DEV Community
Follow
Our Electron renderer has no preload script, and it talks to 28 HTTP endpoints on 127.0.0.1
Electron applications typically use preload scripts to grant renderer processes access to privileged Electron APIs. However, Notifio’s main window eschews this approach, disabling node integration and context isolation. Instead, the renderer is treated as a standard web page served by a local HTTP server running within the main process. This server exposes 28 routes that form the complete interface between the UI and the application's monitoring logic.This architectural choice was driven by several factors. Firstly, the renderer genuinely functions as a web app, built with standard web technologies and unaware of Electron. Secondly, using HTTP provides a structured and existing vocabulary for API interactions, such as CRUD operations, avoiding the continuous design effort required for custom IPC channels. Thirdly, the disposable nature of the main window, which reloads its renderer frequently, benefits from an HTTP API that allows the UI to rebuild its state easily on each load.Live updates are handled via polling these HTTP routes rather than push mechanisms. The server's placement within the main process simplifies its operation by removing serialization boundaries and the need for separate process management. Authentication for this local HTTP API is enforced by binding it exclusively to the loopback interface, preventing external network access.While the HTTP server provides a clean separation, certain Electron-specific functionalities, like opening new browser windows for user logins, are managed through a small, in-process bridge. This bridge allows route handlers to delegate Electron-dependent tasks without the server module itself importing Electron. The only exception to this HTTP-centric design is the recorder window, which uses a preload script and IPC. This is necessary because it loads third-party sites and needs to observe page interactions, a task better suited for a preload script within a sandboxed environment. The distinction is that HTTP is used when the renderer queries the app, while preload/IPC is for observing external pages.