Skip to content

fix(devtools-bundler-core): open source files outside cwd and end bad open-source requests - #541

Open
AlemTuzlak wants to merge 1 commit into
mainfrom
fix/open-source-path-outside-cwd
Open

AlemTuzlak wants to merge 1 commit into
mainfrom
fix/open-source-path-outside-cwd

Conversation

@AlemTuzlak

@AlemTuzlak AlemTuzlak commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

"Go to Source" opens a wrong path when the source file is outside the current working directory, for example in a monorepo package or when Vite runs from another directory. This PR makes the open-source handler keep the absolute path of such files. It also answers 400 for a bad source, so the request no longer stays pending.

🎯 Changes

  • addSourceToJsx strips process.cwd() from the module path. A file outside cwd keeps its absolute path, and the handler then added cwd again: /repo/apps/web/repo/packages/pkg/src/panel.tsx.
  • The handler now uses the absolute path when the cwd-relative file does not exist and the absolute file does. Files inside cwd resolve as before.
  • A missing or malformed source returned without res.end(), so the request stayed pending until the browser timed out (the server part of Click-to-source sends empty source= and hangs because setDisabledAfterClick(true) runs before reading highlightState.dataSource #451). It now answers 400.
  • The Vite and Rspack plugins both use this shared handler.

✅ Checklist

  • I have followed the steps in the Contributing guide.
  • I have tested code changes locally with pnpm test:pr, or these tests do not apply to this pull request.
  • I fully understand the code in this pull request, including any code generated with AI assistance.

🚀 Release Impact

  • This change affects published code, and I have generated a changeset.
  • This change is docs/CI/dev-only (no release).

Testing

Commands run

  • vitest run in packages/devtools-bundler-core: 200 tests pass. The 3 new and updated tests failed before the fix.
  • eslint, tsc, and prettier --check on the changed files: pass.
  • I did not run the full pnpm test:pr.

Manual test

  1. In a monorepo, run Vite from apps/web and render a component from packages/pkg. Or use the StackBlitz repro in Click-to-code does not work when command run from different directory #281.
  2. Before this fix: click-to-source on that component sends a path with cwd added twice, and the editor opens an empty file.
  3. After this fix: the editor opens packages/pkg/src/... at the right line.
  4. Open /__tsd/open-source?source= in the browser. Before: pending forever. After: 400.

How this PR makes testing easy

Unit tests in utils.test.ts cover a file outside cwd (the repo root package.json) and the 400 answers.

Linked issues

Fixes #281
Fixes #176
Refs #451 (the client part of #451 was fixed in @tanstack/devtools@0.12.3)

Risk / rollback

Low. If both the cwd-relative path and the absolute path exist, the cwd-relative path wins, as before. To undo, revert this PR.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes
    • “Go to Source” now handles files outside the current working directory correctly.
    • Requests with missing or invalid source paths now receive an HTTP 400 response instead of remaining pending.

… open-source requests

addSourceToJsx strips cwd from the module path. A file outside cwd (a
monorepo package, or Vite run from another directory) keeps its absolute
path, and the open-source handler then prefixed cwd again. The editor got
paths like /repo/apps/web/repo/packages/pkg/src/panel.tsx.

The handler now uses the absolute path when the cwd-relative file does not
exist and the absolute one does.

A missing or malformed `source` returned without ending the response, so the
request stayed pending until the browser timed out. It now answers 400.

Fixes #281
Fixes #176
Refs #451
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: TanStack/devtools/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: e3cd093d-ff24-48b9-b20c-0e76ac59ce84

📥 Commits

Reviewing files that changed from the base of the PR and between afa01fe and 32e150a.

📒 Files selected for processing (3)
  • .changeset/open-source-outside-cwd.md
  • packages/devtools-bundler-core/src/utils.test.ts
  • packages/devtools-bundler-core/src/utils.ts

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The handler now preserves applicable source paths outside the current working directory and returns a completed HTTP 400 response when the source value is missing or malformed.

Changes

Source request handling

Layer / File(s) Summary
Invalid source responses
packages/devtools-bundler-core/src/utils.ts, packages/devtools-bundler-core/src/utils.test.ts
Missing or malformed source values now produce a 400 response that ends. Tests verify that no callback or next() call occurs.
Open-source path resolution
packages/devtools-bundler-core/src/utils.ts, packages/devtools-bundler-core/src/utils.test.ts, .changeset/open-source-outside-cwd.md
Open-source paths use resolveSourceFile. A test verifies that an absolute path outside the current working directory is preserved. The changeset records patch releases for three packages.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix · Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to 32e15

The changes are mergeable. A pre-existing click-to-code edge case remains when an external directory’s name begins with the working directory’s name.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 32e15

The fix supports source files outside the working directory and completes invalid requests. The previous implementation already allowed paths outside that directory, so the change does not establish a new maximum file-access scope. Risk remains dependent on who can reach the development server and the controls surrounding it.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — If an untrusted caller can reach this middleware, the relevant scope is the development host's configured editor action, including paths outside cwd. Effective network exposure is unresolved. The inspected change does not demonstrate file-content disclosure, arbitrary command execution, or newly elevated privileges.

