Skip to content

Add a React Start server-components skill - #7181

Merged
schiller-manuel merged 3 commits into
TanStack:mainfrom
CodingCossack:codex/upstream-react-start-rsc
Apr 13, 2026
Merged

Add a React Start server-components skill#7181
schiller-manuel merged 3 commits into
TanStack:mainfrom
CodingCossack:codex/upstream-react-start-rsc

Conversation

@CodingCossack

@CodingCossackCodingCossack commented Apr 13, 2026

Copy link
Copy Markdown
Contributor

This upstreams the existing TanStack Start RSC skill into the official React Start skills tree.

What changed

  • adds the existing server-components skill under packages/react-start/skills/react-start/
  • preserves the current skill structure, docs, and examples with only mechanical compatibility changes
  • wires the skill into the current React Start intent artifacts

Validation

  • npx @tanstack/intent validate packages/react-start/skills
  • git diff --check -- packages/react-start/skills

Summary by CodeRabbit

  • New Features

    • Added a "Server Components" sub-skill to the React Start skill inventory and skill tree with cross-references.
  • Documentation

    • Added comprehensive Server Components docs: architecture, caching/refresh/SSR modes, composite components, current API notes, debugging & review checklist, sources, and failure-mode guidance.
  • Examples

    • Added multiple end-to-end examples showcasing renderable routes, composite slots, query-owned RSCs, selective-SSR, browser-owned loaders, and Flight streaming.

@coderabbitai

coderabbitaiBot commented Apr 13, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

Pull request was closed or merged during review

📝 Walkthrough

Walkthrough

Adds a new "Server Components" sub-skill to React Start: skill metadata, skill-tree entry, comprehensive docs (architecture, caching/SSR, composite components, API notes, debugging, sources), and six runnable examples demonstrating route/query ownership, selective SSR, slots, and Flight streaming.

Changes

Cohort / File(s)Summary
Skill metadata
packages/react-start/skills/_artifacts/domain_map.yaml, packages/react-start/skills/_artifacts/skill_spec.md, packages/react-start/skills/_artifacts/skill_tree.yaml
Register new server-components sub-skill under deployment-and-rendering; add metadata, dependencies, sources, and three documented failure modes.
Skill docs entry
packages/react-start/skills/react-start/SKILL.md, packages/react-start/skills/react-start/server-components/SKILL.md
Add cross-reference and primary skill doc describing when to apply the skill, invariants, API normalization, decision flows, pattern chooser, and review checklist.
Core guidance & patterns
packages/react-start/skills/react-start/server-components/docs/architecture.md, .../caching-refresh-ssr.md, .../composite-components.md, .../current-api-notes.md
Introduce RSC mental model, cache ownership (router/query/HTTP), refresh/invalidation rules, selective SSR modes, composite-slot semantics, Flight APIs, serialization constraints, and current API conventions (e.g., .inputValidator, structuralSharing: false).
Debugging & sources
packages/react-start/skills/react-start/server-components/docs/debugging-review.md, .../sources.md
Add structured debugging/review workflow, failure-stage checks, bundling/import guidance, checklist, and validated source links with observed API drift notes.
Examples (six)
packages/react-start/skills/react-start/server-components/examples/01-renderable-route-loader.tsx, .../02-composite-slots.tsx, .../03-query-owned-rsc.tsx, .../04-selective-ssr-data-only.tsx, .../05-ssr-false-browser-loader.tsx, .../06-low-level-flight-api-route.tsx
Add runnable examples covering: route-owned renderable, composite slots (children/render-prop/component-prop), query-owned RSC (with structuralSharing: false), selective SSR (ssr: 'data-only'), browser-owned loader (ssr: false), and low-level Flight streaming API + client consumption.

Sequence Diagram(s)

sequenceDiagram
participant Browser as Browser
participant Router as Router
participant QueryClient as QueryClient
participant ServerFn as Server Function
participant RSC as RSC Runtime
Browser->>Router: Navigate /posts/:id
Router->>QueryClient: ensureQueryData(queryKey)
QueryClient->>ServerFn: invoke getPostRsc (server fn / HTTP)
ServerFn->>RSC: renderServerComponent / createCompositeComponent
RSC-->>ServerFn: Flight src or stream
ServerFn-->>QueryClient: return RSC src (structuralSharing: false)
QueryClient-->>Router: resolved data
Router-->>Browser: serialized loader payload (includes RSC src)
Browser->>RSC: createFromFetch / CompositeComponent render (fill slots)
RSC-->>Browser: rendered UI
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Suggested labels

documentation

Suggested reviewers

  • brenelz

Poem

🐰 Hoppity hop, docs in a row,
Server components ready to show.
Slots and streams, cache kept tight,
Examples guide the day and night.
A little rabbit cheers the flow. 🥕✨

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 8.33% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: adding a new React Start server-components skill to the repository, which aligns with all the file modifications across domain mappings, skill tree, documentation, and examples.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

github-actionsBot commented Apr 13, 2026

Copy link
Copy Markdown
Contributor

Bundle Size Benchmarks

  • Commit: 16f6892d6b7c
  • Measured at: 2026-04-13T23:32:05.540Z
  • Baseline source: history:16f6892d6b7c
  • Dashboard: bundle-size history
ScenarioCurrent (gzip)Delta vs baselineRawBrotliTrend
react-router.minimal87.35 KiB0 B (0.00%)274.60 KiB75.97 KiB▅▅▅▅▁▁▁▁▁▁█
react-router.full90.60 KiB0 B (0.00%)285.67 KiB78.76 KiB████▁▁▁▁▁▁▃
solid-router.minimal35.51 KiB0 B (0.00%)106.60 KiB31.91 KiB████▁▁▁▁▁▁▃
solid-router.full39.99 KiB0 B (0.00%)120.09 KiB35.93 KiB████▁▁▁▁▁▁▆
vue-router.minimal53.30 KiB0 B (0.00%)152.01 KiB47.88 KiB████▁▁▁▁▁▁▄
vue-router.full58.20 KiB0 B (0.00%)167.43 KiB52.06 KiB████▁▁▁▁▁▁▄
react-start.minimal101.74 KiB0 B (0.00%)322.32 KiB87.98 KiB████▁▁▁▁▁▁▆
react-start.full105.18 KiB0 B (0.00%)332.66 KiB90.97 KiB████▁▁▁▁▁▁▄
solid-start.minimal49.52 KiB0 B (0.00%)152.41 KiB43.66 KiB████▁▁▁▁▁▁▄
solid-start.full55.04 KiB0 B (0.00%)168.61 KiB48.44 KiB████▁▁▁▁▁▁▅

Trend sparkline is historical gzip bytes ending with this PR measurement; lower is better.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/react-start/skills/_artifacts/domain_map.yaml`:
- Line 469: The YAML bullet "Selective SSR modes (ssr: 'data-only', ssr: false)"
contains an unquoted colon which makes the scalar invalid; update the bullet
value (the entire string containing "Selective SSR modes (ssr: 'data-only', ssr:
false)") to be a quoted scalar (e.g., wrap the whole item in single or double
quotes) so the colon in "ssr: false" is treated as part of the string and the
YAML parses correctly.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: cd76a75f-45f7-4726-9f94-949149d5fbf3

📥 Commits

Reviewing files that changed from the base of the PR and between f1a4973 and da6ab52.

📒 Files selected for processing (17)
  • packages/react-start/skills/_artifacts/domain_map.yaml
  • packages/react-start/skills/_artifacts/skill_spec.md
  • packages/react-start/skills/_artifacts/skill_tree.yaml
  • packages/react-start/skills/react-start/SKILL.md
  • packages/react-start/skills/react-start/server-components/SKILL.md
  • packages/react-start/skills/react-start/server-components/docs/architecture.md
  • packages/react-start/skills/react-start/server-components/docs/caching-refresh-ssr.md
  • packages/react-start/skills/react-start/server-components/docs/composite-components.md
  • packages/react-start/skills/react-start/server-components/docs/current-api-notes.md
  • packages/react-start/skills/react-start/server-components/docs/debugging-review.md
  • packages/react-start/skills/react-start/server-components/docs/sources.md
  • packages/react-start/skills/react-start/server-components/examples/01-renderable-route-loader.tsx
  • packages/react-start/skills/react-start/server-components/examples/02-composite-slots.tsx
  • packages/react-start/skills/react-start/server-components/examples/03-query-owned-rsc.tsx
  • packages/react-start/skills/react-start/server-components/examples/04-selective-ssr-data-only.tsx
  • packages/react-start/skills/react-start/server-components/examples/05-ssr-false-browser-loader.tsx
  • packages/react-start/skills/react-start/server-components/examples/06-low-level-flight-api-route.tsx

Comment threadpackages/react-start/skills/_artifacts/domain_map.yaml Outdated
@nx-cloud

nx-cloudBot commented Apr 13, 2026

Copy link
Copy Markdown
Contributor

View your CI Pipeline Execution ↗ for commit df501ca

CommandStatusDurationResult
nx affected --targets=test:eslint,test:unit,tes...✅ Succeeded11m 9sView ↗
nx run-many --target=build --exclude=examples/*...✅ Succeeded22sView ↗

☁️ Nx Cloud last updated this comment at 2026-04-13 23:44:06 UTC

@schiller-manuel
schiller-manuel merged commit 8caa202 into TanStack:mainApr 13, 2026
15 of 16 checks passed
@codspeed-hq

Copy link
Copy Markdown

Merging this PR will not alter performance

✅ 6 untouched benchmarks


Comparing CodingCossack:codex/upstream-react-start-rsc (df501ca) with main (16f6892)

Open in CodSpeed

birkskyum added a commit that referenced this pull request Jun 1, 2026
* fix: republish react-start-rsc dependency chain
* ci: changeset release
* chore: sync published start package versions
* ci: changeset release
* fix publishing
* ci: changeset release
* fix
* ci: apply automated fixes
* ci: changeset release
* refactor: switch router stores to atom get/set API (#7150)
* ci: changeset release
* refactor: shorten internal router store names (#7152)
* ci: changeset release
* chore(types): re-export SearchMiddleware type from react-router (#7087)
* fix(start-plugin-core): reuse deduped server function ids across compilers (#7153)
* ci: changeset release
* fix(router-core): avoid false notFound matches for proxied loader data (#7156)
* fix(router-core): avoid false notFound matches for proxied loader data
* test(react-start): cover proxied loader data notFound regression
* test(react-start): move notFound regression to rsc direct loader
* chore: add changeset
* ci: changeset release
* fix: reduce start SSR manifest asset duplication (#7157)
Co-authored-by: schiller-manuel <schiller-manuel@users.noreply.github.com>
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
* ci: changeset release
* docs: fix file extension syntax for prefix/suffix routing examples (#7149)
docs: fix file-based routing examples with literal dots
* chore: bump to h3 v2 rc.20 (#7140)
* ci: changeset release
* chore: stabilize tests (#7159)
* chore: add vite 8 to peer deps (#7160)
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* ci: changeset release
* chore(start-server-core): remove unnecessary `any` in `getRequestHeaders` (#7164)
* fix(router-generator): harden route file transform rewrites (#7167)
* fix docs (#7168)
* ci: changeset release
* fix(router-plugin): update vite-plugin-solid peer dependency to support version 3.0.0-0 (#7170)
* ci: changeset release
* fix(router-generator): normalize virtual physical subtree paths (#7169)
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* ci: changeset release
* fix: unify virtual module handling for Start Vite plugins (#7178)
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Co-authored-by: CodeRabbit <noreply@coderabbit.ai>
Co-authored-by: schiller-manuel <schiller-manuel@users.noreply.github.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
* ci: changeset release
* fix: add react-server server export for react-start (#7180)
* ci: changeset release
* fix(docs): correct server function name in example (#7173)
* fix react server exports for start and react-router (#7183)
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
* chore: stabilize tests (#7185)
* ci: changeset release
* fix(router-core): avoid intermediate success state for async notFound (#7184)
* ci: changeset release
* Add a React Start server-components skill (#7181)
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* chore: add sharding for playwright tests (#7187)
* add sharding
* fix dependnancy
* fix playwright shard port reuse
* full bust
* throw more runners into this run
* try to throw money at it and see the effect
* tune
* fix react-router shared route css persistence on nav (#7186)
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
* ci: changeset release
* chore: stabilize test (#7192)
* fix(start): include Vite style.css when cssCodeSplit is disabled (#7191)
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
* ci: changeset release
* chore: bump solid-js override 1.9.12 (#7202)
* chore: bump query override to 5.99.0 (#7203)
* fix(solid-router): use keyed Show in Outlet to fix child route rendering with useQuery (#7204)
* ci: changeset release
* docs(start): fix authenticated routes doc URL (#7214)
* chore(deps): vitest 4.1.4 (#7212)
* stabilize rsc tests (#7217)
* fix(react-router): prevent webpack static analysis of React.use with let binding (#7182)
* ci: changeset release
* stabilize test (#7220)
* chore: unify react-start basic e2e mode projects (#7206)
* feat(nx): support rsbuild in Playwright inference (#7221)
* test(e2e-rsc): migrate to playwrightModes and dynamic inferred dist (#7222)
* fix(nx): align playwright mode build target naming (#7223)
* docs(start): add missing space after comma in 'Handling requests with a body' (#7234)
* update intent workflow (#7243)
* rsbuild plugin (#7228)
Co-authored-by: neverland <chenjiahan.jait@bytedance.com>
Co-authored-by: Keven Arroyo <dake.3601@gmail.com>
* ci: changeset release
* fix: Split Start plugin core (#7249)
* ci: changeset release
* update intent workflow (#7244)
* fix: asset sorting (#7251)
* ci: changeset release
* chore(deps): update Rsbuild related deps to v2.0.1 (#7245)
* fix actions again? (#7252)
* inline css (#7253)
* ci: changeset release
* fix: do not import 'react-refresh/runtime' (#7255)
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
* ci: changeset release
* chore(examples): checkin git outdated route-tree files for react and solid examples (#7257)
* add new bundlesize measurements for rsbuild (#7256)
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
* refactor(router-plugin): upgrade unplugin to `v3` (#7258)
* refactor(router-plugin): upgrade unplugin to `v3`
* refactor(start-client-core): use a more explicit typing to `CustomFetch` type
* chore(examples): runtime enforce for needing the `VITE_CONVEX_URL`
* ci: changeset release
* fix: issue 7240 causing fouc (#7250)
* fix: server middleware type in solid-router (#7260)
* replace tsx by jiti (#7261)
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
* ci: changeset release
* docs: Fix server function middleware prop (#7262)
* feat(query): add support for custom dehydrate and hydrate options in SSR integration (#7246)
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* ci: changeset release
* fix: use loader data goes undefined (#7265)
* fix: streaming when using Await component (#7264)
* ci: changeset release
* fix(solid-start): bundle solid-query packages during SSR to fix duplicate QueryClientContext (#6151) (#7267)
* ci: changeset release
* fix(solid-router): hydration mismatch for ssr='data-only' with pendingComponent (#7266)
* docs(router): fix typo in doc (#7268)
* ci: changeset release
* fix(router-core): wildcard nodes respect DFS priority like other nodes in route matching (#7273)
* ci: changeset release
* fix(solid-router): enable route component HMR for Solid
* ci: apply automated fixes
* Revert "ci: apply automated fixes"
This reverts commit 7122f28.
* Revert "fix(solid-router): enable route component HMR for Solid"
This reverts commit b86b061.
* fix(react-start-rsc): re-export renderable types from public entries (#7278)
* fix(react-start-rsc): re-export renderable types from public entries
* changeset - patch
* ci: changeset release
* fix: disabled topLevelVar (#7293)
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* ci: changeset release
* fix: fix exports for react-start so useServerFn is available with RSC (#7292)
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
* feat: match params (#7263)
* ci: changeset release
* fix(start-plugin-core): sort server fn manifest entries for deterministic build output (#7287)
Co-authored-by: Dor Alagem <doralagem@MacBook-Pro-sl-Dor.local>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Manuel Schiller <meisterpink@gmail.com>
* docs: remove redundant code example from query integration doc (#7298)
* ci: changeset release
* fix: Ignore fully type-only imports and re-exports when collecting im… (#7305)
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* ci: changeset release
* feat: `strict: false` for server functions (#7277)
* feat: `strict: false` for server functions
Add a `strict` option to `createServerFn` for type-level server function serialization checks
* feat: `strict: false` for server functions [Self-Healing CI Rerun]
---------
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
* ci: changeset release
* fix: parse params union inference (#7306)
* ci: changeset release
* feat: rsc css (#7310)
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* ci: changeset release
* fix(router-plugin): isolate route metadata per plugin instance (#7313)
* ci: changeset release
* docs: Improve key differences b/w Start Server Functions and Next.js Server Actions (#7312)
* fix(deps): move fetchdts from devDependencies to dependencies (#7317)
* Revise bug report template for clarity and requirements
Updated the bug report template to clarify the requirements for a reproducer project and modified some labels and descriptions for better clarity.
* ci: changeset release
* chore: fix duplicate "the" typo across router packages (#7323)
* feat: early hints (#7324)
* ci: changeset release
* feat: Link header (#7327)
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
* ci: changeset release
* docs(skills): address 8 agent failure modes from user feedback (#7314)
* docs(skills): address 8 agent failure modes from external feedback
Adds new start-core/auth-server-primitives skill (sessions, cookies,
OAuth+PKCE, password-reset enumeration defense, CSRF, rate limiting,
session rotation) and updates 8 existing skills + matching docs to fix
patterns where agents produce insecure or wrong-framework output.
Skill changes:
- new: start-core/auth-server-primitives (server half of auth)
- router-core/auth-and-guards: route guard != RPC guard
- start-core/server-functions: wrong import path, RPC auth required,
Cache-Control public is a cross-tenant leak, wrong-framework patterns
- start-core/middleware: wrong import path, sendContext shape vs access
(3-layer wrong/still-wrong/correct), authMiddleware framing
- start-core/execution-model: file markers (server-only/client-only),
module-level process.env is undefined under Worker SSR
- start-core/deployment: cloudflare env-at-request-time
- router-core/ssr: wrong file structures (next.js, react-router-dom)
- router-core/type-safety: wrong-framework imports + structures
Docs updated to mirror each skill change so source-of-truth and the
intent-indexed skill stay in sync. New authentication-server-primitives
guide is the long-form companion to the new skill.
intent validate: 30 skill files pass (was 29).
* ci: apply automated fixes
* docs(skills): address coderabbit review feedback
- Fix internal docs links to use correct relative paths instead of an
absolute /start/latest/... URL and missing one ../ segment
- Remove blank line inside auth-and-guards blockquote (markdownlint MD028)
- Restore overload pattern in type-safety ValidateNavigateOptions and
ValidateRedirectOptions examples; the casts I had introduced stripped
generic context and contradicted the skill's own no-cast rule
- Add db.sessions.revokeAllForUser before create in login rotation
snippets so the example matches the prose
- Soften useServerFn guidance: it's required only when the server
function throws redirect/notFound; plain-data calls work directly and
via useMutation/useQuery
* ci: apply automated fixes
* docs(skills): compress type-safety to stay under 500-line cap
Prettier's autofix expanded my single-line overload signatures across
multiple lines, pushing the file over the 500-line limit. Drop the
redundant fetchOrRedirect example (same pattern as useDelayedNavigate)
and describe ValidateRedirectOptions usage in prose instead.
* docs(skills): CSRF origin check should compare full origin, not host alone
Comparing only new URL(origin).host against APP_HOST silently accepts a
mismatched scheme — http://example.com would pass a check meant for
https://example.com. Compare the full origin (scheme + host + port)
against APP_ORIGIN instead. Same fix in skill and docs.
* docs(skills): make useDelayedNavigate callback truly return void
The callback returned the result of setTimeout (a timer handle), not
void as the public overload's return type implied. Wrap in a block so
the example matches the declared return type.
Skipped the related nitpick to add a separate redirect example — the
existing prose already describes the same overload pattern, and a
duplicate example would push the file close to the 500-line cap that
prettier autofix has been bumping us against.
* docs(skills): fix two real bugs in auth-server-primitives examples
1. Cookie parser truncated values containing '='. Signed cookies, JWTs,
and base64-padded values all use '='. Use indexOf to split on the
FIRST '=' only.
2. Login example short-circuited verifyPasswordHash on user-not-found,
contradicting the prose's "same time, same error" claim — the
no-user branch returned instantly while wrong-password spent ~100ms
hashing, leaking account existence over the wire. Always verify
against a hash; use a precomputed DUMMY_PASSWORD_HASH when the user
