{"_id":"@banshanyanyu/local-html-preview","name":"@banshanyanyu/local-html-preview","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@banshanyanyu/local-html-preview","version":"1.0.0","description":"Preview local HTML files through a small Express-powered CLI.","main":"src/server.js","bin":{"local-html-preview":"bin/local-html-preview.js"},"scripts":{"start":"node ./bin/local-html-preview.js","pack:check":"npm pack --dry-run"},"publishConfig":{"access":"public"},"keywords":["html","preview","local","cli"],"engines":{"node":">=20"},"dependencies":{"commander":"^12.1.0","express":"^4.21.2"},"_id":"@banshanyanyu/local-html-preview@1.0.0","gitHead":"a1696c30384423ebfdb75db9fbc0d38686ac1027","_nodeVersion":"20.20.0","_npmVersion":"10.8.2","dist":{"integrity":"sha512-bdtL9wSr8Q/8OD5HcBo5Dy79v6902gudAqwgo6XbcDEyYJrls2g0eRNM1ILuybkIoGZiFW1I0HS8wvL4hak0yg==","shasum":"49685470689308e550b13f28dccfb739f909ef0c","tarball":"https://registry.npmjs.org/@banshanyanyu/local-html-preview/-/local-html-preview-1.0.0.tgz","fileCount":11,"unpackedSize":36005,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDzByQexy8azRF58x7pkCw+YzCQZSQM97fpjKBY+My56AIgXgkuntifpVZLCRA15LO3HO20DGOVBI35kNKzcuAw0G0="}]},"_npmUser":{"name":"banshanyanyu","email":"banshanyanyu@gmail.com"},"directories":{},"maintainers":[{"name":"banshanyanyu","email":"banshanyanyu@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/local-html-preview_1.0.0_1780028653102_0.9334109583276546"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-29T04:24:12.959Z","1.0.0":"2026-05-29T04:24:13.234Z","modified":"2026-05-29T04:24:13.414Z"},"maintainers":[{"name":"banshanyanyu","email":"banshanyanyu@gmail.com"}],"description":"Preview local HTML files through a small Express-powered CLI.","keywords":["html","preview","local","cli"],"readme":"# Local HTML Preview\n\nLocal HTML Preview is a small Node.js CLI for browsing and previewing HTML files from a local directory.\n\n## Requirements\n\n- Node.js 20+\n- npm\n\n## Install\n\n```bash\nnpm install -g @banshanyanyu/local-html-preview\n```\n\n## Usage\n\n```bash\nlocal-html-preview <directory>\n```\n\nExample:\n\n```bash\nlocal-html-preview ~/Desktop/htmls\nlocal-html-preview ~/Desktop/htmls --port 4567 --open\nlocal-html-preview ~/Desktop/htmls --username admin --password secret\n```\n\nThe server opens the browser by default and serves the preview at:\n\n```text\nhttp://localhost:4567\n```\n\n## Behavior\n\n- `GET /api/files` rescans the target directory on every request.\n- Only `.html` and `.htm` files are shown in the left file list.\n- Each page has an independent URL such as `/view/index.html` or `/view/docs/demo.html`.\n- The right preview pane uses an iframe that loads `/raw/<filepath>`.\n- Files outside the selected root directory are blocked.\n\n## Authentication\n\nAuthentication is optional. If `--username` and `--password` are not provided, the preview server is open.\n\n```bash\nlocal-html-preview ./demo --username admin --password secret\n```\n\nWhen authentication is enabled, all preview pages, APIs, static assets, and raw files require login.\n\nThe login page encrypts the password before submitting it. The browser derives an AES-GCM key from the username and the current timestamp, then sends `username`, `timestamp`, `iv`, and `encryptedPassword`. The server derives the same key from the uploaded timestamp, decrypts the password, validates it, and stores the login state in an HttpOnly session cookie.\n\nFor public internet exposure, run the server behind HTTPS or a trusted reverse proxy. Timestamp-based password encryption avoids sending the password as plain text, but it is still not a replacement for HTTPS because session cookies and page content can still be intercepted on plain HTTP.\n\n## Development Check\n\nCreate a demo directory:\n\n```text\ndemo/\n├── index.html\n├── a.html\n└── docs/\n    └── b.html\n```\n\nRun:\n\n```bash\nlocal-html-preview demo --open\n```\n\nThen verify file switching, browser back/forward, refresh behavior, dynamic file changes, and blocked traversal paths such as `/raw/../../etc/passwd`.\n\n## Publish\n\nThis package is configured as a public scoped npm package:\n\n```bash\nnpm login\nnpm run pack:check\nnpm publish\n```\n\nFor the first publish of a scoped package, `publishConfig.access` keeps it public so other users can install it with `npm install -g @banshanyanyu/local-html-preview`.\n","readmeFilename":"README.md","_rev":"1-e196d0dbad0f5be4300d5632735bf2e5"}