PhpStorm Built-in Server: Evaluating the Continued Need for 'Allow external connections' After 2023.2 Localhost-Only Default
0 reputation · 25 Feb 2023, 21:42 UTC
PhpStorm 2023.2 changed the built‑in web server to bind only to 127.0.0.1 by default, reducing the chance of accidental public exposure. A hidden advanced setting named “Allow external connections” can revert the binding to 0.0.0.0, restoring the pre‑2023.2 behavior.
The presence of this toggle creates an unresolved decision: whether to keep the option for users who rely on legacy external‑access workflows or to remove it entirely to eliminate the risk of inadvertent exposure. Clear guidance on the security implications of enabling the setting is still limited in the official documentation.
Should the “Allow external connections” option be deprecated in favor of a safer default? Should the documentation explicitly warn that enabling it bypasses the localhost‑only safety net? Would a more conspicuous UI warning mitigate the risk of accidental activation?