Skip to content

Scan rule · RSC-ARC-015

Requests go to a development machine

Architecture & SEOSeverity: High

Finds shipped code that sends its requests to localhost, a private network address or a tunnel — these requests never arrive for users.

Why this matters

AI tools like to write the backend address with a fallback: `import.meta.env.VITE_API_URL || "http://localhost:3000"`. If the variable is set when you deploy, the fallback disappears from the code entirely during the build. If it is missing, the fallback stays — and every request goes to the user's own machine.

For your users this means: data does not load, forms send nothing, login hangs. On your own machine you do not notice, because that very server runs there.

We only report an address if it is the base of a request in the shipped code (`fetch`, `axios`, WebSocket). If it sits behind a development-only condition (`location.hostname === "localhost"`, `NODE_ENV === "development"`) or is a library default, the check stays silent. An address that only appears without a request is reported by the weaker rule RSC-ARC-012.

Scan tier

External scan (anonymous)

How to fix it

Set the backend address as an environment variable in the hosting dashboard and redeploy. Remove the development fallback from the code so a missing value shows up instead of silently falling back to localhost.

Scan your own app for free