AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Next 16.3 Regression: HtmlLimitedBots Matching Browser UAs Forces Cacheable PPR Pages To Private/No-Store

In Next.js 16.3, when cacheComponents is enabled and htmlLimitedBots is configured as a broad regex (e.g. /.*/), ordinary browser user agents matching the pattern are treated as limited bots, causing shouldForceDynamicPPRRender to become true. This disables SSG/cacheable PPR responses and emits private, no-cache, no-store, max-age=0, must-revalidate for all such requests, even though the route metadata is compatible with streaming. In 16.2.11 the same configuration kept browser requests cacheable. This regresses CDN cache hit rates and increases origin load.

highConfidence 85%Next.jsAffected V16.3.0Affected V16.3.1-Canary.0

Origin Analysis

Changes in PRs #96364 and #96367 converted htmlLimitedBots into an unconditional experimentalBypassFor rule and made shouldForceDynamicPPRRender = isRoutePPREnabled && !serveStreamingMetadata. For any non-empty user agent matched by the regex, serveStreamingMetadata is false, so all PPR requests are forced into dynamic rendering, bypassing SSG/prerender cache eligibility. The condition does not check whether the route's metadata is actually postponed or incompatible with the streaming shape, so even routes with compatible metadata lose their public cache policy.
1. Clone https://github.com/mdotk/next-163-html-limited-cache-repro 2. npm install 3. npm run build 4. npm start 5. npm run check 6. Observe that Chrome user-agent requests receive private/no-store in 16.3.0 while in 16.2.11 they were cacheable.

Fixing Code Block

Edge Case Audit

This change relies on accurate metadata flags in the prerender manifest. If those flags are missing or incorrectly set in certain PPR routes, the original metadata mismatch may reappear. Test extensively with real bot UAs (Googlebot, Bingbot) and with narrow vs broad htmlLimitedBots patterns before deploying. If any metadata-boundary or hydration error occurs, roll back to Next.js 16.2.11 or temporarily set a more restrictive htmlLimitedBots regex. Avoid using /.*/ in production as it intentionally matches all UAs.

Ecosystem Topology