angular / angular/angular-cli

Can't use an array of hostnames in --allowedHosts cli parameter in @angular/build:dev-server

Open Beginner friendly
#33,955 0 comments 0 reactions 0 assignees View on GitHub
area: @angular/build gemini-triaged
Dominant language
TypeScript
Stars
27k
Forks
11.8k
Avg merge
14h 23m
Merged PRs (30d)
162

Description

### Command

serve

### Is this a regression?

- [ ] Yes, this behavior used to work in the previous version

### The previous version in which this bug was not present was

_No response_

### Description

When using `@angular-devkit/build-angular:dev-server` I can use `--allowedHosts` parameter with array of hostnames, so my hostnames can be dynamic.

But when using `@angular/build:dev-server` the array of names is not recognized (only boolean type is passed instead?)

```bash
ng serve myproject --allowed-hosts "example.com"
```
"**Error: Unknown argument: example.com**"

Workaround:

```bash
__VITE_ADDITIONAL_SERVER_ALLOWED_HOSTS=example.com ng serve myproject
```

or hard code in the array format in `angular.json` like mentioned in https://github.com/angular/angular/issues/64104

Comparing the two builder i can see this difference if you "patch" `@angular/build:dev-server`'s schema.json, then the command will work.

https://github.com/angular/angular-cli/blob/main/packages/angular_devkit/build_angular/src/builders/dev-server/schema.json
vs
https://github.com/angular/angular-cli/blob/main/packages/angular/build/src/builders/dev-server/schema.json

```diff
"allowedHosts": {
+ "type": "array",
"description": "The hosts that the development server will respond to. This option sets the Vite option of the same name. For further details: https://vite.dev/config/server-options.html#server-allowedhosts",
"default": [],
+ "items": {
+ "type": "string"
+ }
- "oneOf": [
- {
- "type": "array",
- "description": "A list of hosts that the development server will respond to.",
- "items": {
- "type": "string"
- }
- },
- {
- "type": "boolean",
- "description": "Indicates that all hosts are allowed. This is not recommended and a security risk."
- }
- ]
},
```

@see issue * PR for the devkit commit that added the option:
- https://github.com/angular/angular-cli/issues/13656
- https://github.com/angular/angular-cli/pull/15366

It note that `@angular-devkit/build-angular:dev-server` also has a (custom?) `--disableHostCheck` parameter which sets `allowedHosts` to `true` if passed, so then disable all hosts situation can be covered as schema no longer allows boolean, only array.

Not sure how to fix properly.

### Minimal Reproduction

-

### Exception or Error

```text

```

### Your Environment

```text
-
```

### Anything else relevant?

_No response_

Contributor guide

Open the contributing guide

Research direction

Compare packages/angular/build/src/builders/dev-server/schema.json with packages/angular_devkit/build_angular/src/builders/dev-server/schema.json, focusing on the allowedHosts definitions and related dev-server option handling. Confirm the intended compatibility with the existing disableHostCheck behavior, then verify that @angular/build:dev-server accepts an array of hostnames through the CLI without breaking the supported all-hosts option.

Written by the indexing model from the issue text.

Assessment

Tech stack
angular, typescript, vite
Domain
build-system, cli
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
74/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.