{"_id":"@emdzej/stm-tunnel","_rev":"2-2feda0a053cfbd87fa0c30d3d584d2ee","name":"@emdzej/stm-tunnel","dist-tags":{"latest":"0.3.0"},"versions":{"0.1.0":{"name":"@emdzej/stm-tunnel","version":"0.1.0","_id":"@emdzej/stm-tunnel@0.1.0","maintainers":[{"name":"emdzej","email":"michal@jaskolski.pro"}],"bin":{"stm-tunnel":"dist/cli.js"},"dist":{"shasum":"e3f77ba43ad2142e4460679a330b16a506fb2bd5","tarball":"https://registry.npmjs.org/@emdzej/stm-tunnel/-/stm-tunnel-0.1.0.tgz","fileCount":5,"integrity":"sha512-/yyqh24dSrXEMrs5IbcxTFhNciT/o0hx0Wg1m57YSCeR1dZwoootgpkdm2Be9YXTb6jGoarILcAST6/4S8VIcg==","signatures":[{"sig":"MEQCIFLdwBhB9TOxc3Aiir5s9Tw3nSyBJFMVKNBWiDuJf/VjAiAEDiw+V3FyeuG49K6fYKb+j0k9G5T31FNYkAe5ASZaOg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":37050},"type":"module","_from":"file:emdzej-stm-tunnel-0.1.0.tgz","engines":{"node":">=20"},"scripts":{"dev":"node --watch --import tsx ./src/cli.ts","lint":"echo skip","build":"node esbuild.config.mjs","clean":"rm -rf dist *.tsbuildinfo","start":"node --import tsx ./src/cli.ts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"emdzej","email":"michal@jaskolski.pro"},"_resolved":"/private/var/folders/7h/x_w_580x4s9dq3sq11tpvzkwy3nbj8/T/0a9627f05c6197b9ff4434c43d0eeb75/emdzej-stm-tunnel-0.1.0.tgz","_integrity":"sha512-/yyqh24dSrXEMrs5IbcxTFhNciT/o0hx0Wg1m57YSCeR1dZwoootgpkdm2Be9YXTb6jGoarILcAST6/4S8VIcg==","_npmVersion":"11.16.0","description":"WebSocket bridge for the STM web serial monitor — exposes a serial port (or a PTY-hosted command) to a browser.","directories":{},"_nodeVersion":"22.22.1","dependencies":{"ws":"^8.18.0","commander":"^12.1.0","serialport":"^12.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","esbuild":"^0.24.0","@types/ws":"^8.5.13","typescript":"^5.7.3","@types/node":"^22.13.1","@emdzej/stm-tunnel-protocol":"0.1.0"},"optionalDependencies":{"node-pty":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/stm-tunnel_0.1.0_1780522003871_0.7214784907062819","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"_id":"@emdzej/stm-tunnel@0.3.0","bin":{"stm-tunnel":"dist/cli.js"},"bugs":{"url":"https://github.com/emdzej/stm/issues"},"dist":{"shasum":"bc8da017e5312aaf3140772e46f278fc1ff44055","tarball":"https://registry.npmjs.org/@emdzej/stm-tunnel/-/stm-tunnel-0.3.0.tgz","fileCount":5,"integrity":"sha512-pzApmRFEzZhbRMJTkaSHw8LrRGoXRSxPSMHlM2YAhsFyyCYfuNbWoQVG/7P/TFEAt3SnbYMHpcFmY9+Ae8QiIQ==","signatures":[{"sig":"MEQCICI5rVrDFQXjWutPmPKRrXQ9sEKjMyVbEZO1hjTLYOWcAiBWrSKvEyKhtH3kp2a36EL2g7vTXLLPTBtKTgOT8EzeiA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIE0ffVPEPq9vrcgmcdUi8shg5dDOh2yMUmEvV7fAFCEpAiEA3K4S4PaRDo7dTG5P07U/T9234IsT9xaZ1NDcw0razh4="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@emdzej%2fstm-tunnel@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":75104},"name":"@emdzej/stm-tunnel","type":"module","_from":"file:emdzej-stm-tunnel-0.3.0.tgz","engines":{"node":">=22.12"},"scripts":{"dev":"node --watch --import tsx ./src/cli.ts","lint":"eslint src","test":"vitest run --dir src","build":"node esbuild.config.mjs","clean":"rm -rf dist *.tsbuildinfo","start":"node --import tsx ./src/cli.ts","typecheck":"tsc --noEmit"},"version":"0.3.0","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:accc02a7-66db-4a9b-97db-1bb137de629e"}},"homepage":"https://github.com/emdzej/stm/tree/main/apps/cli#readme","_resolved":"/tmp/47ead9bfd054dd12a8fb58e2aabf791b/emdzej-stm-tunnel-0.3.0.tgz","_integrity":"sha512-pzApmRFEzZhbRMJTkaSHw8LrRGoXRSxPSMHlM2YAhsFyyCYfuNbWoQVG/7P/TFEAt3SnbYMHpcFmY9+Ae8QiIQ==","repository":{"url":"git+https://github.com/emdzej/stm.git","type":"git","directory":"apps/cli"},"_npmVersion":"11.20.0","description":"WebSocket bridge for the STM web serial monitor — exposes a serial port (or a PTY-hosted command) to a browser.","directories":{},"maintainers":[{"name":"emdzej","email":"michal@jaskolski.pro"}],"_nodeVersion":"24.21.0","dependencies":{"ws":"^8.22.0","commander":"^15.0.0","serialport":"^13.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.23.15","vitest":"^5.0.2","esbuild":"^0.28.2","@types/ws":"^8.18.1","typescript":"^6.0.3","@types/node":"^22.19.19","@emdzej/stm-tunnel-protocol":"0.3.0"},"optionalDependencies":{"node-pty":"^1.1.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/stm-tunnel_0.3.0_1790575877173_0.08571745708279854"}}},"time":{"created":"2026-06-03T21:26:43.627Z","modified":"2026-09-28T06:11:17.691Z","0.1.0":"2026-06-03T21:26:44.010Z","0.3.0":"2026-09-28T06:11:17.263Z"},"description":"WebSocket bridge for the STM web serial monitor — exposes a serial port (or a PTY-hosted command) to a browser.","maintainers":[{"name":"emdzej","email":"michal@jaskolski.pro"}],"readme":"# @emdzej/stm-tunnel\n\nSmall Node CLI that bridges a local serial port to a WebSocket, so browsers without Web Serial (Firefox, Safari, iOS) can talk to the STM web app.\n\n```\nstm-tunnel --port /dev/ttyUSB0 --baud 115200\nSTM_TUNNEL_TOKEN=<secret> stm-tunnel --port COM3 --listen 0.0.0.0:8787 --allowed-origin https://stm.example.com\nstm-tunnel --port /dev/ttyACM0 --tls-cert cert.pem --tls-key key.pem\nstm-tunnel --exec \"bash -i\" --clean-env\n```\n\nOne port per process.\n\n## Security model\n\n- **A token is always required.** If you don't give one (`--token` or the\n  `STM_TUNNEL_TOKEN` env var), a random token is generated and printed at\n  startup. The web client sends it in the `Sec-WebSocket-Protocol` header, so\n  it never appears in URLs or access logs.\n- **Origin allowlist.** Browser connections are only accepted from\n  `https://stm.emdzej.pl` and `http://localhost:*` / `127.0.0.1:*` /\n  `[::1]:*`. Browsers don't apply CORS to WebSockets, so without this any\n  website you had open could reach the tunnel. `--allowed-origin` replaces the\n  list and can be repeated; `scheme://host:*` matches any port, `*` matches\n  anything. Clients that send no `Origin` header (non-browser tools) are\n  allowed.\n- `--no-auth` is only accepted for loopback binds in `--port` mode.\n- `--exec` gives a shell to whoever connects. It always needs a token; add\n  `--clean-env` so the child doesn't inherit your credentials.\n- Binding a non-loopback address without TLS prints a warning: the token\n  travels in cleartext.\n- One client at a time. Inbound frames are capped at 1 MiB, the device is\n  paused while the client falls behind (backpressure), and clients that miss a\n  30 s heartbeat are dropped.\n","readmeFilename":"README.md","homepage":"https://github.com/emdzej/stm/tree/main/apps/cli#readme","repository":{"url":"git+https://github.com/emdzej/stm.git","type":"git","directory":"apps/cli"},"bugs":{"url":"https://github.com/emdzej/stm/issues"}}