Apps could read a deep link's params at launch but had no way to write the browser URL, so app state was never shareable or bookmarkable. setURLParams() lets an app own the query string of its own /app/<name> URL. The path segment is always built from the window's own data-app, never from app input, so an app can decorate its own URL but cannot make the address bar name another app or a Puter route. Writes use replaceState, so apps cannot mint history entries and Back keeps meaning "leave the app". Params Puter itself interprets on a page load are refused: a shareable link is exactly where they would do damage (auth_token would turn an app's "copy link" button into a session-fixation link, api_origin would point token traffic elsewhere, embedded_in_popup diverts boot into the popup-auth path, error_from_within_iframe makes the backend serve an error page). The deny-list carries an audit rule, since these are read from three different places: url_query_params, a direct location.search parse during boot-mode selection, and req.query server-side. Ownership is enforced GUI-side and re-checked when a paced write lands: dashboard mode only, never explorer, the window must claim the URL and not be minimized. Writes are coalesced per app name at 500ms, kept under WebKit's history budget so a spamming app cannot exhaust what the GUI needs for its own pushes. Also fixes four pre-existing bugs this surfaced: - An unguarded pushState aborted UIWindow() mid-build when a browser refused the write, leaving a headless dashboard window with no minimize or close control. - A dashboard tile click focused an already-open app without re-claiming the URL, so the address bar kept naming the app the user just left. - push_dashboard_app_url's dedup branch left dashboard_url_pop_pending set, so restoring an app inside the pop watchdog's window got it re-minimized. - UIDesktop's posargs JSON.parse was unguarded, matching the guard initgui.js already had.
The Open-Source Internet Computer!
« LIVE DEMO »
Puter.com
·
App Store
·
Developers
·
Discord
·
Reddit
·
X
Puter
Puter is an advanced, open-source, self-hostable internet computer designed to be feature-rich, fast, and highly extensible.
For Users
Puter's goal is to provide you with every app and feature you need to work, create, and play under one roof. From a simple Notepad and Voice Recorder to Spreadsheet and Camera, Puter wants to be the all-in-one solution for your digital life.
For Developers
Puter provides everything you need to build and publish web apps and games. From AI to Cloud Storage and Database to Serverless Workers, Puter has you covered. Puter also helps you get users! Once you build your app, you can publish it on our App Store to reach and monetize users.
Getting Started
💻 Local Development
git clone https://github.com/HeyPuter/puter
cd puter
npm install
npm start
→ This should launch Puter at http://puter.localhost:4100
🚀 Self-Hosting
Linux/macOS
curl -fsSL https://puter.com/selfhost | sh
Windows
irm https://puter.com/selfhost?os=windows | iex
→ For more details, see Self-Hosting Puter.
☁️ Puter.com
Puter is available as a hosted service at puter.com.
Support
Connect with the maintainers and community through these channels:
- Bug report or feature request? Please open an issue.
- Discord: discord.com/invite/PQcx7Teh8u
- X (Twitter): x.com/HeyPuter
- Reddit: reddit.com/r/puter/
- Mastodon: mastodon.social/@puter
- Security issues or abuse reports? security@puter.com
- Email maintainers at hi@puter.com
We are always happy to help you with any questions you may have. Don't hesitate to ask!
License
This repository, including all its contents, sub-projects, modules, and components, is licensed under AGPL-3.0 unless explicitly stated otherwise. Third-party libraries included in this repository may be subject to their own licenses.
Translations
- Arabic / العربية
- Armenian / Հայերեն
- Bengali / বাংলা
- Chinese / 中文
- Danish / Dansk
- English
- Farsi / فارسی
- Finnish / Suomi
- French / Français
- German / Deutsch
- Hebrew/ עברית
- Hindi / हिंदी
- Hungarian / Magyar
- Indonesian / Bahasa Indonesia
- Italian / Italiano
- Japanese / 日本語
- Korean / 한국어
- Malay / Bahasa Malaysia
- Malayalam / മലയാളം
- Polish / Polski
- Portuguese / Português
- Punjabi / ਪੰਜਾਬੀ
- Romanian / Română
- Russian / Русский
- Spanish / Español
- Swedish / Svenska
- Tamil / தமிழ்
- Telugu / తెలుగు
- Thai / ไทย
- Turkish / Türkçe
- Ukrainian / Українська
- Urdu / اردو
- Vietnamese / Tiếng Việt