is missing, then combine with the user-exists bit for the final ok.
Same fixes in the SKILL.md and the docs companion.
* docs(skills): address manuel's review on react-specific guides
- middleware.md, server-functions.md: drop cross-framework <framework>
placeholders; this is the React-specific guide, just say
@tanstack/react-start
- execution-model.md: drop the same trailing line about solid-start /
vue-start paths
- hosting.md: remove the Cloudflare env-handling subsection — the
general per-request rule lives in environment-variables.md and
doesn't need to be repeated under a specific host
- environment-variables.md: mention the cloudflare:workers env binding
as the canonical Cloudflare way to read env (including module scope),
per Manuel's link to the Cloudflare docs
- deployment skill: same upgrade — show the cloudflare:workers env
pattern alongside the per-request handler approach
* docs(skills): drop redundant server-only marker in session example
The file already imports from @tanstack/react-start/server, which is
on import protection's default client-deny specifier list. The
side-effect marker is redundant — drop it. Same fix in skill and docs.
* docs(skills): drop wrong-import-path mistakes — TS already catches them
Manuel pointed out that TypeScript catches both common wrong paths:
'@tanstack/react-router' has no exported member createServerFn /
createMiddleware, and '@tanstack/start' is "Cannot find module". Skill
space is precious; the items don't earn their slot if tsc handles them.
Removed:
- Common Mistake "Wrong import path" from server-functions and
middleware skills (renumbered the remaining mistakes)
- The matching top-of-file CRITICAL line in both skills
- The "Import path" callouts in the middleware and server-functions
docs
---------
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* remove old intent artifacts (#7333)
* fix(start-server-core): fall back to GET handler for HEAD requests (RFC 9110 §9.3.2) (#7325)
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* ci: changeset release
* test: add reproducer for #2514 (#7336)
* test: reproducer for #2547 (#7337)
* fix: fix plain TypeScript parser handling (#7342)
* ci: changeset release
* fix: disable rsbuild server compression (#7348)
* fix: update deps (#7340)
* ci: changeset release
* update bundlesize benchmark (#7356)
* fix: Bump jiti to 2.7.0 (#7355)
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
* ci: apply automated fixes
* ci: changeset release
* Document server function strict serialization options (#7358)
* Document server function strict option
Agent-Logs-Url: https://github.com/TanStack/router/sessions/8deabe7a-7412-455e-9111-97a13cb4582e
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
* Refine strict docs wording
Agent-Logs-Url: https://github.com/TanStack/router/sessions/e2857d6e-314e-496c-b99b-78c207c28c77
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
* feat(start): CSRF middleware (#7373)
* fix(router-core): fix missing closing paren in CSS.supports check for view transition types (#7369)
* fix: fix jiti usage for tsconfig paths (#7382)
* Enable jiti tsconfig path aliases
Agent-Logs-Url: https://github.com/TanStack/router/sessions/0a481c9b-eb97-4543-acc5-71d43b97d386
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
* Use fixture for jiti tsconfig aliases
Agent-Logs-Url: https://github.com/TanStack/router/sessions/182b9baa-9e54-4813-a322-c33a1da5417d
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
* Track fixture path alias helper
Agent-Logs-Url: https://github.com/TanStack/router/sessions/182b9baa-9e54-4813-a322-c33a1da5417d
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
* Add router-generator changeset
Agent-Logs-Url: https://github.com/TanStack/router/sessions/ab1a42cc-7326-4e36-a656-f01179221cee
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
* Format virtual config fixture
Agent-Logs-Url: https://github.com/TanStack/router/sessions/22194166-b3a7-431e-b723-ad594d4b0405
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
* Update bundle-size.yml
* Update labeler.yml
* Update bundle-size.yml
* ci: add pinGitHubActionDigests (#7387)
* chore(deps): pin dependencies (#7388)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* minor semver bump to all packages (#7395)
* ci: zizmor (#7389)
* chore(pnpm): update pnpm to v11 (#7392)
* chore: add CODEOWNERS file (#7394)
* chore: add CODEOWNERS file
* chore: add Nx and NPMRC
* Update .github/CODEOWNERS
---------
Co-authored-by: Nicolas Beaussart <nic.beaussart@gmail.com>
