Skip to content

feat(react-router): support request-scoped CSP nonces in createSentryHandleRequest #23445

Description

@blimmer

Problem

createSentryHandleRequest() does not currently support a request-scoped Content Security Policy nonce.

React Router requires the same nonce in both places when rendering a Framework Mode document:

  1. The nonce prop on <ServerRouter>
  2. The nonce option passed to renderToPipeableStream

https://reactrouter.com/how-to/security

The current helper owns both calls but does not expose a nonce option, and its loadContext argument is unused:

https://github.com/getsentry/sentry-javascript/blob/10.70.0/packages/react-router/src/server/createSentryHandleRequest.tsx

A minimal setup generates a unique nonce in server middleware and stores it in React Router's request context:

const loadContext = new RouterContextProvider();
loadContext.set(cspContext, {
  nonce: crypto.randomBytes(16).toString("base64"),
});

There is currently no way to pass that value through createSentryHandleRequest(). Applications must copy React Router's Node handler and manually compose getMetaTagTransformer() and wrapSentryHandleRequest().

A static nonce option would not be sufficient because CSP nonces must be fresh and unpredictable for each rendered response.

Suggested direction

Could the helper expose a request-aware mechanism for resolving the nonce? For example, without prescribing the final API:

getNonce({ request, loadContext }): string | undefined

The returned value would need to be passed to both:

<ServerRouter nonce={nonce} ... />

and:

renderToPipeableStream(element, { nonce, ... })

The helper should continue to provide Sentry's trace meta-tag injection and request wrapping.

Importing @sentry/react-router/cloudflare is not an appropriate workaround for a Node deployment. This application runs on Node 24 in AWS Lambda, uses renderToPipeableStream and Node streams, and does not run on Cloudflare. Additionally, the Cloudflare transformer cannot provide the nonce to <ServerRouter>.

Versions tested

  • @sentry/react-router: 10.70.0
  • react-router: 8.3.0
  • @react-router/node: 8.3.0
  • react: 19.2.6
  • react-dom: 19.2.6
  • Node.js 24
  • AWS Lambda

Activity

  1. linear-code commented on Aug 17, 2026

    @linear-code
  2. moved this to Waiting for: Product Owner in GitHub Issues with 👀 3on Aug 17, 2026
  3. andreiborza commented on Aug 18, 2026

    @andreiborza
    Member

    Hi, we are currently on a company-wide hackweek and will get back to issue triaging August 24th. We'll take another look then.

  4. moved this from Waiting for: Product Owner to No status in GitHub Issues with 👀 3on Aug 18, 2026
  5. moved this to Waiting for: Product Owner in GitHub Issues with 👀 3on Sep 29, 2026
  6. self-assigned this
    on Sep 29, 2026
  7. moved this from Waiting for: Product Owner to No status in GitHub Issues with 👀 3on Sep 29, 2026
  8. added a commit that references this issue on Sep 29, 2026
    5f395ad
  9. github-actions commented on Oct 1, 2026

    @github-actions
    Contributor

    A PR closing this issue has just been released 🚀

    This issue was referenced by PR #24826, which was included in the 11.2.0 release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions