npm run dev is POSIX-only; the Windows fallback 403s on every save
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 76/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- node.js, typescript, vite
- Ambito
- backend, developer-experience
Direzione di ricerca
Start with the dev script in package.json, then read the origin handling in src/server/index.ts and src/server/app.ts alongside the proxy in vite.config.ts. Check the Windows setup instructions in README.md and .env.example. Done means the documented one-command dev path works on Windows and saving through the Vite proxy no longer returns the reported 403.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
npm run dev cannot run on Windows at all, and the natural workaround replaces that failure with a subtler one: the UI loads but every write returns 403 Cross-origin requests are not allowed.
Verified against c2569bb (2026-10-02).
1. The dev script uses POSIX-only syntax
package.json:11:
"dev": "concurrently -k \"NODE_ENV=development node --env-file-if-exists=.env --import tsx --watch src/server/index.ts\" \"vite\""
The VAR=value command form is interpreted by sh/bash/zsh only. In cmd.exe and PowerShell it is parsed as a program name, so npm run dev fails with 'NODE_ENV' is not recognized as an internal or external command.
There is no documented Windows path: grep -in "windows\|powershell\|cross-env" README.md docs/ CONTRIBUTING.md returns nothing. The Get started block (README.md:150-161) also uses cp .env.example .env, which does not exist in cmd.exe (PowerShell's cp alias happens to work).
2. Dropping NODE_ENV silently breaks the origin check
Running the same two processes without the env assignment starts both servers and the page loads, but saving a Space or page fails:
403 { "error": "Cross-origin requests are not allowed." }
This is because the dev origin allowlist is derived from NODE_ENV (src/server/index.ts:88-92):
origin:
process.env.APP_ORIGIN ??
(process.env.NODE_ENV === 'development'
? 'http://127.0.0.1:5173'
: undefined),
and then compared against the server's own origin when unset (src/server/app.ts:49-52):
const expectedOrigin = origin ?? new URL(c.req.url).origin;
if (requestOrigin && requestOrigin !== expectedOrigin)
return c.json({ error: 'Cross-origin requests are not allowed.' }, 403);
In development the browser talks to Vite on :5173, which proxies /api to :4310 (vite.config.ts:9) while preserving the browser's Origin: http://127.0.0.1:5173. With origin undefined, expectedOrigin becomes http://127.0.0.1:4310, so the check fails on every request.
Uncommenting APP_ORIGIN=http://127.0.0.1:5173 in .env does fix it — but that is a second manual step caused by the first failure, and .env.example ships it commented out (# APP_ORIGIN=http://127.0.0.1:5173) with a note saying "npm run dev allows http://127.0.0.1:5173", which is only true when NODE_ENV was actually set.
Setting the variable in the calling shell also works and needs no .env edit:
$env:NODE_ENV="development"; npx concurrently -k "node --env-file-if-exists=.env --import tsx --watch src/server/index.ts" "vite"
But neither of these is something a Windows user can discover from the README.
Suggested fix
Make the documented one-command path work everywhere, rather than documenting a workaround:
- Add
cross-envtodevDependenciesand prefix the inner command:cross-env NODE_ENV=development node --env-file-if-exists=.env .... One-line change, no behavior drift.
Optionally also decouple the dev origin from NODE_ENV so a missing env var can never produce this confusing 403 (e.g. pass APP_ORIGIN explicitly in the dev script), and add a short Windows note to Get started with a copy-command-neutral instruction.
Testing note
Mechanism verified by reading package.json, src/server/index.ts, src/server/app.ts and vite.config.ts. The POSIX-shell dependency and the origin comparison are unambiguous in source. The npm run dev error string itself was reported by someone running on Windows; my own full run of the app was on Linux, where npm run dev works as documented.
- Lingua principale
- TypeScript
- Stelle
- 2.8k
- Fork
- 344
- Merge medio
- 7h 8m
- PR unite (30g)
- 10
Preparare l'ambiente
- Include un Dockerfile o un file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di CopilotKit/OpenDots
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
CopilotKit/OpenDots#69 ·
I maintainer di solito rispondono entro 1 giorno
-
Long page titles are clipped in the page editorForse già presa @charan-rathore l’ha presa 1 giorno fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
CopilotKit/OpenDots#68 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
CopilotKit/OpenDots#67 ·
I maintainer di solito rispondono entro 1 giorno
-
copilotkit project select rewrites INTELLIGENCE_API_KEY to CPK_INTELLIGENCE_API_KEY, which OpenDots never readsForse già presa @charan-rathore l’ha presa 1 giorno fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
CopilotKit/OpenDots#55 ·
I maintainer di solito rispondono entro 1 giorno
-
Error banner stays after the server connection recoversForse già presa @charan-rathore l’ha presa 1 giorno fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
CopilotKit/OpenDots#51 ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di CopilotKit/OpenDots
Issue simili
-
perf(core): getComments() runs the approved count and the comment list as two sequential queriesApertaarea/core bot:bug bot:working
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
emdash-cms/emdash#3905 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
community first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
lingdojo/kana-dojo#31728 · 1 commento · 5 reazioni ·
I maintainer di solito rispondono entro 1 giorno
-
selective-claw: freshTailTurns=0 keeps ALL turns verbatim and summarizes none (slice(-0) === slice(0))Forse già presa @zjncs l’ha presa oggi. Apertacomponent:tokenless
Difficoltà 2/5 1-3 ore Idoneità per principianti 80/100
agentic-os-org/ANOLISA#6112 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
bug needs triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
rjsf-team/react-jsonschema-form#5439 ·
I maintainer di solito rispondono entro 1 giorno
-
enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
I maintainer di solito rispondono entro 1 giorno