Skip to content

fix(start): emit boot-sibling chunks as scripts for IIFE entries - #7501

Merged
schiller-manuel merged 3 commits into
mainfrom
fix-iife-rsbuild-single-runtime
May 28, 2026
Merged

fix(start): emit boot-sibling chunks as scripts for IIFE entries#7501
schiller-manuel merged 3 commits into
mainfrom
fix-iife-rsbuild-single-runtime

Conversation

@schiller-manuel

@schiller-manuelschiller-manuel commented May 28, 2026

Copy link
Copy Markdown
Collaborator

Summary by CodeRabbit

  • Bug Fixes

    • Ensure client entry scripts are emitted for IIFE bundles with static-import siblings so hydration works correctly.
  • Chores

    • Update build/test fixture for more extensive development stress-testing.
    • Manifest/public API changes: manifests and TypeScript types no longer expose a top-level clientEntry; manifest shape/asset handling standardized and simplified.

Review Change Stack

@coderabbitai

coderabbitaiBot commented May 28, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: a54baa35-59f4-46f4-be77-54242cbdbd5b

📥 Commits

Reviewing files that changed from the base of the PR and between e2ab690 and 72af98d.

📒 Files selected for processing (1)
  • packages/start-plugin-core/src/vite/start-manifest-plugin/plugin.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/start-plugin-core/src/vite/start-manifest-plugin/plugin.ts

📝 Walkthrough

Walkthrough

This PR removes the top-level clientEntry from start manifests, emits client entry scripts via routes.__root__ (respecting scriptFormat for module vs iife), and simplifies server-side APIs to use ServerManifest directly; tests and dev/E2E fixtures were updated accordingly.

Changes

Manifest contract and entry script emission

Layer / File(s)Summary
StartManifest contract removal
packages/start-plugin-core/src/start-manifest-plugin/manifestBuilder.ts
Remove clientEntry: string from the public StartManifest interface and from buildStartManifest's return.
Entry script generation and route append helpers
packages/start-plugin-core/src/start-manifest-plugin/manifestBuilder.ts
Add buildScript, appendRouteScripts, and appendEntryChunkScripts to construct and merge manifest scripts (module vs iife attributes) onto routes.
Wire entry scripts into buildStartManifest
packages/start-plugin-core/src/start-manifest-plugin/manifestBuilder.ts
Attach entry-chunk scripts to routes.__root__ during manifest build; default scriptFormat to 'module'; use shallow copies for missing chunk data.
Update dev virtual modules and fallback manifest
packages/start-plugin-core/src/rsbuild/virtual-modules.ts, packages/start-plugin-core/src/vite/start-manifest-plugin/plugin.ts
Replace dev fallback { routes: {}, clientEntry } with routes.__root__ containing preloads and scripts whose attrs are generated from scriptFormat; move normalize import to normalized-client-build.
Reorganize Vite manifest helper imports
packages/start-plugin-core/src/start-manifest-plugin/manifestBuilder.ts, packages/start-plugin-core/src/vite/start-manifest-plugin/plugin.ts
Import normalizeViteClientBuild from normalized-client-build and remove re-exports from manifestBuilder.
Simplify server-core manifest types to ServerManifest
packages/start-server-core/src/finalManifest.ts, packages/start-server-core/src/router-manifest.ts, packages/start-server-core/src/tanstack-start.d.ts
Change GetBaseManifest and related functions to return Promise<ServerManifest>; remove StartManifestWithClientEntry re-exports; add internal buildFinalManifest to choose transforms.
Remove ClientEntry helpers from asset transformation
packages/start-server-core/src/transformAssetUrls.ts
Remove StartManifestWithClientEntry and buildClientEntryScriptTag; make transformManifestAssets accept ServerManifest and stop injecting client entry; add buildManifest that deep-clones inlineCss without adding client entry.

