From e5fbd27a15a671996c8694daafeb290d926b0708 Mon Sep 17 00:00:00 2001 From: Mattt Zmuda Date: Wed, 23 Sep 2026 11:38:21 -0700 Subject: [PATCH] Accept connections only over loopback The listener accepted connections on every IPv4 interface, so another device on the same network could reach it (#103). The CLI has connected over 127.0.0.1 since #229, so bind both listeners to the IPv4 loopback address. Bonjour still advertises the service and its port. --- App/Controllers/ServerController.swift | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/App/Controllers/ServerController.swift b/App/Controllers/ServerController.swift index 5eb8beea..e2eeef00 100644 --- a/App/Controllers/ServerController.swift +++ b/App/Controllers/ServerController.swift @@ -619,8 +619,9 @@ actor NetworkDiscoveryManager { let parameters = NWParameters.tcp parameters.acceptLocalOnly = true parameters.includePeerToPeer = false - // Match the IPv4 protocol below to avoid NECP errors for an IPv6 wildcard. - parameters.requiredLocalEndpoint = .hostPort(host: .ipv4(.any), port: .any) + // Accept connections from this Mac only; the CLI connects over loopback (#229). + // IPv4 matches the protocol below and avoids NECP errors for an IPv6 wildcard. + parameters.requiredLocalEndpoint = .hostPort(host: .ipv4(.loopback), port: .any) if let tcpOptions = parameters.defaultProtocolStack.internetProtocol as? NWProtocolIP.Options @@ -686,8 +687,9 @@ actor NetworkDiscoveryManager { let parameters: NWParameters = NWParameters.tcp // Explicit type parameters.acceptLocalOnly = true parameters.includePeerToPeer = false - // Match the IPv4 protocol below to avoid NECP errors for an IPv6 wildcard. - parameters.requiredLocalEndpoint = .hostPort(host: .ipv4(.any), port: .any) + // Accept connections from this Mac only; the CLI connects over loopback (#229). + // IPv4 matches the protocol below and avoids NECP errors for an IPv6 wildcard. + parameters.requiredLocalEndpoint = .hostPort(host: .ipv4(.loopback), port: .any) if let tcpOptions = parameters.defaultProtocolStack.internetProtocol as? NWProtocolIP.Options