react-doctor/react-router-csp-nonce-consistency
CSP nonce is not shared across server rendering
- Category: Security
- Severity: error
- Source:
oxlint-plugin-react-doctor - Framework: global
- Enabled when: react-router:7, react-router-framework
- Tags: test-noise
- Default: Enabled
Validate the diagnostic
Confirm the reported code matches this rule before you edit it.
Confirm the reported code matches react-doctor/react-router-csp-nonce-consistency. Compare it with the Before example and verify the same API, framework, and execution context. Treat it as a false positive only when one of those conditions differs.
Compare the code
The corrected pattern shows a focused way to address the diagnostic.
Reported pattern
const html = renderToPipeableStream(
<ServerRouter context={context} nonce={nonce} />,
{},
);Corrected pattern
const html = renderToPipeableStream(
<ServerRouter context={context} nonce={nonce} />,
{ nonce },
);How to fix
Use the corrected pattern as a reference. Preserve behavior that the rule does not require you to change.
Copyable fix prompt
Copy this self-contained prompt into your coding agent after you confirm the diagnostic.
Fix every confirmed
Reference transformation:Before:react-doctor/react-router-csp-nonce-consistency diagnostic in the current repository.
Required change:
- Pass the same request-scoped nonce to ServerRouter and the React server-rendering stream options.const html = renderToPipeableStream(
<ServerRouter context={context} nonce={nonce} />,
{},
);const html = renderToPipeableStream(
<ServerRouter context={context} nonce={nonce} />,
{ nonce },
);Constraints:
- Confirm the reported code matches the Before pattern.
- Make the smallest change that fixes the root cause.
- Preserve behavior and interfaces unrelated to this diagnostic.
- Reuse existing project components, utilities, and conventions.
- Do not introduce render-phase side effects, render-phase state updates, or Hooks rule violations.
- Keep validation and authorization on trusted boundaries. Do not replace them with client-only checks.
- Adapt identifiers and framework details instead of copying blindly.
- Do not disable the rule or suppress matching code.
- Confirm this rule is enabled for the project:
react-router:7, react-router-framework.
Verification:
- Run focused tests for the changed behavior.
- Run React Doctor and confirm this diagnostic no longer appears.
- Report the files changed and any checks you could not run.Related rules
More Security rules from the rules reference:
react-doctor/repository-secret-file: A committed env file, credential, or token is exposed to anyone with repo access and must be rotated, even after you remove it.react-doctor/request-body-mass-assignment: Request input spread without field allowlistreact-doctor/require-pnpm-hardening: pnpm project is missing supply-chain hardening in pnpm-workspace.yaml — set `minimumReleaseAge`, keep `blockExoticSubdeps: true`, and set `trustPolicy: no-downgrade`react-doctor/secret-in-fallback: Hardcoded secret fallback for env varreact-doctor/supabase-client-owned-authz-field: When the client writes authorization columns (`ownerId`, `orgId`, `role`, `isAdmin`) to Supabase, an attacker can forge them and escalate their own access.