Test updates for manifest refactors

Layer / File(s)Summary
Update start-manifest-plugin tests
packages/start-plugin-core/tests/start-manifest-plugin.test.ts, packages/start-plugin-core/tests/start-manifest-plugin/manifestBuilder.test.ts
Adjust tests to expect src/attrs on root-route script entries; update imports to normalized-client-build; add tests asserting module vs iife root emission and auto-injected client entry scripts.
Update server-core manifest tests
packages/start-server-core/tests/finalManifest.test.ts, packages/start-server-core/tests/transformAssets.test.ts
Use ServerManifest fixtures (top-level inlineCss/routes); update to buildManifest; add immutability and deep-clone assertions; validate preload/script ordering for iife and crossOrigin handling.

E2E test fixture and release notes

Layer / File(s)Summary
E2E test rsbuild config for iife output
e2e/react-start/custom-server-rsbuild/rsbuild.config.ts
Expand the e2e rsbuild fixture to produce IIFE client output, enable rspack build cache, set output.assetPrefix to /static/, and force single runtime chunk.
Release notes
.changeset/seven-times-pump.md
Add a changelog entry describing the fix to ensure client entry scripts are emitted from the root route manifest to correct IIFE hydration when entry chunks have static-import siblings.

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

Possibly related PRs

  • TanStack/router#6606: Refactors the transform/manifest pipeline that introduced client-entry–centric APIs this PR removes.
  • TanStack/router#7482: Changes Vite/start-manifest client-entry wiring for bundled-dev; overlaps with manifest emission behavior here.
  • TanStack/router#7477: Introduces rsbuild iife output-work that this PR's scriptFormat handling builds upon.

Suggested reviewers

  • beaussan
  • SeanCassiere

Poem

🐰 I hopped through manifests, scripts in tow,
Rooted the entry where preloads grow,
Module or IIFE, they find their part —
No top-level clutter, a cleaner start!

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 12.50% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main fix: addressing IIFE entry handling with boot-sibling chunks being emitted as scripts, which is the core change across the manifest and asset transformation refactoring.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix-iife-rsbuild-single-runtime

Comment @coderabbitai help to get the list of available commands and usage tips.

@nx-cloud

nx-cloudBot commented May 28, 2026

Copy link
Copy Markdown
Contributor

View your CI Pipeline Execution ↗ for commit e2ab690

CommandStatusDurationResult
nx affected --targets=test:eslint,test:unit,tes...✅ Succeeded9m 16sView ↗
nx run-many --target=build --exclude=examples/*...✅ Succeeded43sView ↗

☁️ Nx Cloud last updated this comment at 2026-05-28 23:38:42 UTC

@github-actions

github-actionsBot commented May 28, 2026

Copy link
Copy Markdown
Contributor

🚀 Changeset Version Preview

2 package(s) bumped directly, 7 bumped as dependents.

🟩 Patch bumps

PackageVersionReason
@tanstack/start-plugin-core1.171.6 → 1.171.7Changeset
@tanstack/start-server-core1.169.4 → 1.169.5Changeset
@tanstack/react-start1.168.14 → 1.168.15Dependent
@tanstack/react-start-rsc0.1.13 → 0.1.14Dependent
@tanstack/react-start-server1.167.9 → 1.167.10Dependent
@tanstack/solid-start1.168.14 → 1.168.15Dependent
@tanstack/solid-start-server1.167.9 → 1.167.10Dependent
@tanstack/vue-start1.168.13 → 1.168.14Dependent
@tanstack/vue-start-server1.167.9 → 1.167.10Dependent

