Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add SRI support for Node.js Runtime #73891

Merged
merged 5 commits into from
Dec 17, 2024
Merged

Add SRI support for Node.js Runtime #73891

merged 5 commits into from
Dec 17, 2024

Conversation

unstubbable
Copy link
Contributor

@unstubbable unstubbable commented Dec 13, 2024

Note

This PR is best reviewed with hidden whitespace changes.

Support for setting Subresource Integrity attributes on app router scripts was added in #39729. But this only covered pages using the Edge Runtime.

With this PR, we're adding support for app pages using the Node.js Runtime. The only change that's needed for that, and which was probably just an oversight in the original PR, is reading the generated manifest file in loadComponents.

In a follow-up we should also add support for adding the integrity attribute to client component chunks that are injected into the head during server-side rendering, but that needs a change in React first.

fixes #66901

@ijjk
Copy link
Member

ijjk commented Dec 13, 2024

Failing test suites

Commit: 417ae25

pnpm test-dev test/e2e/persistent-caching/persistent-caching.test.ts

  • persistent-caching > should persistent cache loaders
Expand output

● persistent-caching › should persistent cache loaders

expect(received).toBe(expected) // Object.is equality

Expected: "Timestamp = 1734467631764"
Received: "Timestamp = 1734467652861"

  55 |       const browser = await next.browser('/pages')
  56 |       // TODO Persistent Caching for webpack dev server is broken
> 57 |       expect(await browser.elementByCss('main').text()).toBe(pagesTimestamp)
     |                                                         ^
  58 |       await browser.close()
  59 |     }
  60 |   })

  at Object.toBe (e2e/persistent-caching/persistent-caching.test.ts:57:57)

Read more about building and testing Next.js in contributing.md.

@ijjk
Copy link
Member

ijjk commented Dec 13, 2024

Stats from current PR

Default Build (Increase detected ⚠️)
General Overall increase ⚠️
vercel/next.js canary vercel/next.js hl/sri-node Change
buildDuration 17.5s 15.6s N/A
buildDurationCached 14.8s 12.4s N/A
nodeModulesSize 410 MB 410 MB ⚠️ +20.1 kB
nextStartRea..uration (ms) 471ms 475ms N/A
Client Bundles (main, webpack)
vercel/next.js canary vercel/next.js hl/sri-node Change
1187-HASH.js gzip 51.4 kB 51.4 kB N/A
8276.HASH.js gzip 169 B 168 B N/A
8377-HASH.js gzip 5.36 kB 5.36 kB N/A
bccd1874-HASH.js gzip 53 kB 53 kB N/A
framework-HASH.js gzip 57.5 kB 57.5 kB N/A
main-app-HASH.js gzip 232 B 235 B N/A
main-HASH.js gzip 34.1 kB 34.1 kB N/A
webpack-HASH.js gzip 1.71 kB 1.71 kB N/A
Overall change 0 B 0 B
Legacy Client Bundles (polyfills)
vercel/next.js canary vercel/next.js hl/sri-node Change
polyfills-HASH.js gzip 39.4 kB 39.4 kB
Overall change 39.4 kB 39.4 kB
Client Pages
vercel/next.js canary vercel/next.js hl/sri-node Change
_app-HASH.js gzip 193 B 193 B
_error-HASH.js gzip 193 B 193 B
amp-HASH.js gzip 512 B 510 B N/A
css-HASH.js gzip 343 B 342 B N/A
dynamic-HASH.js gzip 1.84 kB 1.84 kB
edge-ssr-HASH.js gzip 265 B 265 B
head-HASH.js gzip 363 B 362 B N/A
hooks-HASH.js gzip 393 B 392 B N/A
image-HASH.js gzip 4.49 kB 4.49 kB N/A
index-HASH.js gzip 268 B 268 B
link-HASH.js gzip 2.35 kB 2.34 kB N/A
routerDirect..HASH.js gzip 328 B 328 B
script-HASH.js gzip 397 B 397 B
withRouter-HASH.js gzip 323 B 326 B N/A
1afbb74e6ecf..834.css gzip 106 B 106 B
Overall change 3.59 kB 3.59 kB
Client Build Manifests
vercel/next.js canary vercel/next.js hl/sri-node Change
_buildManifest.js gzip 749 B 746 B N/A
Overall change 0 B 0 B
Rendered Page Sizes
vercel/next.js canary vercel/next.js hl/sri-node Change
index.html gzip 523 B 523 B
link.html gzip 538 B 537 B N/A
withRouter.html gzip 519 B 520 B N/A
Overall change 523 B 523 B
Edge SSR bundle Size
vercel/next.js canary vercel/next.js hl/sri-node Change
edge-ssr.js gzip 128 kB 128 kB N/A
page.js gzip 204 kB 204 kB N/A
Overall change 0 B 0 B
Middleware size
vercel/next.js canary vercel/next.js hl/sri-node Change
middleware-b..fest.js gzip 671 B 669 B N/A
middleware-r..fest.js gzip 155 B 156 B N/A
middleware.js gzip 31.3 kB 31.3 kB N/A
edge-runtime..pack.js gzip 844 B 844 B
Overall change 844 B 844 B
Next Runtimes
vercel/next.js canary vercel/next.js hl/sri-node Change
523-experime...dev.js gzip 322 B 322 B
523.runtime.dev.js gzip 314 B 314 B
app-page-exp...dev.js gzip 324 kB 324 kB
app-page-exp..prod.js gzip 128 kB 128 kB
app-page-tur..prod.js gzip 141 kB 141 kB
app-page-tur..prod.js gzip 136 kB 136 kB
app-page.run...dev.js gzip 314 kB 314 kB
app-page.run..prod.js gzip 124 kB 124 kB
app-route-ex...dev.js gzip 37.5 kB 37.5 kB
app-route-ex..prod.js gzip 25.5 kB 25.5 kB
app-route-tu..prod.js gzip 25.5 kB 25.5 kB
app-route-tu..prod.js gzip 25.3 kB 25.3 kB
app-route.ru...dev.js gzip 39.1 kB 39.1 kB
app-route.ru..prod.js gzip 25.3 kB 25.3 kB
pages-api-tu..prod.js gzip 9.69 kB 9.69 kB
pages-api.ru...dev.js gzip 11.6 kB 11.6 kB
pages-api.ru..prod.js gzip 9.68 kB 9.68 kB
pages-turbo...prod.js gzip 21.7 kB 21.7 kB
pages.runtim...dev.js gzip 27.5 kB 27.5 kB
pages.runtim..prod.js gzip 21.7 kB 21.7 kB
server.runti..prod.js gzip 916 kB 916 kB N/A
Overall change 1.45 MB 1.45 MB
build cache Overall increase ⚠️
vercel/next.js canary vercel/next.js hl/sri-node Change
0.pack gzip 2.08 MB 2.08 MB ⚠️ +1.33 kB
index.pack gzip 73.4 kB 73.5 kB ⚠️ +185 B
Overall change 2.15 MB 2.15 MB ⚠️ +1.52 kB
Diff details
Diff for main-HASH.js

Diff too large to display

Diff for server.runtime.prod.js

Diff too large to display

Commit: b386219

@darthmaim
Copy link
Contributor

This will fix

unstubbable added a commit that referenced this pull request Dec 13, 2024
In #73891 we added another manifest to be loaded in `loadComponents`.
This uncovered a flakiness in prod mode when attempting to load an
optional manifest. The non-existent manifest is attempted to be loaded
three times with 100ms delay between attempts, before giving up. For
some reason this increased loading time leads to more test flakiness.

To mitigate this, we're limiting the retry behaviour to the dev mode,
which matches the original intention when this was introduced in #45244.
@unstubbable unstubbable force-pushed the hl/sri-node branch 2 times, most recently from 8395a2b to f7f6a52 Compare December 13, 2024 17:20
@unstubbable unstubbable marked this pull request as ready for review December 13, 2024 17:21
@unstubbable unstubbable requested a review from wyattjoh December 13, 2024 17:21
unstubbable added a commit that referenced this pull request Dec 13, 2024
In #73891 we added another manifest to be loaded in `loadComponents`
(initially unconditionally). This uncovered a flakiness in prod mode
when attempting to load an optional manifest. The non-existent manifest
is attempted to be loaded three times with 100ms delay between attempts,
before giving up. For some reason the increased loading time leads to
more test flakiness.

To mitigate this, we're limiting the retry behaviour to the dev mode,
which matches the original intention when this was introduced in #45244.
Support for setting [Subresource
Integrity](https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_Integrity)
attributes on app router scripts was added in #39729. But this only
covered pages using the Edge Runtime.

With this PR, we're adding support for pages using the Node.js Runtime.
The only change that's needed for that, and which was probably just an
oversight in the original PR, is reading the generated manifest file in
`loadComponents`.
This reverts commit a3d27b2.

This is not supported by Next.js yet, and will be added in a separate
PR.
@unstubbable unstubbable merged commit 56ea9e9 into canary Dec 17, 2024
124 of 129 checks passed
@unstubbable unstubbable deleted the hl/sri-node branch December 17, 2024 21:41
@lilong7676
Copy link

That's great. Good work 🫶
Just one question, does Nextjs SRI only support app router mode? Will you support it in the future? @unstubbable

ztanner pushed a commit that referenced this pull request Dec 24, 2024
In #73891 we added another manifest to be loaded in `loadComponents`
(initially unconditionally). This uncovered a flakiness in prod mode
when attempting to load an optional manifest. The non-existent manifest
is attempted to be loaded three times with 100ms delay between attempts,
before giving up. For some reason the increased loading time leads to
more test flakiness.

To mitigate this, we're limiting the retry behaviour to the dev mode,
which matches the original intention when this was introduced in #45244.
ztanner pushed a commit that referenced this pull request Dec 24, 2024
In #73891 we added another manifest to be loaded in `loadComponents`
(initially unconditionally). This uncovered a flakiness in prod mode
when attempting to load an optional manifest. The non-existent manifest
is attempted to be loaded three times with 100ms delay between attempts,
before giving up. For some reason the increased loading time leads to
more test flakiness.

To mitigate this, we're limiting the retry behaviour to the dev mode,
which matches the original intention when this was introduced in #45244.
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Jan 10, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Subresource Integrity (SRI) not working
5 participants