Debugger listening on 0.0.0.0:9229 when using nodemon --inspect
29K reputation · 14 Jun 2024, 01:15 UTC
When nodemon is started with the --inspect flag (or --inspect-brk) without an explicit host, it forwards the flag unchanged to the underlying Node.js process. Node.js then binds the debugger to 0.0.0.0:, exposing the debugging interface on all network interfaces. The goal is to prevent accidental exposure of the debugger in environments where the host is reachable from untrusted networks while preserving the ability to inspect the application during development.
However, nodemon currently does not enforce localhost binding for inspector flags, and the project has not reached a consensus on changing this default behavior. Users must manually specify a host (e.g., --inspect=127.0.0.1:9229) or configure it via nodemon.json to mitigate the risk. This leaves an unresolved decision about whether nodemon should automatically bind the inspector to localhost when no host is provided.
Should nodemon automatically bind the inspector to localhost when no host is specified in the --inspect flag?
What impact would changing the default binding have on existing development workflows that rely on remote debugging?
Could a configuration option be added to nodemon.json to enforce localhost binding without breaking backward compatibility?
1 answer
0 question comments
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.