Alexandro.Net

Version 1.0.0

@stackline/http-server

A simple zero-configuration command-line http server

Independent maintenance of http-server 14.1.1. Original authors and licenses are retained.

Installation

# Preserve existing imports with an npm alias
npm install http-server@npm:@stackline/http-server@1.0.0
# Or use the scoped package name in your imports
npm install @stackline/http-server@1.0.0

Node.js: >=12. Read the compatibility and maintenance notes before migrating.

Usage and API

The reference below may retain upstream package names. Use the alias installation above to run those imports with this Stackline release.

@stackline/http-server

Independent maintenance fork of http-server@14.1.1, preserving its API and published type declarations.

npm install @stackline/http-server
# Keep existing imports:
npm install http-server@npm:@stackline/http-server@1.0.0

Stackline · Issues · Community

See UPSTREAM.md for source identity and issue review, and CHANGELOG.md for maintenance changes. Functional tests also run against the final npm tarball; releases are published from GitHub Actions with provenance.

Upstream documentation

GitHub Workflow Status (master) npm homebrew npm downloads license

http-server: a simple static HTTP server

http-server is a simple, zero-configuration command-line static HTTP server. It is powerful enough for production usage, but it's simple and hackable enough to be used for testing, local development and learning.

Example of running http-server

Installation:

Running on-demand:

Using npx you can run the script without installing it first:

npx http-server [path] [options]

Globally via npm

npm install --global http-server

This will install http-server globally so that it may be run from the command line anywhere.

Globally via Homebrew

brew install http-server
 

As a dependency in your npm package:

npm install http-server

Usage:

 http-server [path] [options]

[path] defaults to ./public if the folder exists, and ./ otherwise.

Now you can visit http://localhost:8080 to view your server

Note: Caching is on by default. Add -c-1 as an option to disable caching.

Available Options:

Command Description Defaults
-p or --port Port to use. Use -p 0 to look for an open port, starting at 8080. It will also read from process.env.PORT. 8080
-a Address to use 0.0.0.0
-d Show directory listings true
-i Display autoIndex true
-g or --gzip When enabled it will serve ./public/some-file.js.gz in place of ./public/some-file.js when a gzipped version of the file exists and the request accepts gzip encoding. If brotli is also enabled, it will try to serve brotli first. false
-b or --brotli When enabled it will serve ./public/some-file.js.br in place of ./public/some-file.js when a brotli compressed version of the file exists and the request accepts br encoding. If gzip is also enabled, it will try to serve brotli first. false
-e or --ext Default file extension if none supplied html
-s or --silent Suppress log messages from output
--cors Enable CORS via the Access-Control-Allow-Origin header
-o [path] Open browser window after starting the server. Optionally provide a URL path to open. e.g.: -o /other/dir/
-c Set cache time (in seconds) for cache-control max-age header, e.g. -c10 for 10 seconds. To disable caching, use -c-1. 3600
-U or --utc Use UTC time format in log messages.
--log-ip Enable logging of the client's IP address false
-P or --proxy Proxies all requests which can't be resolved locally to the given url. e.g.: -P http://someurl.com
--proxy-options Pass proxy options using nested dotted objects. e.g.: --proxy-options.secure false
--username Username for basic authentication
--password Password for basic authentication
-S, --tls or --ssl Enable secure request serving with TLS/SSL (HTTPS) false
-C or --cert Path to ssl cert file cert.pem
-K or --key Path to ssl key file key.pem
-r or --robots Automatically provide a /robots.txt (The content of which defaults to User-agent: *\nDisallow: /) false
--no-dotfiles Do not show dotfiles
--mimetypes Path to a .types file for custom mimetype definition
-h or --help Print this list and exit.
-v or --version Print the version and exit.

Magic Files

Catch-all redirect

To implement a catch-all redirect, use the index page itself as the proxy with:

http-server --proxy http://localhost:8080?

Note the ? at the end of the proxy URL. Thanks to @houston3 for this clever hack!

TLS/SSL

First, you need to make sure that openssl is installed correctly, and you have key.pem and cert.pem files. You can generate them using this command:

openssl req -newkey rsa:2048 -new -nodes -x509 -days 3650 -keyout key.pem -out cert.pem

You will be prompted with a few questions after entering the command. Use 127.0.0.1 as value for Common name if you want to be able to install the certificate in your OS's root certificate store or browser so that it is trusted.

This generates a cert-key pair and it will be valid for 3650 days (about 10 years).

Then you need to run the server with -S for enabling SSL and -C for your certificate file.

http-server -S -C cert.pem

If you wish to use a passphrase with your private key you can include one in the openssl command via the -passout parameter (using password of foobar)

e.g. openssl req -newkey rsa:2048 -passout pass:foobar -keyout key.pem -x509 -days 365 -out cert.pem

For security reasons, the passphrase will only be read from the NODE_HTTP_SERVER_SSL_PASSPHRASE environment variable.

This is what should be output if successful:

Starting up http-server, serving ./ through https

http-server settings:
CORS: disabled
Cache: 3600 seconds
Connection Timeout: 120 seconds
Directory Listings: visible
AutoIndex: visible
Serve GZIP Files: false
Serve Brotli Files: false
Default File Extension: none

Available on:
  https://127.0.0.1:8080
  https://192.168.1.101:8080
  https://192.168.1.104:8080
Hit CTRL-C to stop the server

Development

Checkout this repository locally, then:

$ npm i
$ npm start

Now you can visit http://localhost:8080 to view your server

You should see the turtle image in the screenshot above hosted at that URL. See the ./public folder for demo content.

Upstream issues and maintenance review

Upstream review

Independent maintenance of http-server14.1.1. Source https://github.com/http-party/http-server/tree/af0ac3e4b9bd5fff55337aee32bf37f6116c7b4f

Original published files and SHA-256 hashes are recorded in .stackline/upstream.json. The parser/server API, CLI name, license, original authors and Node >=12 declaration are retained. Development/release tests use Node24.

Issue evidence collected: 2026-09-29T00:24:08.203209+00:00. The latest100 open and30 closed entries were collected, then pull requests filtered. The following table records all71 open issue entries returned; it is not a claim that every issue was reproduced or fixed.