@github-actions

github-actionsBot commented May 28, 2026

Copy link
Copy Markdown
Contributor

Bundle Size Benchmarks

  • Commit: 9e152f8b1150
  • Measured at: 2026-05-28T23:30:23.383Z
  • Baseline source: history:bae50be10aed
  • Dashboard: bundle-size history
ScenarioCurrent (gzip)Delta vs baselineInitial gzipRawBrotliTrend
react-router.minimal87.30 KiB0 B (0.00%)87.16 KiB274.03 KiB75.92 KiB▃▁▁▁▁██████
react-router.full90.75 KiB0 B (0.00%)90.61 KiB285.39 KiB78.80 KiB███▁▁▂▂▂▂▂▂
solid-router.minimal35.53 KiB0 B (0.00%)35.41 KiB106.33 KiB32.01 KiB▁▆▆▆▆██████
solid-router.full40.23 KiB0 B (0.00%)40.11 KiB120.52 KiB36.19 KiB▇██▂▂▁▁▁▁▁▁
vue-router.minimal53.02 KiB0 B (0.00%)52.89 KiB150.35 KiB47.56 KiB█████▁▁▁▁▁▁
vue-router.full58.65 KiB0 B (0.00%)58.52 KiB168.08 KiB52.55 KiB▁▁▁██▅▅▅▅▅▅
react-start.minimal101.93 KiB0 B (0.00%)101.79 KiB322.35 KiB88.25 KiB███▁▁▁▁▁▁▁▁
react-start.deferred-hydration102.66 KiB0 B (0.00%)101.81 KiB323.72 KiB88.82 KiB███▆▆▁▁▁▁▁▁
react-start.full105.31 KiB0 B (0.00%)105.17 KiB332.66 KiB91.06 KiB███▁▁▁▁▁▁▁▁
react-start.rsbuild.minimal99.61 KiB0 B (0.00%)99.44 KiB316.79 KiB85.73 KiB███▁▁▁▁▂▂▂▂
react-start.rsbuild.full102.88 KiB0 B (0.00%)102.71 KiB327.18 KiB88.52 KiB███▁▁▁▁▁▁▁▁
solid-start.minimal49.63 KiB0 B (0.00%)49.50 KiB152.40 KiB43.84 KiB███▁▁▁▁▁▁▁▁
solid-start.deferred-hydration52.89 KiB0 B (0.00%)49.55 KiB160.44 KiB46.71 KiB█████▁▁▁▁▁▁
solid-start.full55.41 KiB0 B (0.00%)55.29 KiB169.33 KiB48.81 KiB███▁▁▁▁▁▁▁▁

Current gzip tracks all emitted client JS chunks. Initial gzip tracks only the entry/import graph. Trend sparkline is historical current gzip ending with this PR measurement; lower is better.

