Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

netlify dev returns 403 for static files in subdirectories on Windows (backslash in rewritten path)

オープン 初心者向け
#8,548 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

@Ramnath0521 がすでに取り組んでいます。

2026年10月6日 から。

  • #8571 @Ramnath0521 による — オープン

評価

難易度
2/5
見積もり時間
1〜3時間
初心者へのやさしさ
88/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
node.js, typescript
領域
backend, cli

調査の方向性

dist/utils/proxy.js の getStatic から始め、特に書き換え後の URL を構築する path.relative 呼び出しを確認します。css/styles.css を含む publish フォルダーを用意し、netlify dev 経由でリクエストして Windows で再現します。ネストされた静的ファイルがプロキシ経由で 200 を返し、ルートのファイルおよび macOS/Linux の動作と一致すれば完了です。

索引モデルが issue の本文から書いたものです。

説明

Describe the bug

On Windows, netlify dev returns 403 Forbidden for any static file inside a subdirectory of the publish folder (e.g. /css/styles.css, /js/app.js). Files at the root of the publish folder (e.g. /index.html, /manifest.json) are served fine.

The cause is in getStatic in dist/utils/proxy.js (line 116 in 27.10.2):

return `/${path.relative(publicFolder, file)}`;

On Windows path.relative returns backslash-separated paths, so /css/styles.css becomes /css\styles.css. It is then passed through encodeURI (req.url = encodeURI(decodeURI(pathname)) + reqUrl.search) and forwarded as /css%5Cstyles.css, which @fastify/static in the static server rejects with:

{"statusCode":403,"error":"Forbidden","message":"Forbidden"}
Steps to reproduce
  1. On Windows, a site with publish = "src" and src/css/styles.css
  2. [dev] framework = "#static" (same result with netlify dev --dir src)
  3. netlify dev
  4. curl http://localhost:8888/css/styles.css → 403
  5. curl http://localhost:<static server port>/css/styles.css (bypassing the proxy) → 200
Expected behavior

/css/styles.css is served with 200 through the netlify dev proxy, as on macOS/Linux and in production.

Actual behavior

403 for every static file in a subdirectory, so pages load without their CSS/JS.

Notes
  • Windows-specific: on macOS/Linux path.relative returns forward slashes, so the path is correct. Production (Netlify CDN) is not affected.
  • Possible fix: normalize the separator, e.g.
    return `/${path.relative(publicFolder, file).split(path.sep).join('/')}`;
Environment
  • netlify-cli 27.10.2
  • Node.js v24.15.0
  • Windows 11 (10.0.26200)
主要言語
TypeScript
スター
1.9k
フォーク
478
平均マージ
1日 18時間
マージ済み PR(30日)
37

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

netlify/cli のほかの issue

netlify/cli の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。