Skip to content

πŸ› Prerender: strip local server origin from captured HTML + fail-hard leak assertΒ #4502

Description

@PierreBrisorgueil

What β€” Prerendered HTML can ship absolute http://127.0.0.1:<port> asset links; strip the local prerender-server origin from captured HTML and fail the build if any leak remains.
Why β€” Vite's __vitePreload absolutizes lazy-chunk deps via import.meta.resolve against the local prerender-server origin, so a prerendered page can reference an internal URL that is dead in production and leaks build internals.

Scope

  • renderRoute(): sanitize captured HTML β€” strip https?://(127.0.0.1|localhost):<port> (static chunks stay relative already; stripping the origin yields the same root-relative form).
  • Fail-hard build assert AFTER the fail-soft render try/catch: re-read each written prerendered file, throw if the leak pattern remains (a render hiccup stays fail-soft; a leaked internal URL never ships).
  • Unit tests for both behaviors.

First observed on a downstream consumer's release build; fix is generic to the stack prerender plugin.
Scope: validated 2026-07-24
Created via /dev:issue

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions