Frontendv0.1.9
@tekir/vite
Vite integration for React, Vue, and Svelte with HMR.
Installation
$
bun add @tekir/viteFeatures
- Vite is the dev gateway on the user-configured `app.port`; Tekir backend moves to an auto-picked port (`get-port`) and Vite proxies `/api` to it
- HMR works natively on the same port the browser hits; no second WebSocket hop, no `clientPort` drift across multiple Vite projects on one machine
- Multiple Tekir + Vite apps on one machine coexist without 5173 collisions because each Tekir picks its own backend port
- `proxyPaths: string[]` to add prefixes Vite should forward (default `['/api']`)
- Auto-discovers your `vite.config.ts` and merges Tekir's structural defaults (`root`, `build.outDir`) only where you have not set them; no path-alias defaults so framework conventions stay yours
- Inlines only `VITE_*` env vars into the client bundle so secrets stay server-side
- Production fallback serves `dist/client/` plus an SPA index.html fallback; compiled binaries serve from the embed map directly
Quick Example
TypeScript
// admin/index.ts
import { tekir } from '@tekir/core'
const app = await tekir({
config: { app: { port: 20000 } },
frontend: { type: 'vite' },
})
await app.router.registerDir('./controllers')
app.start()
// Dev: Vite on http://localhost:20000 (gateway, HMR native);
// Tekir on an auto-picked port; `/api` proxied to Tekir.
//
// Build: `tekir build --outdir ./dist` produces dist/index.js (backend)
// and dist/client/ (Vite assets) in one step.Changelog
v0.1.9LatestSeptember 16, 2026
- Published output now uses the shared Node-targeted ESM bundle pipeline with external dependencies and generated TypeScript declarations, while Bun consumers keep the native source export.
v0.1.8July 23, 2026
- Package metadata now follows the shared compatible
0.1.xdependency range used by this coordinated Tekir release.
v0.1.7July 16, 2026
- Build embedding and production asset serving reject symlink escapes outside configured roots, including paths that pass lexical containment checks.
v0.1.6June 13, 2026
- Static file serving for
public/anddist/now goes through a hardened path resolver, matching@tekir/static: percent-decoding is guarded, null bytes and cross-drive paths are rejected, every segment is checked for dotfiles (.env/.git), and backslash-encoded separators are handled. This closes a path-traversal surface in the prod static fallback. - The compiled import path is now embedded safely so a crafted path cannot break out of the generated source.
- Found and fixed with Fable.
v0.1.5May 8, 2026
- Vite middleware honours the
tekir testrunner signal. Whenprocess.env.TEKIR_RUNNER === 'test'the dev gateway block (which would otherwise spin up its own listener onapp.port) is skipped, so a user entry can keepfrontend: { type: 'vite' }unconditional without aprocess.env.NODE_ENV === 'test' ? undefined : ...ternary. The build hook (server.onBuild) and the prod static fallback are still registered — they don't bind anything, so they're safe under tests and atekir buildrun still producesdist/client/.
v0.1.4May 6, 2026
- Fix: production builds no longer return the SPA
index.htmlfor unmatched backend paths. Requests to a configuredproxyPathsprefix (default['/api']) that the router did not claim now return a404 application/jsoninstead of the 200 HTML shell, matching the contract clients already expect from the dev gateway. The same gate applies to compiled binaries' embed map. Custom prefixes still work — setproxyPaths: ['/api', '/v2', '/internal']to extend the list.
v0.1.3May 6, 2026
- Fix: vite middleware no longer crashes apps with
Logger not initialized. Call tekir() first.at startup. The internal vite logger now resolves the framework logger lazily, on each log call instead of once when the middleware is constructed, and falls back toconsolewhen the framework logger is not yet populated. This was visible in production bundles where the bundler's module init order put the vite middleware ahead oftekir()'s container setup, or when a duplicate copy of@tekir/coreended up in the bundle and the vite middleware saw a different module-scope_loggerthan the one tekir populated.
v0.1.2May 5, 2026
- Vite is now the dev gateway. It owns the user-configured
app.port; the Tekir backend moves to a free port picked automatically and Vite proxies/api(default, configurable viaproxyPaths) to it. HMR works natively because the browser connects to Vite directly. The previous architecture proxied through Tekir's HTTP fallback, which forced a hardcodedhmr.clientPort: 5173that collided with every other Vite project on the box (most visibly: navigating to a Tekir admin panel could serve a sibling project's HTML when 5173 was already taken). - All
process.cwd()references replaced with theappRootTekir injects via the new setupctx.vite.config.tsdiscovery,envDir,public/, anddist/client/paths now resolve from the project root regardless of launching cwd. Same fix removes theprocess.chdir(import.meta.dir)workaround monorepo apps used. - New
tekirDefaultsPlugininjectsrootandbuild.outDironly where the user'svite.config.tshas not set them. No path alias is defaulted on purpose, since@,~, and$libconventions vary per framework and~has special semantics in some CSS toolchains. - Setup signature is
vite(server, config, ctx)(third arg optional).ctx.configStoreis what lets the gateway rewriteapp.portbeforeserver.start()reads it;ctx.appRootis the project root fromtekir(). Older(server, config)integrations still work. - Fix: production builds no longer crash with a 500 (
EISDIR) when the browser navigates to/. The prod fallback now skips entries that resolve to a directory rather than a file, soGET /correctly falls through to the SPAindex.html. - Adds
get-port@^7as a runtime dependency.
v0.1.1April 27, 2026
- Single-executable support via
bun run index.ts build --compile. Vite output is bundled into the binary and served at runtime with nonode_moduleson disk. - Auto-discovers your
vite.config.ts(or.js,.mts,.mjs) in the project root, so plugins like@vitejs/plugin-react,@vitejs/plugin-vue, and the Svelte and Solid plugins are picked up correctly in both dev and production builds. - Inlines only
VITE_*env vars into the client bundle so secrets stay server-side.
v0.1.0April 1, 2026
- Initial release