Skip to content

fix: apply nonce to streaming redirect and SPA entry scripts - #2252

Merged
birkskyum merged 1 commit into
solidjs:mainfrom
birkskyum:fix-issue-1263
Jul 26, 2026
Merged

fix: apply nonce to streaming redirect and SPA entry scripts#2252
birkskyum merged 1 commit into
solidjs:mainfrom
birkskyum:fix-issue-1263

Conversation

@birkskyum

Copy link
Copy Markdown
Member

Closes the remaining CSP gaps from #1263, so a strict script-src policy no longer needs unsafe-inline.

Two script tags weren't picking up the configured nonce:

  • Streaming redirect (server/handler.ts). When a redirect resolves after the shell has flushed, the fallback is a client-side <script>window.location=...</script>. It was emitted without a nonce. Since this string is built as raw HTML rather than JSX, the nonce is escaped on the way in.
  • SPA entry script (server/spa/StartServer.tsx). Now passes nonce, matching what the SSR StartServer already did.

Note that the manifest part of #1263 was already fixed: v2 no longer inlines window.manifest, and HydrationScript already receives the nonce via sharedConfig.context.

Verification

Built the bare fixture with { nonce: "..." } plus a route that sets Location after the shell flushes:

@changeset-bot

changeset-bot Bot commented Jul 26, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 3736277

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@solidjs/start Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@netlify

netlify Bot commented Jul 26, 2026

Copy link
Copy Markdown

Deploy Preview for solid-start-landing-page ready!

Name Link
🔨 Latest commit 3736277
🔍 Latest deploy log https://app.netlify.com/projects/solid-start-landing-page/deploys/6a6622af1baa740008909c5f
😎 Deploy Preview https://deploy-preview-2252--solid-start-landing-page.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@pkg-pr-new

pkg-pr-new Bot commented Jul 26, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@solidjs/start@2252

commit: 3736277

@birkskyum birkskyum added the Start 2.x targeting SolidStart 2.x versions label Jul 26, 2026
@birkskyum
birkskyum merged commit d8f1ea8 into solidjs:main Jul 26, 2026
11 checks passed
brenelz added a commit that referenced this pull request Jul 29, 2026
Brings the v2 rc line (through 2.0.0-rc.6) into the Solid 2 branch.

Ported main features onto the Solid 2 architecture:
- Server-function error handler (#2262): wired through
  handleServerFunctionRequest's transformResult hook and the
  solid-start:server-fn-error-handler virtual module.
- Custom seroval plugins (#2250): serialization.plugins now feeds the
  @solidjs/web codec on both the client transport and the server handler.
- ~ alias fix for workspace packages (#2239): adopted appRootAlias in
  place of the global resolve.alias entry.
- Dev toolbar (#2049, replaces the dev overlay): ported to Solid 2
  (Errored/Loading, onSettled, two-arg createEffect, draft-mutation
  stores, terracotta 2 subpath imports, @solidjs/web Portal/Dynamic/JSX,
  createMemo(async) instead of createResource). Protocol-specific pieces
  (SerovalChunkReader, body-format markers) moved local to the toolbar.
- Deferred stream response via h3 iterable() (#2231), StartHandler type
  (#2234), routerLoad restore (#2228), nonce on streaming redirect
  script (#2252), ResizeObserver-loop filter (#2240) all kept.

Kept deleted (superseded by vite-plugin-solid / @solidjs/web /
@solidjs/router server-function integration): fs-routes tree-shake,
manifest.ts, directives, fns serialization/registration/shared and their
specs. Fixes main landed in those files (#2249, #2238, #2243, #2245,
#2241, #2261) live upstream now and are tracked for porting there.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Start 2.x targeting SolidStart 2.x versions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature/Security]: Convert inline manifest into separate file to improve CSP default settings

2 participants