@pkg-pr-new

pkg-pr-newBot commented May 28, 2026

Copy link
Copy Markdown
More templates

@tanstack/arktype-adapter

npm i https://pkg.pr.new/@tanstack/arktype-adapter@7501

@tanstack/eslint-plugin-router

npm i https://pkg.pr.new/@tanstack/eslint-plugin-router@7501

@tanstack/eslint-plugin-start

npm i https://pkg.pr.new/@tanstack/eslint-plugin-start@7501

@tanstack/history

npm i https://pkg.pr.new/@tanstack/history@7501

@tanstack/nitro-v2-vite-plugin

npm i https://pkg.pr.new/@tanstack/nitro-v2-vite-plugin@7501

@tanstack/react-router

npm i https://pkg.pr.new/@tanstack/react-router@7501

@tanstack/react-router-devtools

npm i https://pkg.pr.new/@tanstack/react-router-devtools@7501

@tanstack/react-router-ssr-query

npm i https://pkg.pr.new/@tanstack/react-router-ssr-query@7501

@tanstack/react-start

npm i https://pkg.pr.new/@tanstack/react-start@7501

@tanstack/react-start-client

npm i https://pkg.pr.new/@tanstack/react-start-client@7501

@tanstack/react-start-rsc

npm i https://pkg.pr.new/@tanstack/react-start-rsc@7501

@tanstack/react-start-server

npm i https://pkg.pr.new/@tanstack/react-start-server@7501

@tanstack/router-cli

npm i https://pkg.pr.new/@tanstack/router-cli@7501

@tanstack/router-core

npm i https://pkg.pr.new/@tanstack/router-core@7501

@tanstack/router-devtools

npm i https://pkg.pr.new/@tanstack/router-devtools@7501

@tanstack/router-devtools-core

npm i https://pkg.pr.new/@tanstack/router-devtools-core@7501

@tanstack/router-generator

npm i https://pkg.pr.new/@tanstack/router-generator@7501

@tanstack/router-plugin

npm i https://pkg.pr.new/@tanstack/router-plugin@7501

@tanstack/router-ssr-query-core

npm i https://pkg.pr.new/@tanstack/router-ssr-query-core@7501

@tanstack/router-utils

npm i https://pkg.pr.new/@tanstack/router-utils@7501

@tanstack/router-vite-plugin

npm i https://pkg.pr.new/@tanstack/router-vite-plugin@7501

@tanstack/solid-router

npm i https://pkg.pr.new/@tanstack/solid-router@7501

@tanstack/solid-router-devtools

npm i https://pkg.pr.new/@tanstack/solid-router-devtools@7501

@tanstack/solid-router-ssr-query

npm i https://pkg.pr.new/@tanstack/solid-router-ssr-query@7501

@tanstack/solid-start

npm i https://pkg.pr.new/@tanstack/solid-start@7501

@tanstack/solid-start-client

npm i https://pkg.pr.new/@tanstack/solid-start-client@7501

@tanstack/solid-start-server

npm i https://pkg.pr.new/@tanstack/solid-start-server@7501

@tanstack/start-client-core

npm i https://pkg.pr.new/@tanstack/start-client-core@7501

@tanstack/start-fn-stubs

npm i https://pkg.pr.new/@tanstack/start-fn-stubs@7501

@tanstack/start-plugin-core

npm i https://pkg.pr.new/@tanstack/start-plugin-core@7501

@tanstack/start-server-core

npm i https://pkg.pr.new/@tanstack/start-server-core@7501

@tanstack/start-static-server-functions

npm i https://pkg.pr.new/@tanstack/start-static-server-functions@7501

@tanstack/start-storage-context

npm i https://pkg.pr.new/@tanstack/start-storage-context@7501

@tanstack/valibot-adapter

npm i https://pkg.pr.new/@tanstack/valibot-adapter@7501

@tanstack/virtual-file-routes

npm i https://pkg.pr.new/@tanstack/virtual-file-routes@7501

@tanstack/vue-router

npm i https://pkg.pr.new/@tanstack/vue-router@7501

@tanstack/vue-router-devtools

npm i https://pkg.pr.new/@tanstack/vue-router-devtools@7501

@tanstack/vue-router-ssr-query

npm i https://pkg.pr.new/@tanstack/vue-router-ssr-query@7501

@tanstack/vue-start

npm i https://pkg.pr.new/@tanstack/vue-start@7501

@tanstack/vue-start-client

npm i https://pkg.pr.new/@tanstack/vue-start-client@7501

@tanstack/vue-start-server

npm i https://pkg.pr.new/@tanstack/vue-start-server@7501

@tanstack/zod-adapter

npm i https://pkg.pr.new/@tanstack/zod-adapter@7501

commit: 72af98d

@coderabbitai

Copy link
Copy Markdown
Contributor

Actionable comments posted: 0

@nx-cloudnx-cloudBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nx Cloud is proposing a fix for your failed CI:

We moved the normalizeViteClientBuild value import above the import type statements in plugin.ts to fix the import/order ESLint violation introduced by the PR. The rule requires all value imports to precede type-only imports, and the new import was accidentally placed after them. This change restores lint compliance without altering any runtime behaviour.

