Skip to content

fix: only require svelte-trusted-html trusted-types policy when client code ships - #16928

Merged
elliott-with-the-longest-name-on-github merged 3 commits into
sveltejs:version-3from
willfarrell:feature/svelte-trusted-html-skip-no-csr-v3
Aug 25, 2026
Merged

fix: only require svelte-trusted-html trusted-types policy when client code ships#16928
elliott-with-the-longest-name-on-github merged 3 commits into
sveltejs:version-3from
willfarrell:feature/svelte-trusted-html-skip-no-csr-v3

Conversation

@willfarrell

Copy link
Copy Markdown
Contributor

Clone of #16866, but bases off version-3

Previously, setting csp.directives['require-trusted-types-for']: ['script'] without including 'svelte-trusted-html' in trusted-types threw during config validation. This blocked builds of apps where every page has csr: false — those apps ship no client-side code, so the policy is never used.

The check now runs at build time instead, reusing the same statically-analysed page options that decide skip_client_build. If any page ships client code (or its csr option can't be statically analysed), the original error still throws; if all pages have csr: false, the build proceeds.

Note: since the analysis only runs during build, vite dev no longer surfaces the missing policy at startup.

  • packages/kit/src/core/config/index.js — removed the check from validate_config
  • packages/kit/src/exports/vite/index.js — added the check after skip_client_build is computed

Please don't delete this checklist! Before submitting the PR, please make sure you do the following:

  • It's really useful if your PR references an issue where it is discussed ahead of time. In many cases, features are absent for a reason. For large changes, please create an RFC: https://github.com/sveltejs/rfcs
  • This message body should clearly illustrate what problems it solves.
  • Ideally, include a test that fails without this PR but passes with it.

Tests

  • Run the tests with pnpm test and lint the project with pnpm lint and pnpm check

Changesets

  • If your PR makes a change that should be noted in one or more packages' changelogs, generate a changeset by running pnpm changeset and following the prompts. Changesets that add features should be minor and those that fix bugs should be patch. Please prefix changeset messages with feat:, fix:, or chore:.

Edits

  • Please ensure that 'Allow edits from maintainers' is checked. PRs without this option may be closed.

Signed-off-by: will Farrell <willfarrell@proton.me>
@pkg-svelte-dev

pkg-svelte-dev Bot commented Aug 25, 2026

Copy link
Copy Markdown

Install the latest version of @sveltejs/kit from 342c98d:

pnpm add https://pkg.svelte.dev/@sveltejs/kit/c/342c98db79bf71ea4a82440865f6dd31df678a4e

Open in pkg.svelte.dev: https://pkg.svelte.dev/repos/kit/pr/16928

Note

This PR is from a fork. A maintainer must approve approve each commit before it can be built and installed.

@changeset-bot

changeset-bot Bot commented Aug 25, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 342c98d

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@sveltejs/kit Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems reasonable, but needs a test that proves it works and prevents us from regressing it in the future.

Signed-off-by: will Farrell <willfarrell@proton.me>
@willfarrell

Copy link
Copy Markdown
Contributor Author

done. tests added.

@elliott-with-the-longest-name-on-github
elliott-with-the-longest-name-on-github merged commit ff8cdd4 into sveltejs:version-3 Aug 25, 2026
36 of 37 checks passed
@elliott-with-the-longest-name-on-github

Copy link
Copy Markdown
Contributor

Thank you!

Rich-Harris pushed a commit that referenced this pull request Aug 26, 2026
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to version-3, this PR
will be updated.

⚠️⚠️⚠️⚠️⚠️⚠️

`version-3` is currently in **pre mode** so this branch has prereleases
rather than normal releases. If you want to exit prereleases, run
`changeset pre exit` on `version-3`.

⚠️⚠️⚠️⚠️⚠️⚠️

# Releases
## @sveltejs/adapter-bun@1.0.0-next.2

### Major Changes

- breaking: require Bun 1.4, which routes `HEAD` to `GET` handlers and
settles `stop()` after a force close
([#16880](#16880))

### Patch Changes

- fix: build apps that use server instrumentation
([#16898](#16898))
- Updated dependencies
[[`ff8cdd4`](ff8cdd4),
[`723572c`](723572c),
[`3b8e034`](3b8e034),
[`f2c5102`](f2c5102),
[`c66a6ed`](c66a6ed),
[`428e5ef`](428e5ef)]:
  - @sveltejs/kit@3.0.0-next.26
## @sveltejs/adapter-node@6.0.0-next.11

### Patch Changes

- chore: remove polka, attach the handler to the http server directly
([#16907](#16907))
- Updated dependencies
[[`ff8cdd4`](ff8cdd4),
[`723572c`](723572c),
[`3b8e034`](3b8e034),
[`f2c5102`](f2c5102),
[`c66a6ed`](c66a6ed),
[`428e5ef`](428e5ef)]:
  - @sveltejs/kit@3.0.0-next.26
## @sveltejs/kit@3.0.0-next.26

### Patch Changes

- fix: only require the `svelte-trusted-html` trusted-types policy when
client-side code is shipped, allowing builds where all pages have `csr:
false` ([#16928](#16928))

- chore: stop externalizing `cookie` dependency during build
([#16936](#16936))

- fix: preserve metadata on streamed page responses
([#16935](#16935))

- fix: error on server-only imports reachable from hooks or service
worker files outside the project root
([#16912](#16912))

- fix: copy worker files emitted by the server build to the client
output directory ([#16929](#16929))

- fix: Reject all pending query promises when a query fails before
resolving with a value for the first time
([#16890](#16890))

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants