cloudflare/vinext

CSP nonce not propagated to `next/dynamic` preload links

已关闭

#1,516 创建于 2026年5月22日

 (0 条评论) (0 个反应) (0 位负责人)TypeScript (384 个派生)github user discovery
adapter-api-e2ehelp wanted

仓库指标

星标
 (8,625 个星标)
PR 合并指标
 (平均合并 1天 1小时) (30 天内合并 462 个 PR)

描述

This issue was created by an agent analysing CI failures from the Next.js Deploy Suite (vinext main vs Next.js v16.2.6, 2026-05-22).

Problem

When a request supplies a CSP nonce via headers(), Next.js attaches nonce="..." to all auto-generated <link rel="modulepreload"> and <script> tags emitted by next/dynamic. vinext does not propagate the nonce, resulting in zero nonce-bearing preload links and CSP violations in the browser.

Expected nonce on dynamic preload links, received none

Estimated Impact

~1 test failures across the deploy suite.

Affected Test Suites

  • test/e2e/app-dir/next-dynamic-csp-nonce/next-dynamic-csp-nonce.test.ts

Recommendation

  1. Reproduce first in vinext's own test suite. Add a next/dynamic component, configure a CSP nonce via headers(), and assert every preload <link> and <script> carries the nonce.

  2. Thread the nonce through dynamic emission. When emitting modulepreload <link> tags and bootstrap <script> tags for next/dynamic, read the request nonce from the request context and add the attribute.


Part of #1328.

贡献者指南