Tip

We verified this fix by re-running @tanstack/start-plugin-core:test:eslint.

diff --git a/packages/start-plugin-core/src/vite/start-manifest-plugin/plugin.ts b/packages/start-plugin-core/src/vite/start-manifest-plugin/plugin.ts
index 5701ab1e..9b9c2745 100644
--- a/packages/start-plugin-core/src/vite/start-manifest-plugin/plugin.ts+++ b/packages/start-plugin-core/src/vite/start-manifest-plugin/plugin.ts@@ -8,9 +8,9 @@ import {
serializeStartManifest,
} from '../../start-manifest-plugin/manifestBuilder'
import { createVirtualModule } from '../createVirtualModule'
+import { normalizeViteClientBuild } from './normalized-client-build'
import type { GetConfigFn, NormalizedClientBuild } from '../../types'
import type { PluginOption, Rollup } from 'vite'
-import { normalizeViteClientBuild } from './normalized-client-build'
type StartManifestEnvironment = {
config: {

Apply fix via Nx CloudReject fix via Nx Cloud


Or Apply changes locally with:

npx nx-cloud apply-locally KJTU-Ey4N

Apply fix locally with your editor ↗View interactive diff ↗



🎓 Learn more about Self-Healing CI on nx.dev

@codspeed-hq

codspeed-hqBot commented May 28, 2026

Copy link
Copy Markdown

Merging this PR will not alter performance

✅ 4 untouched benchmarks
⏩ 2 skipped benchmarks1


Comparing fix-iife-rsbuild-single-runtime (72af98d) with main (bae50be)

Open in CodSpeed

Footnotes

  1. 2 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports.

