Skip to content

fix: throw an error when prerendering a root +server.js that returns a non-HTML response - #15994

Merged
Rich-Harris merged 6 commits into
sveltejs:mainfrom
geodask:fix/prerender-root-server-js-error
Jun 16, 2026
Merged

fix: throw an error when prerendering a root +server.js that returns a non-HTML response#15994
Rich-Harris merged 6 commits into
sveltejs:mainfrom
geodask:fix/prerender-root-server-js-error

Conversation

@geodask

@geodask geodask commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

Closes #11087

When a root +server.js returns a non-HTML response and is marked as prerenderable, SvelteKit was silently saving the response as index.html. This was caused by output_filename() falling back to 'index.html' when the path slice for the root was an empty string.

The fix throws a clear error at build time instead. There's no valid static filename for a non-HTML response at the root path. A static host will always serve an HTML file for /.


Please don't delete this checklist! Before submitting the PR, please make sure you do the following:

  • It's really useful if your PR references an issue where it is discussed ahead of time. In many cases, features are absent for a reason. For large changes, please create an RFC: https://github.com/sveltejs/rfcs
  • This message body should clearly illustrate what problems it solves.
  • Ideally, include a test that fails without this PR but passes with it.

Tests

  • Run the tests with pnpm test and lint the project with pnpm lint and pnpm check

Changesets

  • If your PR makes a change that should be noted in one or more packages' changelogs, generate a changeset by running pnpm changeset and following the prompts. Changesets that add features should be minor and those that fix bugs should be patch. Please prefix changeset messages with feat:, fix:, or chore:.

Edits

  • Please ensure that 'Allow edits from maintainers' is checked. PRs without this option may be closed.

@changeset-bot

changeset-bot Bot commented Jun 9, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ea4f823

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@sveltejs/kit Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@elliott-with-the-longest-name-on-github

Copy link
Copy Markdown
Contributor

There's no valid static filename for a non-HTML response at the root path. A static host will always serve an HTML file for /.

I don't think this is a true premise. Surely it's possible on most static hosts to configure the root file + mime type, right?

@geodask

geodask commented Jun 14, 2026

Copy link
Copy Markdown
Contributor Author

This approach was suggested by @Rich-Harris in #14135 (comment). Happy to improve the error message wording if needed

@Rich-Harris

Copy link
Copy Markdown
Member

test failures are caused by some inscrutable lockfile nonsense

Rich-Harris added a commit that referenced this pull request Jun 16, 2026
mostly just trying to unstick whatever's causing CI to fail on #15994

@Rich-Harris Rich-Harris left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thank you!

@Rich-Harris
Rich-Harris merged commit 80cc084 into sveltejs:main Jun 16, 2026
42 of 44 checks passed
@github-actions github-actions Bot mentioned this pull request Jun 16, 2026
huskas-2189 pushed a commit to huskas-2189/Bookmark that referenced this pull request Jun 20, 2026
This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@sveltejs/kit](https://svelte.dev) ([source](https://github.com/sveltejs/kit/tree/HEAD/packages/kit)) | [`2.65.1` → `2.66.0`](https://renovatebot.com/diffs/npm/@sveltejs%2fkit/2.65.1/2.66.0) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@sveltejs%2fkit/2.66.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@sveltejs%2fkit/2.65.1/2.66.0?slim=true) |

---

### Release Notes

<details>
<summary>sveltejs/kit (@&#8203;sveltejs/kit)</summary>

### [`v2.66.0`](https://github.com/sveltejs/kit/blob/HEAD/packages/kit/CHANGELOG.md#2660)

[Compare Source](https://github.com/sveltejs/kit/compare/@sveltejs/kit@2.65.2...@sveltejs/kit@2.66.0)

##### Minor Changes

- feat: precompress prerendered `.md` and `.mdx` files ([#&#8203;15893](sveltejs/kit#15893))

- feat: warn the user when they forget to make boolean inputs optional in their form schemas ([#&#8203;15804](sveltejs/kit#15804))

##### Patch Changes

- fix: blur active element before component update during navigation so that blur/focusout handlers fire while old component data is still valid ([#&#8203;15452](sveltejs/kit#15452))

- fix: ensure `base` is available from `$service-worker` during development ([#&#8203;15882](sveltejs/kit#15882))

- fix: use correct relative asset paths when rendering an error page for a missing `__data.json` request ([#&#8203;15884](sveltejs/kit#15884))

- fix: preserve active `for await` consumers across `query.live` reconnects ([#&#8203;16022](sveltejs/kit#16022))

- fix: settle `query.live` reconnect promise on all exit paths, preventing `invalidateAll()` from deadlocking when a live query is offline or interrupted ([#&#8203;16022](sveltejs/kit#16022))

- fix: preserve last value when a `query.live` stream completes without yielding on reconnect ([#&#8203;16022](sveltejs/kit#16022))

- fix: remove `types: ['node']` from generated tsconfig to avoid errors when `@types/node` is not installed ([#&#8203;15709](sveltejs/kit#15709))

- fix: prefer pages over endpoints when prerendering ([#&#8203;16076](sveltejs/kit#16076))

- fix: restore snapshots after afterNavigate callbacks ([#&#8203;16066](sveltejs/kit#16066))

- fix: support `ws:`/`wss:` and `trusted-types-eval` for CSP sources ([#&#8203;15938](sveltejs/kit#15938))

- fix: omit empty `file` inputs from remote form data ([#&#8203;15898](sveltejs/kit#15898))

- fix: fail early if a route with `+page` and `+server` is marked as prerenderable ([#&#8203;16075](sveltejs/kit#16075))

- fix: wait a tick before resetting forms ([#&#8203;15805](sveltejs/kit#15805))

- fix: `preflight` schemas apply correctly when chained before `for` ([#&#8203;15863](sveltejs/kit#15863))

- fix: blank page in SPA mode when root layout `load()` throws ([#&#8203;15798](sveltejs/kit#15798))

- fix: pass all unknown options from the `sveltekit` Vite plugin through to `vite-plugin-svelte` ([#&#8203;16010](sveltejs/kit#16010))

### [`v2.65.2`](https://github.com/sveltejs/kit/blob/HEAD/packages/kit/CHANGELOG.md#2652)

[Compare Source](https://github.com/sveltejs/kit/compare/@sveltejs/kit@2.65.1...@sveltejs/kit@2.65.2)

##### Patch Changes

- fix: throw an error when prerendering a root +server.js that returns a non-HTML response ([#&#8203;15994](sveltejs/kit#15994))

- fix: decode base64-serialized fetch bodies before caching them for client-side replay ([#&#8203;16034](sveltejs/kit#16034))

- fix: correctly access explicit dynamic public environment variables from prerendered pages and service workers ([#&#8203;16024](sveltejs/kit#16024))

- fix: allow `preloadCode` to be called during initial page load ([#&#8203;16028](sveltejs/kit#16028))

- fix: send `cache-control: private, no-store` on remote function responses so personalized query results can never be cached by shared caches ([#&#8203;16020](sveltejs/kit#16020))

- fix: preserve the HTTP status and error body when a remote function request fails in transport (e.g. a 401/403 from a `handle` hook), instead of reporting a generic 500 ([#&#8203;16021](sveltejs/kit#16021))

- fix: avoid loading universal nodes during build analysis when the app uses a hash router ([#&#8203;16042](sveltejs/kit#16042))

- fix: correctly serve client entry during development when using the pnpm global virtual store ([#&#8203;16045](sveltejs/kit#16045))

- fix: normalize path separators when comparing config ([#&#8203;16037](sveltejs/kit#16037))

- fix: ensure `building` resolves correctly to allow avoiding build-time explicit environment variable validation ([#&#8203;16058](sveltejs/kit#16058))

- fix: prevent unhandled promise rejections when remote function failures are consumed via `current`/`error` instead of `await` ([#&#8203;16018](sveltejs/kit#16018))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled because a matching PR was automerged previously.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMjAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjIyMC4wIiwidGFyZ2V0QnJhbmNoIjoiZGV2ZWxvcCIsImxhYmVscyI6W119-->

Reviewed-on: https://codeberg.org/huskas-2189/Bookmark/pulls/126
Rich-Harris added a commit that referenced this pull request Jul 30, 2026
…arset parameter (#16567)

The prerenderer compares `content-type` with `===`, so `text/html;
charset=utf-8` is not treated as HTML: the page is written without a
`.html` extension and its links are never crawled. `is_content_type`
already normalizes the header for this reason, from #7195 (strip
parameters) and GHSA-gv7g-x59x-wf8f (case-insensitive compare); the two
prerender checks predate both.

Reproduces #13612, closed as unreproducible, using the charset
workaround from #3184. The root `+server.js` error added in #15994 is
gated on the same value, so it can fire for an app that has none.

Co-authored-by: Nic Polumeyv <nicolas.polum@gmail.com>
Co-authored-by: Rich Harris <richard.a.harris@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Prerendered root +server.js is always saved as index.html

4 participants