Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Start mode: generated entries render without the CSP nonce, and there is no per-request seam to supply one

オープン
#388 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
5/5
見積もり時間
1週間以上
初心者へのやさしさ
35/100
issue の種類
機能追加
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
typescript

調査の方向性

Start in src/ssr/index.ts at the generated-entry sites around lines 932 and 1394, then inspect the nonce handling near line 1279 and the Fetchable around line 1461. Reproduce the issue in examples/start-ssr with the two handleRequest calls; done means generated and authored entries propagate resolved nonce values, dev-injected tags are covered, and the object CSPNonce form no longer throws.

索引モデルが issue の本文から書いたものです。

説明

Problem

A strict CSP (script-src 'nonce-…' 'strict-dynamic', no 'unsafe-inline') cannot be served with Start mode's generated entries. The only nonce input is handleRequest(request, { nonce }), added in #311, and it only reaches two tags: the injected client-entry <script> and the post-flush redirect fallback.

The generated entry renders with a fixed { manifest } and ignores the context it receives:

https://github.com/solidjs/solid-vite-plugin/blob/e4cdee454dbe0a99d9cb566d1dba72a93a9dcac1/src/ssr/index.ts#L932

https://github.com/solidjs/solid-vite-plugin/blob/e4cdee454dbe0a99d9cb566d1dba72a93a9dcac1/src/ssr/index.ts#L1394

So even when a host passes nonce, renderToStream never gets it. The hydration bootstrap (_$HY), the streamed data and swap scripts and the modulepreload links all go out without a nonce, and the page does not hydrate under the policy.

There is also no way to supply the nonce from inside the app:

  • Deployments that dispatch through the default Fetchable (Nitro calls mod.fetch(req)) never pass options. That is intentional, since the second argument of a Fetchable belongs to the host: https://github.com/solidjs/solid-vite-plugin/blob/e4cdee454dbe0a99d9cb566d1dba72a93a9dcac1/src/ssr/index.ts#L1461
  • start.middleware is the natural place to generate the nonce and set the Content-Security-Policy header, but it only sees (request, next). The options bag is fixed before the chain runs.
  • start.setup returns a component and start.renderMode returns a mode, so neither can change the stream options.
  • @solidjs/web only reads the nonce from the renderToStream options, not from the request event or locals.

Today the workaround is hand-written entry-server / entry-client files that pass nonce to renderToStream. Entries come in pairs, so both have to be written, and authored entries also give up the generated DefaultErrorBoundary. SolidStart had a per-request seam for this (createHandler(fn, (event) => ({ nonce })), see solidjs/solid-start#2252). #311 ported the client-entry part of that change.

A related bug: the object form CSPNonce that @solidjs/web accepts ({ script, style }) throws in the client-entry transform, because it escapes the value as a string:

https://github.com/solidjs/solid-vite-plugin/blob/e4cdee454dbe0a99d9cb566d1dba72a93a9dcac1/src/ssr/index.ts#L1279

TypeError: value.replace is not a function
Reproduction

With @solidjs/vite-plugin 3.0.0-next.47 and @solidjs/web 2.0.0-rc.13, in examples/start-ssr:

const html = await (await handleRequest(new Request('http://localhost/'), { nonce: 'abc' })).text();
// only the client-entry <script> carries nonce="abc";
// the _$HY bootstrap, the data scripts and the modulepreload links do not

await handleRequest(new Request('http://localhost/'), { nonce: { script: 'abc', style: false } });
// TypeError: value.replace is not a function
Proposal

A start.nonce option that follows the renderMode module convention. The option names a module that default-exports (event) => CSPNonce | undefined | Promise<…>. The handler resolves it after the middleware chain, next to resolveRenderMode, so a middleware can generate the nonce, set the header and store it on event.locals:

solid({ start: { middleware: './src/middleware.ts', nonce: './src/nonce.ts' }, ssr: true });

// src/nonce.ts
export default (event: RequestEvent) => event.locals.nonce as string | undefined;

The resolved value (or handleRequest's nonce, which keeps precedence) would go to:

  • the generated entry's renderToStream;
  • the client-entry tag and createSSRResponse, both through scriptNonce, which also fixes the object form;
  • in dev, the head tags the handler injects (the style patch and Vite client scripts, the collected styles, and a csp-nonce meta for the styles the Vite client injects);
  • authored entries, as context.nonce.

I have a PR ready and will link it here.

主要言語
TypeScript
スター
520
フォーク
70
平均マージ
21時間 42分
マージ済み PR(30日)
36

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

solidjs/solid-vite-plugin のほかの issue

solidjs/solid-vite-plugin の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。