npm run dev is POSIX-only; the Windows fallback 403s on every save
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 新手友好度
- 76/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- node.js, typescript, vite
调研方向
Start with the dev script in package.json, then read the origin handling in src/server/index.ts and src/server/app.ts alongside the proxy in vite.config.ts. Check the Windows setup instructions in README.md and .env.example. Done means the documented one-command dev path works on Windows and saving through the Vite proxy no longer returns the reported 403.
由索引模型根据 Issue 内容生成。
描述
Summary
npm run dev cannot run on Windows at all, and the natural workaround replaces that failure with a subtler one: the UI loads but every write returns 403 Cross-origin requests are not allowed.
Verified against c2569bb (2026-10-02).
1. The dev script uses POSIX-only syntax
package.json:11:
"dev": "concurrently -k \"NODE_ENV=development node --env-file-if-exists=.env --import tsx --watch src/server/index.ts\" \"vite\""
The VAR=value command form is interpreted by sh/bash/zsh only. In cmd.exe and PowerShell it is parsed as a program name, so npm run dev fails with 'NODE_ENV' is not recognized as an internal or external command.
There is no documented Windows path: grep -in "windows\|powershell\|cross-env" README.md docs/ CONTRIBUTING.md returns nothing. The Get started block (README.md:150-161) also uses cp .env.example .env, which does not exist in cmd.exe (PowerShell's cp alias happens to work).
2. Dropping NODE_ENV silently breaks the origin check
Running the same two processes without the env assignment starts both servers and the page loads, but saving a Space or page fails:
403 { "error": "Cross-origin requests are not allowed." }
This is because the dev origin allowlist is derived from NODE_ENV (src/server/index.ts:88-92):
origin:
process.env.APP_ORIGIN ??
(process.env.NODE_ENV === 'development'
? 'http://127.0.0.1:5173'
: undefined),
and then compared against the server's own origin when unset (src/server/app.ts:49-52):
const expectedOrigin = origin ?? new URL(c.req.url).origin;
if (requestOrigin && requestOrigin !== expectedOrigin)
return c.json({ error: 'Cross-origin requests are not allowed.' }, 403);
In development the browser talks to Vite on :5173, which proxies /api to :4310 (vite.config.ts:9) while preserving the browser's Origin: http://127.0.0.1:5173. With origin undefined, expectedOrigin becomes http://127.0.0.1:4310, so the check fails on every request.
Uncommenting APP_ORIGIN=http://127.0.0.1:5173 in .env does fix it — but that is a second manual step caused by the first failure, and .env.example ships it commented out (# APP_ORIGIN=http://127.0.0.1:5173) with a note saying "npm run dev allows http://127.0.0.1:5173", which is only true when NODE_ENV was actually set.
Setting the variable in the calling shell also works and needs no .env edit:
$env:NODE_ENV="development"; npx concurrently -k "node --env-file-if-exists=.env --import tsx --watch src/server/index.ts" "vite"
But neither of these is something a Windows user can discover from the README.
Suggested fix
Make the documented one-command path work everywhere, rather than documenting a workaround:
- Add
cross-envtodevDependenciesand prefix the inner command:cross-env NODE_ENV=development node --env-file-if-exists=.env .... One-line change, no behavior drift.
Optionally also decouple the dev origin from NODE_ENV so a missing env var can never produce this confusing 403 (e.g. pass APP_ORIGIN explicitly in the dev script), and add a short Windows note to Get started with a copy-command-neutral instruction.
Testing note
Mechanism verified by reading package.json, src/server/index.ts, src/server/app.ts and vite.config.ts. The POSIX-shell dependency and the origin comparison are unambiguous in source. The npm run dev error string itself was reported by someone running on Windows; my own full run of the app was on Linux, where npm run dev works as documented.
- 主要语言
- TypeScript
- 星标
- 2.8k
- 派生
- 344
- 平均合并
- 7 小时 8 分钟
- 30 天内合并 PR
- 10
环境准备
- 提供 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
CopilotKit/OpenDots 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 68/100
CopilotKit/OpenDots#69 ·
维护者通常 1 天内回复
-
Long page titles are clipped in the page editor可能已有人在做 @charan-rathore 于 1 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 72/100
CopilotKit/OpenDots#68 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 70/100
CopilotKit/OpenDots#67 ·
维护者通常 1 天内回复
-
copilotkit project select rewrites INTELLIGENCE_API_KEY to CPK_INTELLIGENCE_API_KEY, which OpenDots never reads可能已有人在做 @charan-rathore 于 1 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 85/100
CopilotKit/OpenDots#55 ·
维护者通常 1 天内回复
-
Error banner stays after the server connection recovers可能已有人在做 @charan-rathore 于 1 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 88/100
CopilotKit/OpenDots#51 ·
维护者通常 1 天内回复
查看 CopilotKit/OpenDots 的全部 Issue
相似的 Issue
-
perf(core): getComments() runs the approved count and the comment list as two sequential queries未关闭area/core bot:bug bot:working
难度 2/5 1-3 小时 新手友好度 76/100
emdash-cms/emdash#3905 · 2 条评论 ·
维护者通常 1 天内回复
-
community first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
难度 1/5 1 小时以内 新手友好度 90/100
lingdojo/kana-dojo#31728 · 1 条评论 · 5 个 reaction ·
维护者通常 1 天内回复
-
selective-claw: freshTailTurns=0 keeps ALL turns verbatim and summarizes none (slice(-0) === slice(0))可能已有人在做 @zjncs 今天认领。 未关闭component:tokenless
难度 2/5 1-3 小时 新手友好度 80/100
agentic-os-org/ANOLISA#6112 · 1 条评论 ·
维护者通常 1 天内回复
-
bug needs triage
难度 2/5 1-3 小时 新手友好度 75/100
rjsf-team/react-jsonschema-form#5439 ·
维护者通常 1 天内回复
-
enhancement
难度 2/5 1-3 小时 新手友好度 76/100
维护者通常 1 天内回复