Edit history

Earlier versions of Support for Isolated / Air-Gapped Environments, newest first.

Current version | Edited by Rex
Changes
Setting this mode via ENV variable would be the best.Removed: ### Notes (optional)Removed: Removed: _No response_Removed: Removed: ### ChecksRemoved: Removed: - ☑ I searched for existing discussions and didn't find a duplicate.Removed:
Show

Support for Isolated / Air-Gapped Environments

Problem

Currently, the application makes outbound network calls to external internet resources during runtime (for example, https://api.pwnedpasswords.com/range/$%7BhashPrefix%7D). When deploying this application in a restricted environment—such as behind a strict corporate firewall, within a high-security air-gapped network, or in a region with limited global internet connectivity—these outbound requests fail.

Proposed solution

I would like a dedicated "Isolated Mode" (or "Offline/Air-Gapped Mode") configuration option. When enabled, the application should adhere to the following constraints:
  • The application must not attempt to make any HTTP/HTTPS requests to domains outside of its own local host or internal network.
  • Fully Self-Contained Assets (fonts, icons, and CSS libraries)
  • JavaScript dependencies fully vendored/bundled at build time.
  • Automatic version checking, crash reporting, and anonymous usage statistics are disabled or bypassed silently without causing errors in the logs.
  • If an external resource was accidentally requested, the application should fail instantly (connection refused) or skip silently rather than hanging the UI thread waiting for a TCP timeout.
Setting this mode via ENV variable would be the best.
Original by Rex
Show

Support for Isolated / Air-Gapped Environments

Problem

Currently, the application makes outbound network calls to external internet resources during runtime (for example, https://api.pwnedpasswords.com/range/$%7BhashPrefix%7D). When deploying this application in a restricted environment—such as behind a strict corporate firewall, within a high-security air-gapped network, or in a region with limited global internet connectivity—these outbound requests fail.

Proposed solution

I would like a dedicated "Isolated Mode" (or "Offline/Air-Gapped Mode") configuration option. When enabled, the application should adhere to the following constraints:
  • The application must not attempt to make any HTTP/HTTPS requests to domains outside of its own local host or internal network.
  • Fully Self-Contained Assets (fonts, icons, and CSS libraries)
  • JavaScript dependencies fully vendored/bundled at build time.
  • Automatic version checking, crash reporting, and anonymous usage statistics are disabled or bypassed silently without causing errors in the logs.
  • If an external resource was accidentally requested, the application should fail instantly (connection refused) or skip silently rather than hanging the UI thread waiting for a TCP timeout.
Setting this mode via ENV variable would be the best.

Notes (optional)

No response

Checks

  • ☑ I searched for existing discussions and didn't find a duplicate.