Skip to content

fix: server-only import guard misses entrypoints outside the project root - #16912

Merged
elliott-with-the-longest-name-on-github merged 1 commit into
version-3from
guard-out-of-root-hooks
Aug 25, 2026
Merged

fix: server-only import guard misses entrypoints outside the project root#16912
elliott-with-the-longest-name-on-github merged 1 commit into
version-3from
guard-out-of-root-hooks

Conversation

@Nic-Polumeyv

Copy link
Copy Markdown
Contributor

Ran into this in a monorepo where several apps share one client hooks file. When files.hooks.client points outside the project root, vite-plugin-sveltekit-guard silently stops detecting server-only imports reachable from it. A $app/env/private import in the hooks file builds cleanly instead of throwing, even though out-of-root hooks are supported (their directory is added to server.fs.allow).

The guard's import map keys go through normalize_id, which leaves ids outside the root absolute, but entrypoints were added as root-relative manifest paths like ../shared/hooks.client.js, so the upward walk never matches the hooks file and concludes the import is server-side only. Entrypoints now go through the same normalize_id. The cwd prefix checks also gained a trailing slash, since a sibling directory whose name extends the root's was treated as inside it.

@pkg-svelte-dev

Copy link
Copy Markdown

Install the latest version of @sveltejs/kit from 4376172:

pnpm add https://pkg.svelte.dev/@sveltejs/kit/c/437617288c9dcc77447affdc780c1c74cdd36a79

Open in pkg.svelte.dev: https://pkg.svelte.dev/repos/kit/pr/16912

@changeset-bot

changeset-bot Bot commented Aug 23, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 4376172

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@sveltejs/kit Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@svelte-docs-bot

Copy link
Copy Markdown

@elliott-with-the-longest-name-on-github
elliott-with-the-longest-name-on-github merged commit f2c5102 into version-3 Aug 25, 2026
104 of 106 checks passed
@elliott-with-the-longest-name-on-github
elliott-with-the-longest-name-on-github deleted the guard-out-of-root-hooks branch August 25, 2026 21:27
Rich-Harris pushed a commit that referenced this pull request Aug 26, 2026
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to version-3, this PR
will be updated.

⚠️⚠️⚠️⚠️⚠️⚠️

`version-3` is currently in **pre mode** so this branch has prereleases
rather than normal releases. If you want to exit prereleases, run
`changeset pre exit` on `version-3`.

⚠️⚠️⚠️⚠️⚠️⚠️

# Releases
## @sveltejs/adapter-bun@1.0.0-next.2

### Major Changes

- breaking: require Bun 1.4, which routes `HEAD` to `GET` handlers and
settles `stop()` after a force close
([#16880](#16880))

### Patch Changes

- fix: build apps that use server instrumentation
([#16898](#16898))
- Updated dependencies
[[`ff8cdd4`](ff8cdd4),
[`723572c`](723572c),
[`3b8e034`](3b8e034),
[`f2c5102`](f2c5102),
[`c66a6ed`](c66a6ed),
[`428e5ef`](428e5ef)]:
  - @sveltejs/kit@3.0.0-next.26
## @sveltejs/adapter-node@6.0.0-next.11

### Patch Changes

- chore: remove polka, attach the handler to the http server directly
([#16907](#16907))
- Updated dependencies
[[`ff8cdd4`](ff8cdd4),
[`723572c`](723572c),
[`3b8e034`](3b8e034),
[`f2c5102`](f2c5102),
[`c66a6ed`](c66a6ed),
[`428e5ef`](428e5ef)]:
  - @sveltejs/kit@3.0.0-next.26
## @sveltejs/kit@3.0.0-next.26

### Patch Changes

- fix: only require the `svelte-trusted-html` trusted-types policy when
client-side code is shipped, allowing builds where all pages have `csr:
false` ([#16928](#16928))

- chore: stop externalizing `cookie` dependency during build
([#16936](#16936))

- fix: preserve metadata on streamed page responses
([#16935](#16935))

- fix: error on server-only imports reachable from hooks or service
worker files outside the project root
([#16912](#16912))

- fix: copy worker files emitted by the server build to the client
output directory ([#16929](#16929))

- fix: Reject all pending query promises when a query fails before
resolving with a value for the first time
([#16890](#16890))

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants