cloudflare/vinext

CSP nonce not propagated to `next/dynamic` preload links

Fermée

#1 516 ouverte le 22 mai 2026

 (0 commentaire) (0 réaction) (0 personne assignée)TypeScript (371 forks)github user discovery
adapter-api-e2ehelp wanted

Métriques du dépôt

Stars
 (8 563 étoiles)
Métriques de merge PR
 (Merge moyen 1j 1h) (462 PRs mergées en 30 j)

Description

This issue was created by an agent analysing CI failures from the Next.js Deploy Suite (vinext main vs Next.js v16.2.6, 2026-05-22).

Problem

When a request supplies a CSP nonce via headers(), Next.js attaches nonce="..." to all auto-generated <link rel="modulepreload"> and <script> tags emitted by next/dynamic. vinext does not propagate the nonce, resulting in zero nonce-bearing preload links and CSP violations in the browser.

Expected nonce on dynamic preload links, received none

Estimated Impact

~1 test failures across the deploy suite.

Affected Test Suites

  • test/e2e/app-dir/next-dynamic-csp-nonce/next-dynamic-csp-nonce.test.ts

Recommendation

  1. Reproduce first in vinext's own test suite. Add a next/dynamic component, configure a CSP nonce via headers(), and assert every preload <link> and <script> carries the nonce.

  2. Thread the nonce through dynamic emission. When emitting modulepreload <link> tags and bootstrap <script> tags for next/dynamic, read the request nonce from the request context and add the attribute.


Part of #1328.

Guide contributeur