v0.6.1
A fix release. Components whose extends clause holds braces load in dev
again, and the plugin now shares one devframe with the current Vite DevTools.
The rest comes from a security pass over the dev server: source opens and
snapshot exports stay inside the project, and the standalone server won't go
without its code gate on a network address.
Changed
lit-devtools dev --no-authonly runs on localhost. Combined with a
--hostother machines can reach, it now refuses to start instead of
letting anyone on the network drive the panel without a code.
Fixed
- Components whose
extendsclause has braces load in dev again. With
sourceOverlayon, a class likeextends Dialog<{open: boolean}>or
extends Mixin(Base, {shadow: true})broke the module with a 500 from the
dev server. Broken since 0.3.0. - Exporting a snapshot can no longer delete your files. The export wipes
its output directory before writing, and nothing checked which directory
that was. It now only writes inside the dev server's working directory and
only replaces an earlier snapshot. - The panel can only open source files inside your project. Source links
from the DevTools panel used to open any absolute path they were given. They
now follow the same rule as the in-page overlay: the path has to be under
the Vite root orserver.fs.allow. - Symlinks can't send the editor outside your project. Opening a source
file used to follow a symlink under the project to wherever it pointed. Now
the target has to be inside the project too. - One copy of devframe alongside the current Vite DevTools. The plugin
pinned devframe 1.0.0 exactly, so apps on@vitejs/devtools-kit0.7.6
installed a second copy and got an unmet-peer warning. It now accepts any
devframe 1.x.