GioJSdocs
On this page

[dev]

Development-only settings: which hosts the dev endpoints answer, the devtools, and the file watcher that restarts the worker.

gio.toml
[dev]
allowed_hosts = ["192.168.1.20", "myvm.local"]
watch_ignore = ["data/**", "*.db.json"]

The section only takes effect when the server runs with NODE_ENV=development (gio dev, npm run dev). In production the dev endpoints do not exist and there is no watcher, whatever it says.

Reference

KeyDefaultDescription
allowed_hostsstring[][]Extra Host names the /_gio/devtools* endpoints and render error details answer to, besides localhost, *.localhost and loopback IPs (from this machine) and a specific [server] host. Hostnames or IPs; a leading . or *. matches subdomains; a pasted http(s):// and port are ignored. An entry that is not a host is skipped with a warning. ["*"] answers any Host from any machine and warns; open-in-editor never follows it (see Not configurable).0 / false / empty: Empty: only the hosts named above
devtoolsbooleantrueRoute the dev endpoints: the dashboard, its state and event stream (which drives live reload), error-overlay codeframes and open-in-editor. Off, the error overlay still shows the message and stack, without codeframes, editor links or live reload.0 / false / empty: /_gio/devtools* answers 404
watchbooleantrueRestart the worker when a source file changes (and reload open tabs). Turn it off in a huge monorepo, on a network filesystem or when the machine runs out of inotify watches.0 / false / empty: No watcher; restart by hand
watch_ignorestring[][]Globs, relative to the project root, the watcher never restarts for: data files the app writes. * stays within a segment, ** spans segments, and a pattern without / matches a name at any depth. See Dev watcher.

Behavior

  • DNS rebinding protection. A request whose Host is not allowed gets 403 from the dev endpoints, and a failed render shows a generic message instead of its error and stack. localhost names count only on a connection from this machine. See Dev endpoints & allowed hosts.
  • Startup logs the extra hosts it answers to, and reminds you when the server binds 0.0.0.0 with no allowed_hosts. devtools = false and watch = false each log an info line.
  • node_modules, hidden directories (.git, .gio) and build output are never watched; neither are the page cache's own files.

Startup warnings

WhenStartup warning
allowed_hosts contains "*"[dev] allowed_hosts = ["*"]: in dev mode the /_gio/devtools endpoints (source codeframes, live server state) and render error details answer any Host from any machine, so DNS rebinding is no longer blocked - list the hostnames you browse from instead
An entry that is not a hostname or IPignoring [dev] allowed_hosts entry "bad host!" in gio.toml: expected a hostname or IP such as "myvm.local", "192.168.1.20" or "*.tunnel.example", or "*" for any host

The "*" warning is logged in every mode, since the file is the same; --check-config reports both.

Examples

Open the dev server from your phone

gio.toml
[dev]
allowed_hosts = ["192.168.1.20"]     # the address you type on the phone

A tunnel

gio.toml
[dev]
allowed_hosts = ["*.trycloudflare.com"]

An app that writes JSON files

gio.toml
[dev]
watch_ignore = ["data/**"]           # lowdb, uploads, caches the app writes

Good to know

  • An allowed_hosts entry opens the dev endpoints - project source included - to every client that can reach the port and sends that host. On an untrusted network, bind 127.0.0.1 instead.
  • A malformed watch_ignore pattern (.., a backslash) stops startup.
  • Development always runs one render worker, whatever [server] workers says.

Not configurable

  • open-in-editor stays same-origin and ignores "*". It accepts POST only and refuses anything but a same-origin request (or Sec-Fetch-Site: none), so a link or form on another site cannot launch your editor. A DNS-rebound page is same-origin with its own Host, so allowed_hosts = ["*"] never covers it: open-in-editor answers only localhost hosts from this machine, a specific [server] host and the hosts allowed_hosts names explicitly (["*", "myvm.local"]).
  • /_gio/devtools* is a 404 in production.

Version history

VersionChanges
v0.1.0-beta.8Introduced with allowed_hosts (["*"] answers any host, with a warning), devtools, watch and watch_ignore.