CSP nonce not propagated to `next/dynamic` preload links
#1 516 ouverte le 22 mai 2026
Métriques du dépôt
- Stars
- (8 563 étoiles)
- Métriques de merge PR
- (Merge moyen 1j 1h) (462 PRs mergées en 30 j)
Description
This issue was created by an agent analysing CI failures from the Next.js Deploy Suite (vinext
mainvs Next.jsv16.2.6, 2026-05-22).
Problem
When a request supplies a CSP nonce via headers(), Next.js attaches nonce="..." to all auto-generated <link rel="modulepreload"> and <script> tags emitted by next/dynamic. vinext does not propagate the nonce, resulting in zero nonce-bearing preload links and CSP violations in the browser.
Expected nonce on dynamic preload links, received none
Estimated Impact
~1 test failures across the deploy suite.
Affected Test Suites
test/e2e/app-dir/next-dynamic-csp-nonce/next-dynamic-csp-nonce.test.ts
Recommendation
-
Reproduce first in vinext's own test suite. Add a
next/dynamiccomponent, configure a CSP nonce viaheaders(), and assert every preload<link>and<script>carries the nonce. -
Thread the nonce through dynamic emission. When emitting modulepreload
<link>tags and bootstrap<script>tags fornext/dynamic, read the request nonce from the request context and add the attribute.
Part of #1328.