diff --git a/.changeset/handle-request-nonce-pair.md b/.changeset/handle-request-nonce-pair.md new file mode 100644 index 00000000..0f1d279a --- /dev/null +++ b/.changeset/handle-request-nonce-pair.md @@ -0,0 +1,5 @@ +--- +'@solidjs/vite-plugin': patch +--- + +`handleRequest(request, { nonce })` accepts the `{ script, style }` form of `@solidjs/web`'s `CSPNonce` and uses its `script` value for the scripts the handler writes: the injected client-entry tag and the post-flush redirect fallback. A pair used to throw `TypeError: value.replace is not a function`. The option is now declared in the `virtual:solid-ssr-handler` types. diff --git a/examples/start-ssr/test/run.mjs b/examples/start-ssr/test/run.mjs index a06cf87d..f5007d41 100644 --- a/examples/start-ssr/test/run.mjs +++ b/examples/start-ssr/test/run.mjs @@ -388,6 +388,17 @@ function record(mode, phase, name, ok, detail = '') { console.log(` [${mode}/${phase}] ${status} ${name}${detail && !ok ? ` — ${detail}` : ''}`); } +// Reads a handler call's whole body; a rejection becomes the assertion's +// detail instead of aborting the whole run. +async function settledText(call) { + try { + const response = await call(); + return { text: await response.text(), error: '' }; + } catch (error) { + return { text: '', error: String(error) }; + } +} + // Pull the function id for `name` out of the client-transformed module so // the endpoint can be hit directly. function extractFunctionId(transformedCode, name) { @@ -1446,6 +1457,51 @@ async function runProdMode() { 'client entry carries the escaped CSP nonce', nonceHtml.includes('