Security Findings and Attack Paths

  • inferred — Direct absolute-path selection is new, but outside-cwd editor targeting is not: the base accepted traversal-style query paths and also forwarded arbitrary parsed JSON to the source callback. This counterevidence prevents treating the absolute-path fallback alone as a newly introduced arbitrary-file boundary bypass.

Trust Boundaries and Controls

  • observed — The inspected handler and plugin callbacks do not authenticate the source request or enforce host, origin, or source-root restrictions. Development gating and syntax validation are present. This local control arrangement predates the PR; restrictions inherited from the surrounding servers were not established.

Hardening Proposals

  • proposed — As separate hardening, consider a consistent caller-authorization and configured source-root policy across both query and JSON editor-request paths. Any root policy should accommodate intentional monorepo sources outside cwd rather than treating cwd as the only allowed root.
🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Out of Scope Changes check ⚠️ Warning The new HTTP 400 response for missing or malformed source requests is not connected to the coding objectives in [#281] or [#176]. Those issues require correct source-path resolution. The PR adds imp… Remove the unrelated missing or malformed source validation and its tests, or link an active issue that requires this behavior.
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (1 skipped: 1 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes both primary changes: preserving source paths outside the current working directory and ending invalid open-source requests.
Description check ✅ Passed The description includes the required Changes, Checklist, Release Impact, testing, linked issues, and rollback information. It clearly explains the motivation and implementation. The full pnpm test:pr…
Linked Issues check ✅ Passed The shared resolveSourceFile logic addresses both path issues [#281] [#176]. It uses the cwd-relative path when that path exists. It preserves an existing absolute path when the cwd-prefixed path do…
Full details: Out of Scope Changes check

Explanation

The new HTTP 400 response for missing or malformed source requests is not connected to the coding objectives in [#281] or [#176]. Those issues require correct source-path resolution. The PR adds implementation and tests for request validation and response termination. The #451 reference does not establish linked scope.

Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@nx-cloud

nx-cloud Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

View your CI Pipeline Execution ↗ for commit 32e150a

Command Status Duration Result
nx run-many --target=test:e2e --parallel=1 --pr... ✅ Succeeded 1m 13s View ↗
nx affected --targets=test:eslint,test:sherif,t... ✅ Succeeded 58s View ↗
nx run-many --targets=build --exclude=examples/... ✅ Succeeded 8s View ↗

☁️ Nx Cloud last updated this comment at 2026-10-02 13:17:45 UTC

@pkg-pr-new

pkg-pr-new Bot commented Oct 2, 2026

Copy link
Copy Markdown
More templates

@tanstack/angular-devtools

npm i https://pkg.pr.new/@tanstack/angular-devtools@541

@tanstack/devtools

npm i https://pkg.pr.new/@tanstack/devtools@541

@tanstack/devtools-a11y

npm i https://pkg.pr.new/@tanstack/devtools-a11y@541

@tanstack/devtools-bundler-core

npm i https://pkg.pr.new/@tanstack/devtools-bundler-core@541

@tanstack/devtools-client

npm i https://pkg.pr.new/@tanstack/devtools-client@541

@tanstack/devtools-rspack

npm i https://pkg.pr.new/@tanstack/devtools-rspack@541

@tanstack/devtools-ui

npm i https://pkg.pr.new/@tanstack/devtools-ui@541

@tanstack/devtools-utils

npm i https://pkg.pr.new/@tanstack/devtools-utils@541

@tanstack/devtools-vite

npm i https://pkg.pr.new/@tanstack/devtools-vite@541

@tanstack/devtools-webmcp

npm i https://pkg.pr.new/@tanstack/devtools-webmcp@541

@tanstack/devtools-event-bus

npm i https://pkg.pr.new/@tanstack/devtools-event-bus@541

@tanstack/devtools-event-client

npm i https://pkg.pr.new/@tanstack/devtools-event-client@541

@tanstack/preact-devtools

npm i https://pkg.pr.new/@tanstack/preact-devtools@541

@tanstack/react-devtools

npm i https://pkg.pr.new/@tanstack/react-devtools@541

@tanstack/solid-devtools

npm i https://pkg.pr.new/@tanstack/solid-devtools@541

@tanstack/svelte-devtools

npm i https://pkg.pr.new/@tanstack/svelte-devtools@541

@tanstack/vue-devtools

npm i https://pkg.pr.new/@tanstack/vue-devtools@541

commit: 32e150a

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Click-to-code does not work when command run from different directory Go to source feature not working on Linux

1 participant