Surface
TypeScript SDK (@mysten-incubation/memwal)
Network
Mainnet (relayer.memory.walrus.xyz)
Package version
@mysten-incubation/memwal@0.1.8
What happened?
Creating a client with serverUrl "http://[::1]:8000" (a local relayer on IPv6 loopback) prints the plaintext-HTTP warning meant for remote hosts. http://localhost:8000 gives no warning, and the doc comment on normalizeServerUrl says ::1 is exempt.
Steps to reproduce
- MemWal.create({ key, accountId, serverUrl: "http://[::1]:8000" })
- Watch the console.
Repro script: https://github.com/Ogstevyn/octobot/blob/main/scripts/repro-memwal.ts (npm run repro, part 1, no account needed)
Expected
No warning, the same as for http://localhost:8000 and http://127.0.0.1:8000.
Actual
The plaintext-HTTP warning is printed for a loopback address.
Logs or error text
new URL("http://[::1]:8000").hostname = "[::1]"
[memwal] serverUrl "http://[::1]:8000" uses plaintext HTTP on a non-localhost host. Signed requests and any bearer material will be visible to the network. Use https:// in production.
Checks
Surface
TypeScript SDK (@mysten-incubation/memwal)
Network
Mainnet (relayer.memory.walrus.xyz)
Package version
@mysten-incubation/memwal@0.1.8
What happened?
Creating a client with serverUrl "http://[::1]:8000" (a local relayer on IPv6 loopback) prints the plaintext-HTTP warning meant for remote hosts. http://localhost:8000 gives no warning, and the doc comment on normalizeServerUrl says ::1 is exempt.
Steps to reproduce
Repro script: https://github.com/Ogstevyn/octobot/blob/main/scripts/repro-memwal.ts (npm run repro, part 1, no account needed)
Expected
No warning, the same as for http://localhost:8000 and http://127.0.0.1:8000.
Actual
The plaintext-HTTP warning is printed for a loopback address.
Logs or error text
Checks