@volter/supercode-remote-access
v0.2.6
Published
Optional remote-access lifecycle and tunnel-provider adapter for Volter Harness frontends
Readme
@volter/supercode-remote-access
Optional remote-access lifecycle for Volter Harness-powered frontends. The package exposes a loopback web origin through one of three transports and reports a UI-ready, provider-neutral snapshot:
- a configured stable
@volter/tunnelrelay; - a zero-account Cloudflare Quick Tunnel;
- an already-authenticated ngrok installation.
It does not serve an application or choose cookies, passcodes, HTTP routes, or WebSocket policy. The host product owns those surfaces. The package does provide the security-sensitive reusable primitives underneath them: digest-only single-use pairing grants, bounded expiring device-session tokens, and browser-safe validation for device snapshots and pairing handoffs. This keeps Volter Harness's session glue independent from HTTP frameworks while preventing each frontend from reimplementing replay and expiry rules.
Browser bundles import validation helpers only from
@volter/supercode-remote-access/client; that entry point has no process, filesystem, or
tunnel-provider imports.
import { createRemoteAccessController } from "@volter/supercode-remote-access";
const remote = createRemoteAccessController({
localOrigin: "http://127.0.0.1:43123",
publicPath: "/",
tunnelId: "my-supercode-ui",
});
remote.subscribe((snapshot) => renderRemoteAccess(snapshot));
await remote.configure({ enabled: true, provider: "auto" });Automatic mode prefers the stable relay, then Cloudflare, then ngrok. Temporary providers never
initiate sign-in or configuration flows. Logs contain provider process output and are written with
user-only permissions under ~/.supercode/logs by default.
The default origin policy remains loopback-only. Hosts with a server bound to a
machine-specific network interface may opt into originPolicy: "local-interface".
On each enable/reconnect, every DNS answer must be loopback or an address on this
machine; the selected numeric address is then pinned before starting a tunnel.
Arbitrary private-network targets, HTTPS targets, and URL credentials are not
accepted. Disable/close invalidates an in-flight lookup before any provider starts.
The built-in stable relay has a narrower target contract: its SDK accepts only a
port and selects a listening 127.0.0.1/::1 endpoint. It therefore refuses other
interface targets; use Cloudflare/ngrok for those. Numeric target pinning does not
replace the stable SDK's existing loopback-family autodetection.
