cloudflare/vinext

CSP nonce not propagated to `next/dynamic` preload links

クローズ

#1,516 opened on 2026/05/22

 (0 件のコメント) (0 件のリアクション) (0 人の担当者)TypeScript (384 件のフォーク)github user discovery
adapter-api-e2ehelp wanted

Repository metrics

Stars
 (8,625 個のスター)
PR merge metrics
 (平均マージ 1d 1h) (30d で 462 merged PRs)

説明

This issue was created by an agent analysing CI failures from the Next.js Deploy Suite (vinext main vs Next.js v16.2.6, 2026-05-22).

Problem

When a request supplies a CSP nonce via headers(), Next.js attaches nonce="..." to all auto-generated <link rel="modulepreload"> and <script> tags emitted by next/dynamic. vinext does not propagate the nonce, resulting in zero nonce-bearing preload links and CSP violations in the browser.

Expected nonce on dynamic preload links, received none

Estimated Impact

~1 test failures across the deploy suite.

Affected Test Suites

  • test/e2e/app-dir/next-dynamic-csp-nonce/next-dynamic-csp-nonce.test.ts

Recommendation

  1. Reproduce first in vinext's own test suite. Add a next/dynamic component, configure a CSP nonce via headers(), and assert every preload <link> and <script> carries the nonce.

  2. Thread the nonce through dynamic emission. When emitting modulepreload <link> tags and bootstrap <script> tags for next/dynamic, read the request nonce from the request context and add the attribute.


Part of #1328.

コントリビューターガイド