[dev]
Development-only settings: which hosts the dev endpoints answer, the devtools, and the file watcher that restarts the worker.
gio.toml
[dev]
allowed_hosts = ["192.168.1.20", "myvm.local"]
watch_ignore = ["data/**", "*.db.json"]The section only takes effect when the server runs with NODE_ENV=development (gio dev, npm run dev). In production the dev endpoints do not exist and there is no watcher, whatever it says.
Reference
| Key | Default | Description |
|---|---|---|
allowed_hostsstring[] | [] | Extra Host names the /_gio/devtools* endpoints and render error details answer to, besides localhost, *.localhost and loopback IPs (from this machine) and a specific [server] host. Hostnames or IPs; a leading . or *. matches subdomains; a pasted http(s):// and port are ignored. An entry that is not a host is skipped with a warning. ["*"] answers any Host from any machine and warns; open-in-editor never follows it (see Not configurable). |
devtoolsboolean | true | Route the dev endpoints: the dashboard, its state and event stream (which drives live reload), error-overlay codeframes and open-in-editor. Off, the error overlay still shows the message and stack, without codeframes, editor links or live reload. |
watchboolean | true | Restart the worker when a source file changes (and reload open tabs). Turn it off in a huge monorepo, on a network filesystem or when the machine runs out of inotify watches. |
watch_ignorestring[] | [] | Globs, relative to the project root, the watcher never restarts for: data files the app writes. * stays within a segment, ** spans segments, and a pattern without / matches a name at any depth. See Dev watcher. |
Behavior
- DNS rebinding protection. A request whose
Hostis not allowed gets403from the dev endpoints, and a failed render shows a generic message instead of its error and stack.localhostnames count only on a connection from this machine. See Dev endpoints & allowed hosts. - Startup logs the extra hosts it answers to, and reminds you when the server binds
0.0.0.0with noallowed_hosts.devtools = falseandwatch = falseeach log aninfoline. node_modules, hidden directories (.git,.gio) and build output are never watched; neither are the page cache's own files.
Startup warnings
| When | Startup warning |
|---|---|
allowed_hosts contains "*" | [dev] allowed_hosts = ["*"]: in dev mode the /_gio/devtools endpoints (source codeframes, live server state) and render error details answer any Host from any machine, so DNS rebinding is no longer blocked - list the hostnames you browse from instead |
| An entry that is not a hostname or IP | ignoring [dev] allowed_hosts entry "bad host!" in gio.toml: expected a hostname or IP such as "myvm.local", "192.168.1.20" or "*.tunnel.example", or "*" for any host |
The "*" warning is logged in every mode, since the file is the same; --check-config reports both.
Examples
Open the dev server from your phone
gio.toml
[dev]
allowed_hosts = ["192.168.1.20"] # the address you type on the phoneA tunnel
gio.toml
[dev]
allowed_hosts = ["*.trycloudflare.com"]An app that writes JSON files
gio.toml
[dev]
watch_ignore = ["data/**"] # lowdb, uploads, caches the app writesGood to know
- An
allowed_hostsentry opens the dev endpoints - project source included - to every client that can reach the port and sends that host. On an untrusted network, bind127.0.0.1instead. - A malformed
watch_ignorepattern (.., a backslash) stops startup. - Development always runs one render worker, whatever
[server] workerssays.
Not configurable
- open-in-editor stays same-origin and ignores
"*". It acceptsPOSTonly and refuses anything but a same-origin request (orSec-Fetch-Site: none), so a link or form on another site cannot launch your editor. A DNS-rebound page is same-origin with its ownHost, soallowed_hosts = ["*"]never covers it: open-in-editor answers only localhost hosts from this machine, a specific[server] hostand the hostsallowed_hostsnames explicitly (["*", "myvm.local"]). /_gio/devtools*is a404in production.
Related
Version history
| Version | Changes |
|---|---|
v0.1.0-beta.8 | Introduced with allowed_hosts (["*"] answers any host, with a warning), devtools, watch and watch_ignore. |