Skip to content

jeview.localhost opens the viewer - #4

Merged
andududu merged 1 commit into
mainfrom
localhost-names
Sep 21, 2026
Merged

andududu merged 1 commit into
mainfrom
localhost-names

Conversation

@andududu

Copy link
Copy Markdown
Owner

Jeview's host allowlist now accepts names ending in .localhost, which are reserved for the machine itself (RFC 6761), so http://jeview.localhost:4777/ opens the viewer with no hosts entry. Lookalike names stay refused; tests cover both.

🤖 Generated with Claude Code

Jeview answers only to the names this machine goes by, so that a page on
another site cannot reach it through a name of its own. A name ending in
.localhost is one of those names: the ending is reserved for the machine
itself, browsers and macOS resolve it to loopback without being told, and
no other site can have it. Names that only look like one (localhost.x.com,
x.localhost.y.com) are refused as before.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@andududu
andududu merged commit 313fb25 into main Sep 21, 2026
2 checks passed
@andududu
andududu deleted the localhost-names branch September 21, 2026 19:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant