fix(security): validate supplemental interception selectors - #2976
Merged
Conversation
Member
Author
|
/bigbonk review for issues |
Contributor
Contributor
|
@james-elicx Bonk workflow failed. Check the logs for details. View workflow run · To retry, trigger Bonk again. |
commit: |
Contributor
|
Contributor
Performance benchmarksCompared 0 improved · 0 regressed · 6 within ±1.5%
View detailed results and traces 🟢 improvement · 🔴 regression · ⚫ change below 1.5% · paired base/head |
Member
Author
|
/bigbonk review for issues |
Contributor
Member
Author
|
/bigbonk review for issues |
Contributor
Member
Author
|
/bigbonk review for issues |
Contributor
Member
Author
|
/bigbonk review for issues |
Contributor
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
X-Vinext-Interception-Idvalues before middleware, redirects, or other cacheable early responses_rscURL before cacheable redirectsSecurity impact
Previously arbitrary
interception:*values could add an unbounded cache dimension, early responders could escape exact verification, rollout hashes could collapse different selectors onto one URL key, and origin ISR keys did not include the selector. Unknown or mismatched selectors are now rejected, while graph-owned selectors are isolated by both the canonical URL hash and origin ISR key.Next.js / Cloudflare reference
Next.js gates generated interception rewrites with
Next-Url, emits it inVaryfor interception responses, and validates the header-derived_rscURL hash because CDNs may ignoreVary.X-Vinext-Interception-Idis vinext-specific because supplemental refreshes fan out retained branches; vinext applies the same URL-key principle and additionally validates the ID against its generated route graph.Validation
vp checkvp run vinext#build