AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

NetworkHostname Should Be In AllowedDevOrigins By Default

Next.js 16.3.0-canary.97 dev server logs a Network URL that is immediately blocked for hot reload due to cross-origin restrictions because the resolved networkHostname is not included in the default allowedDevOrigins.

mediumConfidence 85%Next.jsAffected V16.3.0-Canary.97

Origin Analysis

The dev server security hardening in PR #91507 blocks cross-origin requests to dev resources and only allows origins in `allowedDevOrigins`. The default allowed origins do not include the automatically resolved `networkHostname`, while the startup log continues to display the network URL, creating a misleading user experience.
1. Create a default Next.js project without allowedDevOrigins config. 2. Run `next dev`. 3. Observe startup log shows both Local and Network URLs. 4. Open the Network URL in a browser. 5. Page fails to load and console shows 'Blocked cross-origin request to Next.js dev resource /_next/hmr'.

Fixing Code Block

// packages/next/src/server/lib/start-server.ts // After resolving networkHostname and before starting the server: const resolvedNetworkHostname = networkHostname // already computed above const defaultAllowedDevOrigins = [ 'localhost', '127.0.0.1', ...(resolvedNetworkHostname ? [resolvedNetworkHostname] : []), ] const allowedDevOrigins = Array.from( new Set([ ...defaultAllowedDevOrigins, ...(nextConfig.allowedDevOrigins ?? []), ]) )
The fix automatically includes the resolved network hostname in the default allowed dev origins, so the Network URL shown in the startup log works out of the box. The user-provided allowedDevOrigins are merged and deduplicated to preserve existing behavior.

Edge Case Audit

Automatically allowing the network hostname expands the cross-origin trust boundary to all devices on the local network. A malicious web page on the same LAN could potentially make requests to the dev server if it can guess the origin. To mitigate, keep the dev server bound to a trusted interface, or only enable this behavior when explicitly requested. Rollback: remove the automatic inclusion and require users to list networkHostname in allowedDevOrigins manually; also consider suppressing the network URL from the startup log when it will be blocked.

Ecosystem Topology