Files
Vance Ingalls acdec1310c fix(vst-host): require a shared-secret token on the sidecar WebSocket
Finding 2 of the final whole-branch review: the sidecar's loopback
WebSocket accepted any connection with no origin/auth check, so any
local process (or webpage that guessed/scanned the ephemeral port)
could drive load-chain to load arbitrary native plugin bundles or read
arbitrary files via wavPath.

server.py's VstServer now generates a per-process secrets.token_urlsafe
token, prints it alongside the ready line, and rejects the WebSocket
handshake via websockets' process_request hook unless the connecting
client presents it as a `?token=` query param. Threaded through:
studio-server's vstSidecar.ts (extended ready-line regex) and
routes/vst.ts (/vst/start response), the CLI adapter, and the studio
client's useVstHost.ts (connects with the token in the WS URL).
vstBounce.ts (the offline render path) is unaffected — it invokes the
sidecar's `bounce` CLI subcommand directly and never opens a WebSocket.

Also folds in two smaller final-review findings that touch the same
files:

- vstSidecar.test.ts's mid-spawn-kill test used a fixed 300ms sleep to
  wait for the child's PID file; replaced with a short-interval poll
  (waitForFile) to remove a CI-contention flake risk.
- useVstHost.ts's handleDisconnect doc-comment claimed trackIndexRef was
  kept "purely for the FX property panel's own direct loadChain calls"
  — false (the FX panel never calls loadChain; only useVstPreview
  does). Corrected to describe it as forward-defensive infrastructure
  with no current FX-panel caller.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-16 18:53:17 -07:00
..

hyperframes

CLI for creating, previewing, and rendering HTML video compositions.

Install

npm install -g hyperframes

Or use directly with npx:

npx hyperframes <command>

Requirements: Node.js >= 22, FFmpeg

Commands

init

Scaffold a new Hyperframes project from a template:

npx hyperframes init my-video
cd my-video

preview

Start the live preview studio in your browser:

npx hyperframes preview
# Studio running at http://localhost:3002

npx hyperframes preview --port 4567

render

Render a composition to MP4. Run from the project directory; the positional argument is the project directory (not a file), so render the project's index.html directly, or point at a specific composition file with -c:

npx hyperframes render -o output.mp4
npx hyperframes render -c ./my-composition.html -o output.mp4

lint

Validate your Hyperframes HTML:

npx hyperframes lint ./my-composition
npx hyperframes lint ./my-composition --json      # JSON output for CI/tooling
npx hyperframes lint ./my-composition --verbose   # Include info-level findings

By default only errors and warnings are shown. Use --verbose to also display informational findings (e.g., external script dependency notices). Use --json for machine-readable output with errorCount, warningCount, infoCount, and a findings array.

compositions

List compositions found in the current project:

npx hyperframes compositions

benchmark

Run rendering benchmarks:

npx hyperframes benchmark ./my-composition.html

doctor

Check your environment for required dependencies (Chrome, FFmpeg, Node.js):

npx hyperframes doctor

browser

Manage the bundled Chrome/Chromium installation:

npx hyperframes browser

info

Print version and environment info:

npx hyperframes info

docs

Open the documentation in your browser:

npx hyperframes docs

upgrade

Check for updates and show upgrade instructions:

npx hyperframes upgrade
npx hyperframes upgrade --check --json  # machine-readable for agents

Documentation

Full documentation: hyperframes.heygen.com/packages/cli