Issue Finding
#965 Configurable changeOrigin in websocket listener? Recorded open report; not reproduced or claimed fixed in this release.
#977 update html-encoding-sniffer to v5+ Recorded open report; not reproduced or claimed fixed in this release.
#973 Transitive deprecated dependencies Transitive maintenance/deprecation concerns are recorded separately; the current task does not authorize recursive forks.
#976 New chet Recorded open report; not reproduced or claimed fixed in this release.
#975 Dreams local boy Recorded open report; not reproduced or claimed fixed in this release.
#483 Remove flatiron/union dependency Removing union is an architectural migration; current middleware/API behavior is retained.
#972 Reporting a new security vulnerability in http-server stable version The report intentionally contains no vulnerability details. It cannot be reproduced from the public report; no fix or security completeness is claimed.
#636 Proxy causing infinite loop Reproduced a self-proxy cycle under a64MB heap limit; fixed loop detection and retained responsiveness regression.
#947 Create Release Branches for 14.1.2, 14.2.0, and 15.0.0 Recorded open report; not reproduced or claimed fixed in this release.
#928 Adding flags is very WET right now Recorded open report; not reproduced or claimed fixed in this release.
#969 [BUG] Attempted to assign to readonly property. Report uses Bun1.3.11 and an inherited union implementation. Bun support is not claimed; the declared Node runtime suite is retained.
#799 [DEP0066] DeprecationWarning: OutgoingMessage.prototype._headers is deprecated Recorded open report; not reproduced or claimed fixed in this release.
#809 Customize access-control-allow-origin headers in order to set specific origin domains Recorded open report; not reproduced or claimed fixed in this release.
#814 Fallback proxy doesn't work on Node v17+ Report shows localhost resolving to IPv6 while the target listens on IPv4. Configure an explicit matching address such as127.0.0.1; global DNS behavior is not changed.
#873 Add bandwidth limit parameter Recorded open report; not reproduced or claimed fixed in this release.
#525 ERR_INVALID_REDIRECT when running http-server Recorded open report; not reproduced or claimed fixed in this release.
#537 DeprecationWarning for OutgoingMessage.prototype._headers Recorded open report; not reproduced or claimed fixed in this release.
#771 only partially follows range spec Multipart byte ranges remain an existing limitation; this release does not claim multipart support.
#360 Add .headers support Recorded open report; not reproduced or claimed fixed in this release.
#526 [FEATURE REQUEST] Add option to sort by date Recorded open report; not reproduced or claimed fixed in this release.
#668 Invalid SSL certificate Recorded open report; not reproduced or claimed fixed in this release.
#644 Setting CSP Recorded open report; not reproduced or claimed fixed in this release.
#859 How to let the json file (*.json) return response header: 'application/json', instead of 'application/json; charset=UTF-8' Recorded open report; not reproduced or claimed fixed in this release.
#849 404 error on the page with param Recorded open report; not reproduced or claimed fixed in this release.
#854 Do not open a new browser window if one is already open Recorded open report; not reproduced or claimed fixed in this release.
#851 Proxy target request header not present Recorded open report; not reproduced or claimed fixed in this release.
#629 Serve file with default ext is same name dir cannot be shown Recorded open report; not reproduced or claimed fixed in this release.
#729 Mirror domain in Access-Control-Allow-Origin header Recorded open report; not reproduced or claimed fixed in this release.
#756 Error: Cannot set headers after they are sent to client, occurs when trying to serve index.html, only occurs in v14.0.0 Recorded open report; not reproduced or claimed fixed in this release.
#825 robots.txt flag is not working Reproduced literal true response; fixed boolean-string handling with HTTP regression.
#678 As a user I would like the ability to specify the default landing page / 404 page / magic pages Recorded open report; not reproduced or claimed fixed in this release.
#761 Node 17 broke the catch all Same IPv4/IPv6 localhost mismatch as814; no global DNS override introduced.
#821 Receives SIGTERM during "DDoS" Recorded open report; not reproduced or claimed fixed in this release.
#820 Bypass etc/hosts for virtual domains Recorded open report; not reproduced or claimed fixed in this release.
#777 Add support for DuckDNS Recorded open report; not reproduced or claimed fixed in this release.
#757 Proxy ? based powerful attack on http-server caught in wild. Can force out of memory The same bounded reproduction exhausted the isolated heap before the fix. Cyclic forwarding now terminates with508, with at most16 forwarding hops.
#812 localhost:4664 not sending data Recorded open report; not reproduced or claimed fixed in this release.
#336 http2 Recorded open report; not reproduced or claimed fixed in this release.
#807 How to serve build with homepage property set? Recorded open report; not reproduced or claimed fixed in this release.
#634 Server Crashing with "Cannot set headers after they are sent to the client" Recorded open report; not reproduced or claimed fixed in this release.
#805 Cannot set headers after they are sent to the client Recorded open report; not reproduced or claimed fixed in this release.
#802 http-server doesn't exit and hold on listening port Recorded open report; not reproduced or claimed fixed in this release.
#798 Allow downloading directory as archive Recorded open report; not reproduced or claimed fixed in this release.
#718 reported 2 issues during file rendering Recorded open report; not reproduced or claimed fixed in this release.
#768 Should Read PORT property from process.env.PORT Recorded open report; not reproduced or claimed fixed in this release.
#641 Support HTTP/2? Recorded open report; not reproduced or claimed fixed in this release.
#670 When using https display https://common_name:8080/ as one of the valid hostnames Recorded open report; not reproduced or claimed fixed in this release.
#665 The server has no method of dealing with global exceptions. Recorded open report; not reproduced or claimed fixed in this release.
#762 Option to use devcert for local development SSL Recorded open report; not reproduced or claimed fixed in this release.
#766 Support beautiful file/folder icon Recorded open report; not reproduced or claimed fixed in this release.
#724 http-server dockerized Recorded open report; not reproduced or claimed fixed in this release.
#770 Allow reading a javascript file for configuration defaults Recorded open report; not reproduced or claimed fixed in this release.
#723 Intermittent test failures Recorded open report; not reproduced or claimed fixed in this release.
#652 Request proxying of custom HTTP headers Recorded open report; not reproduced or claimed fixed in this release.
#684 Is there a way to set the Access-Control-Allow-Methods header? Recorded open report; not reproduced or claimed fixed in this release.
#380 Feature: Do not cache local, but cache remote files (option) Recorded open report; not reproduced or claimed fixed in this release.
#545 Add support for 'Access-Control-Expose-Headers' using --cors Recorded open report; not reproduced or claimed fixed in this release.
#506 Some directories are not shown Recorded open report; not reproduced or claimed fixed in this release.
#509 Server side caching Recorded open report; not reproduced or claimed fixed in this release.
#630 [Feature] Lack of excluding files / pointing target folder to serve. Recorded open report; not reproduced or claimed fixed in this release.
#273 SLL mode does not serve HTTP request Recorded open report; not reproduced or claimed fixed in this release.
#280 Is it possible to proxy some url to other server not all url. Recorded open report; not reproduced or claimed fixed in this release.
#539 Trailing slash when serving directory index.html Recorded open report; not reproduced or claimed fixed in this release.
#623 html documents served are downloaded Recorded open report; not reproduced or claimed fixed in this release.
#632 Unable to close port 7010 Recorded open report; not reproduced or claimed fixed in this release.
#138 Memory leak on large files with streaming middleware union Recorded open report; not reproduced or claimed fixed in this release.
#467 More logging options Recorded open report; not reproduced or claimed fixed in this release.
#263 HTTP 400 response with body "URI Error: URI malformed" when requesting an URL with a ISO-8859-1 encoding Recorded open report; not reproduced or claimed fixed in this release.
#487 Add option to disable unsafe TLS v1 protocol Recorded open report; not reproduced or claimed fixed in this release.
#155 Support for CA bundles? Recorded open report; not reproduced or claimed fixed in this release.
#396 Support HTTP PUT requests via a flag Recorded open report; not reproduced or claimed fixed in this release.

Validation

All31 original test files run with maintained Tap and a compatible maintained Request client. Removed Tap method aliases are updated and the HTTP test client disables connection pooling to avoid reusing closed fixture servers. The source and extracted final package run the original suite and focused HTTP regressions. Runtime and full workspace audits must report zero findings.

Release completion requires the exact CI tarball, successful CodeQL with zero open alerts, npm provenance/identity, direct and alias consumers, and identical immutable release assets.

Security review after CodeQL

The CORS parser, directory boundary and directory redirect have focused fixes and real HTTP regressions. Remaining scanner findings and the trusted-root/symlink boundary are explained in CODEQL_REVIEW.md. Runtime remains fully scanned; this is not a physical filesystem sandbox.

Dependency scope qualification

The compatible html-encoding-sniffer3 runtime branch inherits the deprecated whatwg-encoding2 package. Newer sniffer majors increase the minimum Node version; this release retains Node12 compatibility. The warning is recorded in consumer evidence, with zero known vulnerability findings and valid dependency trees. This is a direct-parent migration, not an unrestricted recursive-maintenance policy pass.

Security review

Directory and redirect CodeQL review

Reviewed against commit d0cb8dd9c9fc81b61a144e684da9daa5cb0ab1a5 and the subsequent regression suite.

The CORS regular-expression backtracking issue is fixed by splitting on literal commas and trimming each field. The original protocol-relative directory redirect is fixed by constructing a single-rooted location and escaping backslashes.

Remaining alerts 2, 3 and 4 (path-injection) cross the explicit containment guard in lib/core/show-dir/index.js. The path is decoded and normalized before requiring equality with the configured root or its separator-delimited prefix. Root-prefix siblings and malformed escapes are tested. Child names passed to sort-files come from fs.readdir, not a user-supplied list. These flows are false positives for lexical directory traversal after the guard.

This preserves upstream behavior that follows filesystem symlinks placed by the operator. The configured root and its symlinks are trusted configuration; the server is not a realpath sandbox or a defense against concurrent filesystem modifications by another local actor.

Alert 6 (unvalidated redirect) crosses a location constructor that prepends one slash, removes all leading slash/backslash characters, and percent-encodes other backslashes. Real HTTP regressions cover protocol-relative paths, escapes, control characters and hostile query values; every emitted redirect remains on the current origin. This remaining finding is a false positive for an external redirect after the fix.

All runtime remains analyzed. No CodeQL query or path is disabled. Full upstream tests, extracted-package tests, targeted security regressions and zero-advisory source/runtime audits are required before publication. A second read-only review independently checked the containment and redirect construction.

Release changes

Changelog

1.0.0

Release files and references

Package bytes, npm provenance and the immutable GitHub release were verified for this version. Security checks describe the reviewed release; documented compatibility risks and upstream reports are not blanket claims of resolution.