netlify dev returns 403 for static files in subdirectories on Windows (backslash in rewritten path)
メンテナーはふだん 1 日以内に返信
評価
- 難易度
- 2/5
- 見積もり時間
- 1〜3時間
- 初心者へのやさしさ
- 88/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- node.js, typescript
調査の方向性
dist/utils/proxy.js の getStatic から始め、特に書き換え後の URL を構築する path.relative 呼び出しを確認します。css/styles.css を含む publish フォルダーを用意し、netlify dev 経由でリクエストして Windows で再現します。ネストされた静的ファイルがプロキシ経由で 200 を返し、ルートのファイルおよび macOS/Linux の動作と一致すれば完了です。
索引モデルが issue の本文から書いたものです。
説明
Describe the bug
On Windows, netlify dev returns 403 Forbidden for any static file inside a subdirectory of the publish folder (e.g. /css/styles.css, /js/app.js). Files at the root of the publish folder (e.g. /index.html, /manifest.json) are served fine.
The cause is in getStatic in dist/utils/proxy.js (line 116 in 27.10.2):
return `/${path.relative(publicFolder, file)}`;
On Windows path.relative returns backslash-separated paths, so /css/styles.css becomes /css\styles.css. It is then passed through encodeURI (req.url = encodeURI(decodeURI(pathname)) + reqUrl.search) and forwarded as /css%5Cstyles.css, which @fastify/static in the static server rejects with:
{"statusCode":403,"error":"Forbidden","message":"Forbidden"}
Steps to reproduce
- On Windows, a site with
publish = "src"andsrc/css/styles.css [dev] framework = "#static"(same result withnetlify dev --dir src)netlify devcurl http://localhost:8888/css/styles.css→ 403curl http://localhost:<static server port>/css/styles.css(bypassing the proxy) → 200
Expected behavior
/css/styles.css is served with 200 through the netlify dev proxy, as on macOS/Linux and in production.
Actual behavior
403 for every static file in a subdirectory, so pages load without their CSS/JS.
Notes
- Windows-specific: on macOS/Linux
path.relativereturns forward slashes, so the path is correct. Production (Netlify CDN) is not affected. - Possible fix: normalize the separator, e.g.
return `/${path.relative(publicFolder, file).split(path.sep).join('/')}`;
Environment
- netlify-cli 27.10.2
- Node.js v24.15.0
- Windows 11 (10.0.26200)
- 主要言語
- TypeScript
- スター
- 1.9k
- フォーク
- 478
- 平均マージ
- 1日 18時間
- マージ済み PR(30日)
- 37
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
netlify/cli のほかの issue
-
`client-ip` is not an IP address when `x-forwarded-for` holds a list or a port対応中かも @Dev-next-gen が 11 日前に担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信
-
`netlify dev` with `--cwd` from outside the project: every function 500s with "module is not defined in ES module scope" (`detectZisiBuilder` passes a string to `readPackageUp`)対応中かも @bsplatt92 が 52 日前に担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信
-
area: command: deploy area: docs type: feature
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
netlify/cli#1984 · コメント 19 件 · リアクション 3 件 ·
メンテナーはふだん 1 日以内に返信
-
type: bug
難易度 4/5 3〜5日 初心者へのやさしさ 15/100
メンテナーはふだん 1 日以内に返信
-
type: bug
難易度 3/5 1〜2日 初心者へのやさしさ 62/100
メンテナーはふだん 1 日以内に返信
似ている issue
-
area: backend bug priority: low
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
snapotter-hq/SnapOtter#2254 ·
メンテナーはふだん 1 日以内に返信
-
bug ticket
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
cratestack/cratestack#1154 ·
メンテナーはふだん 1 日以内に返信
-
server 消息处理器 cmd 分支补显式错误回报——竞态非法命令现走未处理拒绝対応中かも @openaddr が今日担当しました。 オープンready-for-agent refactor wayfinder:task
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
openaddr/dafung-web#428 ·
メンテナーはふだん 1 日以内に返信
-
Flaky: mongodb-memory-server 'Port already in use' when another process starts a mongod concurrentlyオープンarea:testing bug effort:S priority:P2
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
メンテナーはふだん 1 日以内に返信
-
lens:agent lens:process process
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
thebristolsound/birdbrain#1772 ·
メンテナーはふだん 1 日以内に返信