npm run dev is POSIX-only; the Windows fallback 403s on every save
Maintainer thường phản hồi trong vòng 2 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 76/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- node.js, typescript, vite
- Lĩnh vực
- backend, developer-experience
Hướng nghiên cứu
Start with the dev script in package.json, then read the origin handling in src/server/index.ts and src/server/app.ts alongside the proxy in vite.config.ts. Check the Windows setup instructions in README.md and .env.example. Done means the documented one-command dev path works on Windows and saving through the Vite proxy no longer returns the reported 403.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Summary
npm run dev cannot run on Windows at all, and the natural workaround replaces that failure with a subtler one: the UI loads but every write returns 403 Cross-origin requests are not allowed.
Verified against c2569bb (2026-10-02).
1. The dev script uses POSIX-only syntax
package.json:11:
"dev": "concurrently -k \"NODE_ENV=development node --env-file-if-exists=.env --import tsx --watch src/server/index.ts\" \"vite\""
The VAR=value command form is interpreted by sh/bash/zsh only. In cmd.exe and PowerShell it is parsed as a program name, so npm run dev fails with 'NODE_ENV' is not recognized as an internal or external command.
There is no documented Windows path: grep -in "windows\|powershell\|cross-env" README.md docs/ CONTRIBUTING.md returns nothing. The Get started block (README.md:150-161) also uses cp .env.example .env, which does not exist in cmd.exe (PowerShell's cp alias happens to work).
2. Dropping NODE_ENV silently breaks the origin check
Running the same two processes without the env assignment starts both servers and the page loads, but saving a Space or page fails:
403 { "error": "Cross-origin requests are not allowed." }
This is because the dev origin allowlist is derived from NODE_ENV (src/server/index.ts:88-92):
origin:
process.env.APP_ORIGIN ??
(process.env.NODE_ENV === 'development'
? 'http://127.0.0.1:5173'
: undefined),
and then compared against the server's own origin when unset (src/server/app.ts:49-52):
const expectedOrigin = origin ?? new URL(c.req.url).origin;
if (requestOrigin && requestOrigin !== expectedOrigin)
return c.json({ error: 'Cross-origin requests are not allowed.' }, 403);
In development the browser talks to Vite on :5173, which proxies /api to :4310 (vite.config.ts:9) while preserving the browser's Origin: http://127.0.0.1:5173. With origin undefined, expectedOrigin becomes http://127.0.0.1:4310, so the check fails on every request.
Uncommenting APP_ORIGIN=http://127.0.0.1:5173 in .env does fix it — but that is a second manual step caused by the first failure, and .env.example ships it commented out (# APP_ORIGIN=http://127.0.0.1:5173) with a note saying "npm run dev allows http://127.0.0.1:5173", which is only true when NODE_ENV was actually set.
Setting the variable in the calling shell also works and needs no .env edit:
$env:NODE_ENV="development"; npx concurrently -k "node --env-file-if-exists=.env --import tsx --watch src/server/index.ts" "vite"
But neither of these is something a Windows user can discover from the README.
Suggested fix
Make the documented one-command path work everywhere, rather than documenting a workaround:
- Add
cross-envtodevDependenciesand prefix the inner command:cross-env NODE_ENV=development node --env-file-if-exists=.env .... One-line change, no behavior drift.
Optionally also decouple the dev origin from NODE_ENV so a missing env var can never produce this confusing 403 (e.g. pass APP_ORIGIN explicitly in the dev script), and add a short Windows note to Get started with a copy-command-neutral instruction.
Testing note
Mechanism verified by reading package.json, src/server/index.ts, src/server/app.ts and vite.config.ts. The POSIX-shell dependency and the origin comparison are unambiguous in source. The npm run dev error string itself was reported by someone running on Windows; my own full run of the app was on Linux, where npm run dev works as documented.
- Ngôn ngữ chính
- TypeScript
- Star
- 2.8k
- Fork
- 344
- Merge trung bình
- 1 ngày 15 giờ
- Pull request đã merge (30 ngày)
- 43
Chuẩn bị môi trường
- Có Dockerfile hoặc tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của CopilotKit/OpenDots
-
Page conversation panel overflows horizontallyCó thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
CopilotKit/OpenDots#69 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Long page titles are clipped in the page editorCó thể đã có người làm @charan-rathore đã nhận 3 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
CopilotKit/OpenDots#68 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Dependency DashboardĐang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
CopilotKit/OpenDots#111 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
BAITAĐang mở
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 15/100
CopilotKit/OpenDots#108 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
CopilotKit/OpenDots#100 ·
Maintainer thường phản hồi trong vòng 2 ngày
Tất cả issue của CopilotKit/OpenDots
Issue tương tự
-
ble-needs-fable-review bug mobile priority:P2
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
ColeMurray/background-agents#2305 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug from-studio
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 63/100
esengine/DeepSeek-Reasonix#12355 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
oblien/openship#1086 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày