Sert le bundle web (dist/) en same-origin via --web-root / IDEA_WEB_ROOT ou le web/ packagé. serve_static durci : anti path-traversal, typage MIME, X-Content-Type-Options nosniff, CSP, fallback SPA. Ajoute POST /api/logout qui révoque la session HTTP + WS, et une journalisation sécurité via SecurityLogger. Documente le déploiement remote (dev local, packaging web/, reverse proxy HTTPS). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
1.4 KiB
IdeA Server/Client Remote Deployment
idea --serve serves the web UI and the API from the same origin. The frontend
build must be available as a web root containing index.html.
Local Development
pnpm --dir frontend build
idea --serve --web-root frontend/dist
The default local listener is 127.0.0.1:17373. Loopback development may use
plain HTTP; the session cookie is still HttpOnly and SameSite=Strict.
Packaged Artifact
The release artifact is still a single IdeA binary/AppImage. Packaging must copy
the frontend build output (frontend/dist) into the packaged web/ resource
next to the binary. idea --serve resolves assets in this order:
--web-root PATHIDEA_WEB_ROOT- packaged
web/, then packagedfrontend/dist/ - development fallback
frontend/distrelative to the current directory
If no index.html is found, the server refuses to start.
Remote HTTPS
Public exposure requires a reverse proxy that terminates HTTPS:
idea --serve \
--listen 127.0.0.1:17373 \
--allow-remote \
--public-origin https://idea.example.com \
--trust-reverse-proxy
The proxy must forward the same origin for the SPA, /api/*, and /api/ws.
Do not expose the backend on a public non-loopback address without TLS proxying.
Secrets must never be placed in URLs; pairing uses POST /api/pair and then an
HttpOnly, Secure, SameSite=Strict session cookie.