Skip to content

[Bug] normalizeServerUrl warns about plaintext HTTP for http://[::1] (IPv6 loopback) #1128

Description

@Ogstevyn

Surface

TypeScript SDK (@mysten-incubation/memwal)

Network

Mainnet (relayer.memory.walrus.xyz)

Package version

@mysten-incubation/memwal@0.1.8

What happened?

Creating a client with serverUrl "http://[::1]:8000" (a local relayer on IPv6 loopback) prints the plaintext-HTTP warning meant for remote hosts. http://localhost:8000 gives no warning, and the doc comment on normalizeServerUrl says ::1 is exempt.

Steps to reproduce

  1. MemWal.create({ key, accountId, serverUrl: "http://[::1]:8000" })
  2. Watch the console.

Repro script: https://github.com/Ogstevyn/octobot/blob/main/scripts/repro-memwal.ts (npm run repro, part 1, no account needed)

Expected

No warning, the same as for http://localhost:8000 and http://127.0.0.1:8000.

Actual

The plaintext-HTTP warning is printed for a loopback address.

Logs or error text

new URL("http://[::1]:8000").hostname = "[::1]"
[memwal] serverUrl "http://[::1]:8000" uses plaintext HTTP on a non-localhost host. Signed requests and any bearer material will be visible to the network. Use https:// in production.

Checks

  • I searched existing issues and this is not a duplicate.
  • This report contains no private keys, mnemonics, or other secrets.

Activity

  1. github-actions commented on Oct 7, 2026

    @github-actions

    Thank you for opening this issue, a team member will review it shortly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions