Repository navigation
release: v1.0.0-alpha.21 - #49
Merged
Merged
Conversation
release: v1.0.0-alpha.20
…y env repairs Documents the root cause of the deploy job's 3x identical SCP timeout (prod-environment-scoped SSH_HOST/SSH_PORT secrets shadowing the repo-level ones), the successful rerun, and the two live env fixes (Upstash Redis token/TLS, SUPABASE_ANON_KEY naming) needed to get / responding after deploy.
Overriding script-src to allow Stripe/Cloudflare domains dropped
nuxt-security's 'nonce-{{nonce}}' placeholder, which its
50-updateCsp.js Nitro plugin looks for verbatim to substitute the
real per-request nonce into the response CSP header. Without it,
every inline <script> tag on the page (Stripe's own hydration
script, and critically Nuxt's __NUXT_DATA__ payload script) gets a
nonce attribute the header never allow-lists, so the browser blocks
it outright — breaking client hydration entirely (dark mode toggle
and any other client-side reactivity silently no-ops after a
"Cannot read properties of undefined (reading 'app')" error).
Confirmed live on clarify.cativo.dev: CSP header's script-src carried
no 'nonce-*' source across repeated requests, while the HTML's own
nonce attribute correctly rotated per request — proving the header
was never receiving the substitution nuxt-security performs only
when it finds the literal placeholder token.
fix(security): restore nonce placeholder in custom CSP script-src
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixed
nuxt-security's'nonce-{{nonce}}'placeholder in the customscript-srcCSP directive, fixing a production-only client hydration break (dark mode toggle and other client reactivity were silently broken).Deploy notes
This is a same-day hotfix release following v1.0.0-alpha.20's first production deploy. Merging main triggers auto-release and then ci-cd deploy to polaris2, same as alpha.20.