@alisio/server
v0.4.4
Published
Local HTTP + SSE server behind `alisio serve`: multi-workspace, multi-session web access to the Alisio agent core with a launch-token cookie, strict Host/Origin checks and fail-closed approvals. node:http only; runs on Node >=22.16 and Bun.
Maintainers
Readme
@alisio/server
The local HTTP + SSE server behind alisio serve. It gives a browser multi-workspace,
multi-session access to the Alisio agent core.
What it is
node:httponly (no web framework, no WebSocket): JSON routes under/apiand one multiplexed Server-Sent Events stream per browser tab (GET /api/events).- One
@alisio/coreApplicationper open workspace, created lazily and evicted when idle. - Local security model: binds
127.0.0.1by default, a per-process launch token exchanged for anHttpOnly; SameSite=Strictcookie, strictHost/Originchecks, a strict CSP and fail-closed approvals (no answer means deny). - Runs on Node.js >= 22.16 and on Bun, with portable Node APIs only.
The CLI loads it with a dynamic import("@alisio/server") inside alisio serve, so alisio,
alisio run and the TUI never load it.
Usage
Most people run it through the CLI:
alisio serve # prints http://127.0.0.1:4317/?token=… and opens the browser
alisio serve --no-open --port 0 --allow-writeEmbedding it directly:
import { startServer } from "@alisio/server";
const server = await startServer({ port: 0, app: { allowWrite: true } });
console.log(server.launchUrl);
// …
await server.close();Plugins are not sandboxed: a trusted project's plugins run inside the server process with its
operating-system permissions. Remote access (--host other than loopback) requires
--allow-remote and has no TLS; prefer an SSH tunnel.
Documentation: https://gustavogutierrez.github.io/alisio/web.
License
MIT
