cloudflare/vinext

CSP nonce not propagated to `next/dynamic` preload links

Chiusa

#1516 aperta il 22 mag 2026

 (0 commenti) (0 reazioni) (0 assegnatari)TypeScript (371 fork)github user discovery
adapter-api-e2ehelp wanted

Metriche repository

Star
 (8563 stelle)
Metriche merge PR
 (Merge medio 1g 1h) (462 PR mergiate in 30 g)

Descrizione

This issue was created by an agent analysing CI failures from the Next.js Deploy Suite (vinext main vs Next.js v16.2.6, 2026-05-22).

Problem

When a request supplies a CSP nonce via headers(), Next.js attaches nonce="..." to all auto-generated <link rel="modulepreload"> and <script> tags emitted by next/dynamic. vinext does not propagate the nonce, resulting in zero nonce-bearing preload links and CSP violations in the browser.

Expected nonce on dynamic preload links, received none

Estimated Impact

~1 test failures across the deploy suite.

Affected Test Suites

  • test/e2e/app-dir/next-dynamic-csp-nonce/next-dynamic-csp-nonce.test.ts

Recommendation

  1. Reproduce first in vinext's own test suite. Add a next/dynamic component, configure a CSP nonce via headers(), and assert every preload <link> and <script> carries the nonce.

  2. Thread the nonce through dynamic emission. When emitting modulepreload <link> tags and bootstrap <script> tags for next/dynamic, read the request nonce from the request context and add the attribute.


Part of #1328.

Guida contributor