--:--:--Douala, Cameroon

Available for work

Next.js

Scanner traffic and the error page that was not there

A routine bot sweep for /.env turned into a 100% error rate on a healthy route, twice, on two different sites.

5 min read

An alert fires: one route at a 100% error rate, dozens of failures, every log line identical. The traffic is a single host running an automated client, probing for /.env and /.DS_Store. No real visitor is affected. The route is fine for everybody else.

How the probe gets in

A localisation proxy has to skip any path containing a dot, or every font and image in your public folder gets handed a language prefix. That exclusion also means dotted paths never reach language negotiation at all. They fall straight through into the dynamic language segment, which happily matches a single path segment, and the application is asked to render a page in a language called .env.

The metadata function usually runs before the layout's validity guard, so the invalid value reaches the translation loader first and the render fails there. The log then reports a missing 500 page, which is a symptom rather than the cause.

Fix the cause, not the symptom

Adding the missing error page would hide the failure and keep the 500 status. The fix is to refuse unknown languages before any of that code runs, so a probe gets a clean 404 and the route never enters an error state.

Nothing flags this. The build is green, every real page works, and it takes a scanner to find it. Which is why it shipped twice.