* fix: revert plugin changes, createCsrfMiddleware compilation, fix HMR tests (#7400)
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Manuel Schiller <manuel.schiller@caligano.de>
* ci: align release workflow to query (#7404)
* ci: Version Packages (#7405)
ci: changeset release
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* feat(start): add inline CSS runtime controls and asset URL templates (#7380)
* ci: Version Packages (#7407)
* fix: Fix literal underscore paths under pathless layouts (#7408)
* ci: Version Packages (#7409)
ci: changeset release
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* feat(router-core): params.priority route option as tie breaker in matching algorithm (#7411)
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* ci: Version Packages (#7413)
* fix(router-core): hydrate before initial client route match (#7416)
* ci: Version Packages (#7417)
* fix(router-plugin): detect typed root route context for HMR (#7420)
* ci: Version Packages (#7421)
* fix: fix route mismatch warnings and HMR route indexes (#7422)
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* ci: Version Packages (#7423)
* security: stricter pnpm config blockExoticSubdeps & trustPolicy (#7425)
* docs(start): use router package for module declaration to type the request context (#7427)
* feat: deferred hydration (#7362)
* feat: deferred hydration
* fix
* tests
* solid tests
* Changes before error encountered
Agent-Logs-Url: https://github.com/TanStack/router/sessions/5263c469-75c2-4470-bd4c-86f9b43964f4
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
* chore: address hydration review follow-ups
Agent-Logs-Url: https://github.com/TanStack/router/sessions/16e27113-ff01-4de8-aded-b9be9f6dd4ff
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
* fix(start-client-core): correct import order in hydrateStart.ts
Co-authored-by: schiller-manuel <schiller-manuel@users.noreply.github.com>
* chore: remove tracked nx self-healing artifacts
Agent-Logs-Url: https://github.com/TanStack/router/sessions/95750760-1348-437c-8f73-cc45e899003a
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
Co-authored-by: schiller-manuel <schiller-manuel@users.noreply.github.com>
* chore: update @swc/core in example/react/quickstart-webpack-file-based (#7434)
* chore: update @swc/core in example/react/quickstart-webpack-file-based
* chore: update @swc/core in example/react/quickstart-webpack-file-based [Self-Healing CI Rerun]
---------
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
* docs(start): compare deferred hydration to Astro islands (#7438)
Adds a short mental-model section answering the common question
about how TanStack Start's deferred hydration relates to Astro
islands.
* docs(start): compare deferred hydration to React selective hydration (#7442)
Adds a short comparison section answering the common question about how
TanStack Start's deferred hydration relates to React 18's selective
hydration. The framing: selective hydration controls the order of
inevitable hydration work; deferred hydration controls whether and when
that work happens at all.
* chore: update chokidar to v5 (#7439)
* chore: update @rolldown/pluginutils to 1.0.1 (#7440)
* chore: update zod to v4.4.3 (#7441)
* chore: update zod to v4.4.3
* fix(start): preserve route path defaults
* fix(examples): resolve zod 4 build failures
* chore: update express and webpack-dev-server (#7443)
* chore: update express to v5.2.1
* chore: update webpack-dev-server to v5.2.4
* ci: Version Packages (#7435)
ci: changeset release
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* chore: ignore nx generated folders (#7451)
* perf: optimize and test rewrite (#7448)
optimize and test rewrite
* fix: fix scroll restoration issues (#7447)
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* ci: Version Packages (#7452)
* fix: Fix escaped underscore index route generation (#7453)
* ci: Version Packages (#7454)
* ci: fix release notes diff range after Release PR flow (#7456)
* fix(start): explicitly re-export public API to survive SSR cold-start cycle (#7466)
* fix: Fix hash scrolling with `resetScroll={false}` (#7464)
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
* chore: enforce pnpm 11 (#7465)
* ci: Version Packages (#7467)
* chore: only run autofix on PRs (#7469)
* feat(start): support rsbuild iife client output (#7477)
* ci: Version Packages (#7478)
* fix: bundled dev support for vite (#7482)
* ci: Version Packages (#7483)
* fix(start): avoid encoded virtual adapter ids in vite dev (#7484)
* fix release (#7487)
* ci: Version Packages (#7485)
* chore: migrate changesets changelog generator (#7490)
* fix: Fix Hydrate re-exports to avoid circular HMR updates (#7492)
* ci: Version Packages (#7493)
* fix(start): emit boot-sibling chunks as scripts for IIFE entries (#7501)
Co-authored-by: Keven Arroyo <kevenarroyo@microsoft.com>
* ci: Version Packages (#7502)
* chore: stabilize tests (#7503)
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* fix: fix streaming (#7497)
* ci: Version Packages (#7504)
ci: changeset release
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* ci: update all actions (#7506)
* ci: update all actions
* disable package manager cache
* fix: fix primitive beforeLoad errors (#7505)
* fix: fix primitive beforeLoad errors
* ci: apply automated fixes
---------
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* ci: Version Packages (#7508)
* feat(rsbuild): add RSC support (#7509)
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* ci: Version Packages (#7513)
* fix(solid): resolve Solid 2 merge issues
* ci: apply automated fixes
* use v2 query
* fix solid v2 imports
* solid v2 port of new e2e
* solid v2
* nxignore solid v1 peer deps
* use "@rsbuild/plugin-solid": "^2.0.0-beta.0",
* fix hydrationscript
* add nohydration
* remove early return
* fix: solid-start hydration
* fix: update createEffect to return true for hydration signals
* remove nxignore
* add back nxignore for 3rdparty deps
* $_TSR stub to fix serialization tests
* Revert "$_TSR stub to fix serialization tests"
This reverts commit ef802e9.
* fix: update solid selective ssr links
* fix: stream solid Await fallback
* align solid-start basic by removing test:e2e
* remove unusese build:prerender build:spa
* fix: clean up solid hydrate fallback dom
* fix: resolve solid wrapper children
* fix: stabilize serialization stream e2e test
* fix: keep SSR globals through document parse
* html standard mode
* clean
* fix: pass solid ssr manifest
* use await fallback
---------
Co-authored-by: Tanner Linsley <tannerlinsley@gmail.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Manuel Schiller <manuel.schiller@caligano.de>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Flo <fpellet@ensc.fr>
Co-authored-by: James Howard <james@reetgood.co.uk>
Co-authored-by: schiller-manuel <schiller-manuel@users.noreply.github.com>
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
Co-authored-by: Mohamed Khaled <mohamedkhaled012@yahoo.com>
Co-authored-by: Birk Skyum <74932975+birkskyum@users.noreply.github.com>
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Ulrich Stark <github@ustark.de>
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Co-authored-by: CodeRabbit <noreply@coderabbit.ai>
Co-authored-by: MoonBrillante <32852571+MoonBrillante@users.noreply.github.com>
Co-authored-by: Coding Cossack <108333654+CodingCossack@users.noreply.github.com>
Co-authored-by: Nicolas Beaussart <nic.beaussart@gmail.com>
Co-authored-by: Pavan Shinde <pavann97@gmail.com>
Co-authored-by: mixelburg <52622705+mixelburg@users.noreply.github.com>
Co-authored-by: Mukunda Rao Katta <mukunda.vjcs6@gmail.com>
Co-authored-by: Sarah Gerrard <gerrardsarah@gmail.com>
Co-authored-by: neverland <chenjiahan.jait@bytedance.com>
Co-authored-by: Keven Arroyo <dake.3601@gmail.com>
Co-authored-by: Sean Cassiere <33615041+SeanCassiere@users.noreply.github.com>
Co-authored-by: Abhishek Raj <abhi@raj.me>
Co-authored-by: Dominik Dorfmeister 🔮 <office@dorfmeister.cc>
Co-authored-by: Birk Skyum <birk.skyum@pm.me>
Co-authored-by: Keven Arroyo <kevenarroyo@microsoft.com>
Co-authored-by: Dor Alagem <dor3382@gmail.com>
Co-authored-by: Dor Alagem <doralagem@MacBook-Pro-sl-Dor.local>
Co-authored-by: Manuel Schiller <meisterpink@gmail.com>
Co-authored-by: Franklin Shera <fshera96@gmail.com>
Co-authored-by: Tom Smithhisler <tomsmithhisler@gmail.com>
Co-authored-by: dfedoryshchev <64079946+dfedoryshchev@users.noreply.github.com>
Co-authored-by: Sarah Gerrard <hello@sarahgerrard.me>
Co-authored-by: Zelys <zelys@dfkhelper.com>
Co-authored-by: Shkumbin Hasani <34962865+shkumbinhasani@users.noreply.github.com>
Co-authored-by: Lachlan Collins <1667261+lachlancollins@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Harry Whorlow <79278353+harry-whorlow@users.noreply.github.com>
Co-authored-by: Corbin Crutchley <git@crutchcorn.dev>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@CodingCossack@schiller-manuel