cloudflare/vinext

App Router: `next/script` stylesheets and `nonce` propagation incomplete

Fechada

#1.517 aberto em 22 de mai. de 2026

 (0 comentário) (0 reação) (0 responsável)TypeScript (371 forks)github user discovery
adapter-api-e2ehelp wanted

Métricas do repositório

Stars
 (8.563 estrelas)
Métricas de merge de PR
 (Mesclagem média 1d 1h) (462 fundiu PRs em 30d)

Description

This issue was created by an agent analysing CI failures from the Next.js Deploy Suite (vinext main vs Next.js v16.2.6, 2026-05-22).

Problem

The next/script component does not load stylesheets associated with scripts, does not pass through nonce attributes, and does not implement bootstrap-script preinitialization (multiple bootstrap scripts expected; only one rendered).

Stylesheets associated with `next/script` not loaded; nonce missing; preinit bootstrap scripts incomplete

Estimated Impact

~3 test failures across the deploy suite.

Affected Test Suites

  • test/e2e/app-dir/app/index.test.ts (3 failures)

Recommendation

  1. Reproduce first in vinext's own test suite. Add a <Script> with an associated stylesheet and a CSP nonce, plus a fixture asserting multiple preinit bootstrap scripts. Confirm each fails.

  2. Load associated stylesheets. When <Script> has linked stylesheets via the Next.js metadata convention, emit corresponding <link rel="stylesheet"> tags.

  3. Propagate nonce. Add the request nonce to every emitted script/style tag.

  4. Implement bootstrap preinit. Match the number of preinit bootstrap scripts Next.js emits for next/script.


Part of #1328.

Guia do colaborador