Start mode: generated entries render without the CSP nonce, and there is no per-request seam to supply one
维护者通常 1 天内回复
评估
- 难度
- 5/5
- 预计耗时
- 一周以上
- 新手友好度
- 35/100
- Issue 类型
- 功能
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- typescript
调研方向
Start in src/ssr/index.ts at the generated-entry sites around lines 932 and 1394, then inspect the nonce handling near line 1279 and the Fetchable around line 1461. Reproduce the issue in examples/start-ssr with the two handleRequest calls; done means generated and authored entries propagate resolved nonce values, dev-injected tags are covered, and the object CSPNonce form no longer throws.
由索引模型根据 Issue 内容生成。
描述
Problem
A strict CSP (script-src 'nonce-…' 'strict-dynamic', no 'unsafe-inline') cannot be served with Start mode's generated entries. The only nonce input is handleRequest(request, { nonce }), added in #311, and it only reaches two tags: the injected client-entry <script> and the post-flush redirect fallback.
The generated entry renders with a fixed { manifest } and ignores the context it receives:
So even when a host passes nonce, renderToStream never gets it. The hydration bootstrap (_$HY), the streamed data and swap scripts and the modulepreload links all go out without a nonce, and the page does not hydrate under the policy.
There is also no way to supply the nonce from inside the app:
- Deployments that dispatch through the default Fetchable (Nitro calls
mod.fetch(req)) never pass options. That is intentional, since the second argument of a Fetchable belongs to the host: https://github.com/solidjs/solid-vite-plugin/blob/e4cdee454dbe0a99d9cb566d1dba72a93a9dcac1/src/ssr/index.ts#L1461 start.middlewareis the natural place to generate the nonce and set theContent-Security-Policyheader, but it only sees(request, next). The options bag is fixed before the chain runs.start.setupreturns a component andstart.renderModereturns a mode, so neither can change the stream options.@solidjs/webonly reads the nonce from therenderToStreamoptions, not from the request event orlocals.
Today the workaround is hand-written entry-server / entry-client files that pass nonce to renderToStream. Entries come in pairs, so both have to be written, and authored entries also give up the generated DefaultErrorBoundary. SolidStart had a per-request seam for this (createHandler(fn, (event) => ({ nonce })), see solidjs/solid-start#2252). #311 ported the client-entry part of that change.
A related bug: the object form CSPNonce that @solidjs/web accepts ({ script, style }) throws in the client-entry transform, because it escapes the value as a string:
TypeError: value.replace is not a function
Reproduction
With @solidjs/vite-plugin 3.0.0-next.47 and @solidjs/web 2.0.0-rc.13, in examples/start-ssr:
const html = await (await handleRequest(new Request('http://localhost/'), { nonce: 'abc' })).text();
// only the client-entry <script> carries nonce="abc";
// the _$HY bootstrap, the data scripts and the modulepreload links do not
await handleRequest(new Request('http://localhost/'), { nonce: { script: 'abc', style: false } });
// TypeError: value.replace is not a function
Proposal
A start.nonce option that follows the renderMode module convention. The option names a module that default-exports (event) => CSPNonce | undefined | Promise<…>. The handler resolves it after the middleware chain, next to resolveRenderMode, so a middleware can generate the nonce, set the header and store it on event.locals:
solid({ start: { middleware: './src/middleware.ts', nonce: './src/nonce.ts' }, ssr: true });
// src/nonce.ts
export default (event: RequestEvent) => event.locals.nonce as string | undefined;
The resolved value (or handleRequest's nonce, which keeps precedence) would go to:
- the generated entry's
renderToStream; - the client-entry tag and
createSSRResponse, both throughscriptNonce, which also fixes the object form; - in dev, the head tags the handler injects (the style patch and Vite client scripts, the collected styles, and a
csp-noncemeta for the styles the Vite client injects); - authored entries, as
context.nonce.
I have a PR ready and will link it here.
- 主要语言
- TypeScript
- 星标
- 522
- 派生
- 72
- 平均合并
- 20 小时 1 分钟
- 30 天内合并 PR
- 31
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
solidjs/solid-vite-plugin 的其他 Issue
-
Test environment detection doesn't consider Vitest workspaces可能已有人在做 @carloitaben 于 45 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 78/100
solidjs/solid-vite-plugin#205 · 1 条评论 · 2 个 reaction ·
维护者通常 1 天内回复
-
难度 4/5 3-5 天 新手友好度 65/100
solidjs/solid-vite-plugin#394 ·
维护者通常 1 天内回复
-
Catch-all route chunks are named `_...404_-<hash>.js`; the `..` trips path-traversal guards and breaks the lazy preload可能已有人在做 关联的 PR 仍在进行中或已合并。 未关闭
难度 3/5 1-2 天 新手友好度 68/100
solidjs/solid-vite-plugin#391 ·
维护者通常 1 天内回复
-
难度 4/5 3-5 天 新手友好度 55/100
solidjs/solid-vite-plugin#390 ·
维护者通常 1 天内回复
-
难度 3/5 1-2 天 新手友好度 68/100
solidjs/solid-vite-plugin#387 ·
维护者通常 1 天内回复
查看 solidjs/solid-vite-plugin 的全部 Issue
相似的 Issue
-
难度 2/5 1 小时以内 新手友好度 85/100
capricorn86/happy-dom#2474 ·
维护者通常 2 天内回复
-
难度 2/5 1-3 小时 新手友好度 68/100
JSerwatka/letterboxd-tweaks#81 · 1 条评论 ·
-
难度 2/5 1-3 小时 新手友好度 75/100
siyuan-note/siyuan#20165 ·
维护者通常 1 天内回复
-
难度 1/5 1 小时以内 新手友好度 90/100
polkadot-js/phishing#5716 ·
-
bug
难度 2/5 1-3 小时 新手友好度 90/100
juice-shop/juice-shop#3662 ·
维护者通常 1 天内回复