Skip to content

fix(browser)!: require sessionId for orchestrator html request#10522

Merged
sheremet-va merged 10 commits into
vitest-dev:mainfrom
hi-ogawa:harden-browser-orchestrator-session
Jun 8, 2026
Merged

fix(browser)!: require sessionId for orchestrator html request#10522
sheremet-va merged 10 commits into
vitest-dev:mainfrom
hi-ogawa:harden-browser-orchestrator-session

Conversation

@hi-ogawa

@hi-ogawa hi-ogawa commented Jun 5, 2026

Copy link
Copy Markdown
Collaborator

Description

Previously any request to /__vitest_test__ serves the same html as /__vitest_test__/?sessionId=... even though the direct request to /__vitest_test__ doesn't provide working browser mode experience. This PR changes to return 404 on /__vitest_test__ to reduce exposed API credentials surface.

TODO

  • doc

Please don't delete this checklist! Before submitting the PR, please make sure you do the following:

  • It's really useful if your PR references an issue where it is discussed ahead of time. If the feature is substantial or introduces breaking changes without a discussion, PR might be closed.
  • Ideally, include a test that fails without this PR but passes with it.
  • Please, don't make changes to pnpm-lock.yaml unless you introduce a new test example.
  • Please check Allow edits by maintainers to make review process faster. Note that this option is not available for repositories that are owned by Github organizations.

Tests

  • Run the tests with pnpm test:ci.

Documentation

  • If you introduce new functionality, document it. You can run documentation with pnpm run docs command.

Changesets

  • Changes in changelog are generated from PR name. Please, make sure that it explains your changes in an understandable manner. Please, prefix changeset messages with feat:, fix:, perf:, docs:, or chore:.

Comment thread packages/vitest/src/node/stdin.ts
@netlify

netlify Bot commented Jun 8, 2026

Copy link
Copy Markdown

Deploy Preview for vitest-dev ready!

Built without sensitive environment variables

Name Link
🔨 Latest commit 510d944
🔍 Latest deploy log https://app.netlify.com/projects/vitest-dev/deploys/6a263246cfa3dd0008c35391
😎 Deploy Preview https://deploy-preview-10522--vitest-dev.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@hi-ogawa
hi-ogawa marked this pull request as ready for review June 8, 2026 03:31
@sheremet-va
sheremet-va merged commit 79b7d8f into vitest-dev:main Jun 8, 2026
15 of 18 checks passed
@hi-ogawa
hi-ogawa deleted the harden-browser-orchestrator-session branch June 8, 2026 05:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Decide whether watch-mode b should be redesigned as a real browser-session shortcut or removed

2 participants