Repository navigation
[16.3.x] Add CSP nonce to script tags of loading and template files - #98403
Merged
Merged
Conversation
Recreation of #98152 so that deployment test credentials are available in CI Closes #98152 Closes #92803 Original description: > `createComponentStylesAndScripts` renders the script tags for a segment's loading, error, and templatefound files, but unlike getLayerAssets it did not pass `ctx.nonce`. When such a file has a chunk that no layout or client reference has already loaded, the tag is served without a nonce and a nonce-based Content-Security-Policy blocks it. ### What? Patches a bug we encountered while using [nonces](https://nextjs.org/docs/app/guides/content-security-policy#nonces) for a CSP with `strict-dynamic`, as in the docs example. In Turbopack, when a `loading.tsx` (or `error` or `template`) file has a chunk that isn’t already loaded by a layout or client component on the page, Next renders a `<script>` tag for that chunk with no `nonce`. (the same chunk script would’ve gotten a `nonce` if it were emitted for a layout or page). Supersedes #92803; this is the same fix but with a new test included. ### Why? While building out our `loading.tsx` pages, we encountered browsers blocking a script and reporting CSP violations, because chunk scripts did not properly carry a `nonce`. ### How? One-line change to bring `createComponentStylesAndScripts` to parity with `getLayerAssets`. --------- Co-authored-by: Luke Taylor <luket@anthropic.com>
Contributor
Tests PassedCommit: 43b0403 |
gnoff
approved these changes
Sep 9, 2026
15 tasks
4 of 7 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Backport #98398