Skip to content

release: v1.0.0-alpha.21 - #49

Merged
cativo23 merged 8 commits into
mainfrom
release/v1.0.0-alpha.21
Sep 29, 2026
Merged

cativo23 merged 8 commits into
mainfrom
release/v1.0.0-alpha.21

Conversation

@cativo23

Copy link
Copy Markdown
Owner

Fixed

  • Restored nuxt-security's 'nonce-{{nonce}}' placeholder in the custom script-src CSP directive, fixing a production-only client hydration break (dark mode toggle and other client reactivity were silently broken).

Deploy notes

This is a same-day hotfix release following v1.0.0-alpha.20's first production deploy. Merging main triggers auto-release and then ci-cd deploy to polaris2, same as alpha.20.

…y env repairs

Documents the root cause of the deploy job's 3x identical SCP timeout
(prod-environment-scoped SSH_HOST/SSH_PORT secrets shadowing the repo-level
ones), the successful rerun, and the two live env fixes (Upstash Redis
token/TLS, SUPABASE_ANON_KEY naming) needed to get / responding after deploy.
Overriding script-src to allow Stripe/Cloudflare domains dropped
nuxt-security's 'nonce-{{nonce}}' placeholder, which its
50-updateCsp.js Nitro plugin looks for verbatim to substitute the
real per-request nonce into the response CSP header. Without it,
every inline <script> tag on the page (Stripe's own hydration
script, and critically Nuxt's __NUXT_DATA__ payload script) gets a
nonce attribute the header never allow-lists, so the browser blocks
it outright — breaking client hydration entirely (dark mode toggle
and any other client-side reactivity silently no-ops after a
"Cannot read properties of undefined (reading 'app')" error).

Confirmed live on clarify.cativo.dev: CSP header's script-src carried
no 'nonce-*' source across repeated requests, while the HTML's own
nonce attribute correctly rotated per request — proving the header
was never receiving the substitution nuxt-security performs only
when it finds the literal placeholder token.
fix(security): restore nonce placeholder in custom CSP script-src
@cativo23
cativo23 merged commit b8eb011 into main Sep 29, 2026
@cativo23
cativo23 deleted the release/v1.0.0-alpha.21 branch September 29, 2026 01:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant