仓库指标
- 星标
- (8,625 个星标)
- PR 合并指标
- (平均合并 1天 1小时) (30 天内合并 462 个 PR)
描述
This issue was created by an agent analysing CI failures from the Next.js Deploy Suite (vinext
mainvs Next.jsv16.2.6, 2026-05-22).
Problem
When a request supplies a CSP nonce via headers(), Next.js attaches nonce="..." to all auto-generated <link rel="modulepreload"> and <script> tags emitted by next/dynamic. vinext does not propagate the nonce, resulting in zero nonce-bearing preload links and CSP violations in the browser.
Expected nonce on dynamic preload links, received none
Estimated Impact
~1 test failures across the deploy suite.
Affected Test Suites
test/e2e/app-dir/next-dynamic-csp-nonce/next-dynamic-csp-nonce.test.ts
Recommendation
-
Reproduce first in vinext's own test suite. Add a
next/dynamiccomponent, configure a CSP nonce viaheaders(), and assert every preload<link>and<script>carries the nonce. -
Thread the nonce through dynamic emission. When emitting modulepreload
<link>tags and bootstrap<script>tags fornext/dynamic, read the request nonce from the request context and add the attribute.
Part of #1328.