求助:为何Heroku部署的站点会加载广告脚本?
Hey there, sorry to hear you're stuck with this frustrating unwanted script issue—nothing throws off a deployment like unexpected code popping up where it shouldn't be. Let's walk through targeted steps to track this down, since you've already ruled out the buildpack and safe mode:
Compare build artifacts between local and Heroku
First, replicate Heroku's build process locally to see if the scripts show up here too. Run the exact publish command Heroku uses (usuallydotnet publish -c Release -o ./publish), then dig into your localpublishfolder for those extra scripts.To cross-check with Heroku's build, spin up a bash session on your app with
heroku run bash. You can inspect files directly (likecat wwwroot/index.htmlto spot injected scripts) or package the build folder into an archive (tar -czf app.tar.gz ./publish) and download it locally for side-by-side comparison. This will tell you if the scripts are added during the build phase or later.Audit your NuGet dependencies
Compromised or malicious packages can sometimes inject code during build or runtime. Rundotnet list packageboth locally and in the Heroku bash session to ensure all package versions match exactly.If there's a mismatch, force a clean restore locally with
dotnet restore --forceto rule out cached packages. Also, scan your dependencies for recent additions, low-download packages, or ones with inactive maintainers—these are common red flags for suspicious behavior.Check Heroku environment variables and add-ons
Even in safe mode, some Heroku add-ons or environment variables might trigger script injection during build. Useheroku configto list all environment variables and cross-reference with your local setup—look for any variables related to analytics, monitoring, or asset processing that you don't recognize.Review your installed Heroku add-ons too. Some monitoring tools inject tracking scripts at build time (not runtime), so safe mode won't disable them. Try temporarily removing non-essential add-ons and redeploying to see if the scripts disappear.
Do a clean, cache-free redeployment
Heroku's build cache can sometimes hold onto old, problematic files. Try clearing the buildpacks first withheroku buildpacks:clear, then re-add thejincod/dotnetcore-buildpackand redeploy withgit push heroku main --force(make sure your local repo is clean, no uncommitted changes first). You can also disable static file caching temporarily withheroku config:set DISABLE_COLLECTSTATIC=1to rule out cached assets.Inspect your app's middleware and startup code
Double-check yourProgram.csorStartup.csfor any middleware that might inject scripts. Even in safe mode, hardcoded middleware (like APM tools, logging utilities, or custom response modifiers) could be adding the scripts. Look for anything that modifies HTTP responses or interacts with static files/HTML views.Dig into the Heroku container's file system
Useheroku run bashto explore the entire app directory. Check for unfamiliar files inwwwroot,Views, or even the.dotnetfolder. Sometimes rogue scripts get dropped into the container during deployment or build. You can also check file modification times withls -lato see if any files were changed unexpectedly.
If none of these steps uncover the issue, try capturing full HTTP responses from both your local app and Heroku. Compare the raw HTML/JS to see if the scripts are injected server-side or if there's a proxy/CDN issue between users and Heroku.
内容的提问来源于stack exchange,提问作者olegshmel

