Repository navigation
Security: spek's servers answer only spek's own pages. (#69)
- Web: the API server is local-only. While
npm run devran, the API server listened on every network interface and let any web page read its responses, so another device on the same network, or any page open in your browser, could list directories on your machine and read OpenSpec content. It now listens on127.0.0.1only and refuses any request that is not from the app itself: another site, another port onlocalhost, or a host name pointed at your machine (DNS rebinding). The dev server on 5173 is loopback-only as well - IntelliJ: the plugin's endpoints refuse other local pages. The IDE already refused other sites, but a page served on another port of your machine could read the plugin's API, because the IDE's built-in server allows any local origin. Only the plugin's own pages (the tool window and the external-browser view) are served now
- Behaviour change: the web app can no longer be opened from another machine (for example a phone on your LAN).
npm run devnow stops with an error when port 5173 is taken, instead of moving to another port. One dev server can browse every worktree, so a second one is not needed