.ts).
  • hub.test.ts now does a real wss:// handshake against an Http2SecureServer with a throwaway self-signed cert.

Copilot AI balanced review requested due to automatic review settings October 1, 2026 12:39
@coldtea-pr-lens

coldtea-pr-lens Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

◈ PR Lens

Note

This drawing shows e54fde6, and the branch has new commits since. Tick Redraw to draw the latest one

  • Redraw

🟢 +0 new · 🟠 ~1 changed · 🔴 -0 removed · 1 flow · 2 files · commit e54fde6


Architecture

Architecture diagram for devframes/devframe at e54fde6

1 component touched across 3 lanes.

Play the interactive walkthrough


Data flow

Data flow diagram for devframes/devframe at e54fde6

Sharing HTTPS dev server for WebSocket upgrade

Follow each request, response and payload


View

  • Architecture lens
  • Data flow lens
  • Expand every detail

Tip

Set github.comment.collapsed: true in .github/pr-lens.yml to fold the comment behind one View architecture and data flow row. Drawing still runs as before

🪧 More tips
  • Run npx skills add coldteadotai/pr-lens, then tell your coding agent: "Diagram the change you just made with PR Lens and attach it to the pull request."
  • Run npx @coldtea/pr-lens-cli analyze --base origin/main on a branch, then npx @coldtea/pr-lens-cli render .pr-lens/graph.json. Same lenses, your own model key, before the pull request exists
  • Untick Architecture lens or Data flow lens under View to hide a diagram, or tick Expand every detail to open every section. The comment redraws in a few seconds
  • Click the link under each diagram to open it on a canvas you can zoom, pan and step through
  • The diagrams are links. Click one to open it on the canvas, then press W or click play to walk through the change
  • Open a diagram on the canvas, then press W or click play to walk through the change one step at a time
  • The CLI's render reads .github/pr-lens.yml and applies your renames, exclusions and lane pins at draw time
  • Set github.draw: on-demand in .github/pr-lens.yml and PR Lens stops drawing pull requests on its own. Comment @pr-lens draw on a pull request when you want that one drawn
  • Add .github/workflows/pr-lens.yml with coldteadotai/pr-lens/packages/action@v0 and your model provider's key as its api-key to run PR Lens from your own CI. Any /chat/completions endpoint works
  • Push a commit and the drawing stays, with a note that it is out of date. Tick Redraw in the note to draw the new head
  • Switch GitHub to dark mode and the diagrams follow. The moving dots are this pull request's data in motion

Thanks for using PR Lens! It's built by Coldtea, free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
devframe Skipped Skipped Oct 1, 2026 1:00pm UTC

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Secure shared servers publish an incorrect ws:// remote-dock endpoint, and the test does not perform a real TLS WebSocket handshake.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
What changed in this PR

Updates the Vite hub integration to share HTTPS/HTTP2 dev servers for WebSocket upgrades.

Changes:

  • Removes the plain-HTTP-only server check.
  • Adds an HTTP2 secure-server regression test.
File Description
packages/​vite/​src/​hub.ts Shares any available Vite HTTP server.
packages/​vite/​test/​hub.test.ts Tests secure-server attachment and discovery metadata.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread packages/vite/src/hub.ts
Comment thread packages/vite/test/hub.test.ts Outdated
Copilot AI balanced review requested due to automatic review settings October 1, 2026 13:00

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Pre-listening Vite servers permanently advertise remote WebSocket endpoints on port zero.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
Resolved since last review (1)

Comment thread packages/devframe/src/node/instance-shell.ts Outdated
Copilot AI balanced review requested due to automatic review settings October 1, 2026 13:18
@vercel

vercel Bot commented Oct 1, 2026

Copy link
Copy Markdown

@erkamyaman is attempting to deploy a commit to the NuxtLabs Team on Vercel.

A member of the Team first needs to authorize it.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

HTTPS configurations using side-car ports still advertise unusable secure WebSocket endpoints.

Review effort: Balanced
Findings: 1 High severity

Open (1)
Resolved since last review (2)
Previously missed (1)

In code that hasn't changed since last review

Low severity Remove ad-hoc warning for conditionally skipped suites

packages/​vite/​test/​hub.test.ts:31

This raw Node-side warning violates the repository's coded-diagnostics rule in .agents/08-diagnostics.md. Vitest already reports the conditionally skipped suite, so remove this ad-hoc warning rather than adding a diagnostic solely for the test environment.

Comment thread packages/vite/src/hub.ts
Copilot AI balanced review requested due to automatic review settings October 2, 2026 01:22

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Shared TLS servers still return a plain-HTTP listening origin.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
Resolved since last review (1)

Comment thread packages/devframe/src/node/instance-shell.ts
@antfu
antfu merged commit 495fc4e into devframes:main Oct 2, 2026
10 of 12 checks passed
@erkamyaman
erkamyaman deleted the fix/vite-hub-https-upgrade branch October 2, 2026 04:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants