netlify dev returns 403 for static files in subdirectories on Windows (backslash in rewritten path)
维护者通常 1 天内回复
评估
- 难度
- 2/5
- 预计耗时
- 1-3 小时
- 新手友好度
- 88/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- node.js, typescript
调研方向
从 dist/utils/proxy.js 中的 getStatic 开始,重点查看构建重写 URL 的 path.relative 调用。在 Windows 上使用包含 css/styles.css 的发布文件夹,并通过 netlify dev 请求该文件进行复现。当嵌套的静态文件能够通过代理获得 200,与根目录文件以及 macOS/Linux 上的行为一致时,即表示完成。
由索引模型根据 Issue 内容生成。
描述
Describe the bug
On Windows, netlify dev returns 403 Forbidden for any static file inside a subdirectory of the publish folder (e.g. /css/styles.css, /js/app.js). Files at the root of the publish folder (e.g. /index.html, /manifest.json) are served fine.
The cause is in getStatic in dist/utils/proxy.js (line 116 in 27.10.2):
return `/${path.relative(publicFolder, file)}`;
On Windows path.relative returns backslash-separated paths, so /css/styles.css becomes /css\styles.css. It is then passed through encodeURI (req.url = encodeURI(decodeURI(pathname)) + reqUrl.search) and forwarded as /css%5Cstyles.css, which @fastify/static in the static server rejects with:
{"statusCode":403,"error":"Forbidden","message":"Forbidden"}
Steps to reproduce
- On Windows, a site with
publish = "src"andsrc/css/styles.css [dev] framework = "#static"(same result withnetlify dev --dir src)netlify devcurl http://localhost:8888/css/styles.css→ 403curl http://localhost:<static server port>/css/styles.css(bypassing the proxy) → 200
Expected behavior
/css/styles.css is served with 200 through the netlify dev proxy, as on macOS/Linux and in production.
Actual behavior
403 for every static file in a subdirectory, so pages load without their CSS/JS.
Notes
- Windows-specific: on macOS/Linux
path.relativereturns forward slashes, so the path is correct. Production (Netlify CDN) is not affected. - Possible fix: normalize the separator, e.g.
return `/${path.relative(publicFolder, file).split(path.sep).join('/')}`;
Environment
- netlify-cli 27.10.2
- Node.js v24.15.0
- Windows 11 (10.0.26200)
- 主要语言
- TypeScript
- 星标
- 1.9k
- 派生
- 478
- 平均合并
- 2 天 17 小时
- 30 天内合并 PR
- 63
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
netlify/cli 的其他 Issue
-
`client-ip` is not an IP address when `x-forwarded-for` holds a list or a port可能已有人在做 @Dev-next-gen 于 11 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复
-
`netlify dev` with `--cwd` from outside the project: every function 500s with "module is not defined in ES module scope" (`detectZisiBuilder` passes a string to `readPackageUp`)可能已有人在做 @bsplatt92 于 52 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复
-
area: command: deploy area: docs type: feature
难度 1/5 1 小时以内 新手友好度 88/100
netlify/cli#1984 · 19 条评论 · 3 个 reaction ·
维护者通常 1 天内回复
-
CARD未关闭
难度 5/5 一周以上 新手友好度 5/100
维护者通常 1 天内回复
-
SBI CREDIT CARD未关闭
难度 5/5 一周以上 新手友好度 12/100
维护者通常 1 天内回复
相似的 Issue
-
[Bug]: Server git tests sign fixture commits with the developer's key when run from the repo root未关闭
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 62/100
melgarafael/DeskcommCRM#2657 ·
维护者通常 1 天内回复
-
难度 1/5 1 小时以内 新手友好度 85/100
MystenLabs/MemWal#1163 · 2 条评论 ·
维护者通常 1 天内回复
-
"Explore the letters"-button should read "Explore the papers"可能已有人在做 关联的 PR 仍在进行中或已合并。 未关闭Mondriaan
难度 1/5 1 小时以内 新手友好度 88/100
knaw-huc/textannoviz#709 ·
维护者通常 1 天内回复
-
billion-context-pi
难度 2/5 1-3 小时 新手友好度 62/100
ranxianglei/billion-context#2521 · 3 条评论 ·
维护者通常 1 天内回复