AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Experimental.Sri Does Not Add Integrity To Inline Flight Scripts (Self.__Next_f.Push), Breaking Strict CSP Without 'Unsafe-Inline'

With experimental.sri enabled, Next.js App Router adds integrity attributes to external scripts but not to inline flight scripts, causing strict CSP policies without 'unsafe-inline' to block hydration and render client components non-functional.

highConfidence 85%Next.jsAffected V16.2.9Affected Vcanary

Origin Analysis

Next.js SubresourceIntegrityPlugin only processes webpack-emitted assets via compilation.getAssets(), so it cannot hash per-request inline flight scripts. The inline script tag creation in use-flight-response.ts constructs `<script>` or `<script nonce=...>` solely from a nonce, with no integrity property, because it has no access to the SRI manifest keyed by static filenames.
1. git clone https://github.com/bearpong/nextjs-sri-inline-csp-repro && cd nextjs-sri-inline-csp-repro 2. npm install 3. npm run build (SRI enabled via experimental.sri, strict CSP set via headers() — script-src 'self', no 'unsafe-inline', no nonce) 4. npm start (must be production build; next dev masks it) 5. Open http://localhost:3000 and open browser console. Observe repeated CSP violations for inline flight scripts; page does not hydrate.

Fixing Code Block

Edge Case Audit

This patch only adds the integrity attribute to inline scripts; it does not automatically add the corresponding sha256-* source to the Content-Security-Policy header. Users must still include the computed hashes in their CSP (or use a middleware to inject them) for browser execution. Additionally, hashing every inline script on each render adds CPU overhead and may affect streaming performance in high-throughput applications. Rollback: revert the patch to restore previous behavior (rebuild, no persistence). For concurrent rendering, ensure no global mutable hash caching is used; per-request computation is safe.

Ecosystem Topology