@schiller-manuel
schiller-manuel merged commit 9c09bca into mainMay 28, 2026
19 checks passed
@schiller-manuel
schiller-manuel deleted the fix-iife-rsbuild-single-runtime branch May 28, 2026 23:42
@github-actionsgithub-actionsBot mentioned this pull request May 28, 2026
birkskyum added a commit that referenced this pull request Jun 1, 2026
* fix: republish react-start-rsc dependency chain
* ci: changeset release
* chore: sync published start package versions
* ci: changeset release
* fix publishing
* ci: changeset release
* fix
* ci: apply automated fixes
* ci: changeset release
* refactor: switch router stores to atom get/set API (#7150)
* ci: changeset release
* refactor: shorten internal router store names (#7152)
* ci: changeset release
* chore(types): re-export SearchMiddleware type from react-router (#7087)
* fix(start-plugin-core): reuse deduped server function ids across compilers (#7153)
* ci: changeset release
* fix(router-core): avoid false notFound matches for proxied loader data (#7156)
* fix(router-core): avoid false notFound matches for proxied loader data
* test(react-start): cover proxied loader data notFound regression
* test(react-start): move notFound regression to rsc direct loader
* chore: add changeset
* ci: changeset release
* fix: reduce start SSR manifest asset duplication (#7157)
Co-authored-by: schiller-manuel <schiller-manuel@users.noreply.github.com>
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
* ci: changeset release
* docs: fix file extension syntax for prefix/suffix routing examples (#7149)
docs: fix file-based routing examples with literal dots
* chore: bump to h3 v2 rc.20 (#7140)
* ci: changeset release
* chore: stabilize tests (#7159)
* chore: add vite 8 to peer deps (#7160)
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* ci: changeset release
* chore(start-server-core): remove unnecessary `any` in `getRequestHeaders` (#7164)
* fix(router-generator): harden route file transform rewrites (#7167)
* fix docs (#7168)
* ci: changeset release
* fix(router-plugin): update vite-plugin-solid peer dependency to support version 3.0.0-0 (#7170)
* ci: changeset release
* fix(router-generator): normalize virtual physical subtree paths (#7169)
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* ci: changeset release
* fix: unify virtual module handling for Start Vite plugins (#7178)
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Co-authored-by: CodeRabbit <noreply@coderabbit.ai>
Co-authored-by: schiller-manuel <schiller-manuel@users.noreply.github.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
* ci: changeset release
* fix: add react-server server export for react-start (#7180)
* ci: changeset release
* fix(docs): correct server function name in example (#7173)
* fix react server exports for start and react-router (#7183)
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
* chore: stabilize tests (#7185)
* ci: changeset release
* fix(router-core): avoid intermediate success state for async notFound (#7184)
* ci: changeset release
* Add a React Start server-components skill (#7181)
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* chore: add sharding for playwright tests (#7187)
* add sharding
* fix dependnancy
* fix playwright shard port reuse
* full bust
* throw more runners into this run
* try to throw money at it and see the effect
* tune
* fix react-router shared route css persistence on nav (#7186)
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
* ci: changeset release
* chore: stabilize test (#7192)
* fix(start): include Vite style.css when cssCodeSplit is disabled (#7191)
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
* ci: changeset release
* chore: bump solid-js override 1.9.12 (#7202)
* chore: bump query override to 5.99.0 (#7203)
* fix(solid-router): use keyed Show in Outlet to fix child route rendering with useQuery (#7204)
* ci: changeset release
* docs(start): fix authenticated routes doc URL (#7214)
* chore(deps): vitest 4.1.4 (#7212)
* stabilize rsc tests (#7217)
* fix(react-router): prevent webpack static analysis of React.use with let binding (#7182)
* ci: changeset release
* stabilize test (#7220)
* chore: unify react-start basic e2e mode projects (#7206)
* feat(nx): support rsbuild in Playwright inference (#7221)
* test(e2e-rsc): migrate to playwrightModes and dynamic inferred dist (#7222)
* fix(nx): align playwright mode build target naming (#7223)
* docs(start): add missing space after comma in 'Handling requests with a body' (#7234)
* update intent workflow (#7243)
* rsbuild plugin (#7228)
Co-authored-by: neverland <chenjiahan.jait@bytedance.com>
Co-authored-by: Keven Arroyo <dake.3601@gmail.com>
* ci: changeset release
* fix: Split Start plugin core (#7249)
* ci: changeset release
* update intent workflow (#7244)
* fix: asset sorting (#7251)
* ci: changeset release
* chore(deps): update Rsbuild related deps to v2.0.1 (#7245)
* fix actions again? (#7252)
* inline css (#7253)
* ci: changeset release
* fix: do not import 'react-refresh/runtime' (#7255)
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
* ci: changeset release
* chore(examples): checkin git outdated route-tree files for react and solid examples (#7257)
* add new bundlesize measurements for rsbuild (#7256)
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
* refactor(router-plugin): upgrade unplugin to `v3` (#7258)
* refactor(router-plugin): upgrade unplugin to `v3`
* refactor(start-client-core): use a more explicit typing to `CustomFetch` type
* chore(examples): runtime enforce for needing the `VITE_CONVEX_URL`
* ci: changeset release
* fix: issue 7240 causing fouc (#7250)
* fix: server middleware type in solid-router (#7260)
* replace tsx by jiti (#7261)
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
* ci: changeset release
* docs: Fix server function middleware prop (#7262)
* feat(query): add support for custom dehydrate and hydrate options in SSR integration (#7246)
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* ci: changeset release
* fix: use loader data goes undefined (#7265)
* fix: streaming when using Await component (#7264)
* ci: changeset release
* fix(solid-start): bundle solid-query packages during SSR to fix duplicate QueryClientContext (#6151) (#7267)
* ci: changeset release
* fix(solid-router): hydration mismatch for ssr='data-only' with pendingComponent (#7266)
* docs(router): fix typo in doc (#7268)
* ci: changeset release
* fix(router-core): wildcard nodes respect DFS priority like other nodes in route matching (#7273)
* ci: changeset release
* fix(solid-router): enable route component HMR for Solid
* ci: apply automated fixes
* Revert "ci: apply automated fixes"
This reverts commit 7122f28.
* Revert "fix(solid-router): enable route component HMR for Solid"
This reverts commit b86b061.
* fix(react-start-rsc): re-export renderable types from public entries (#7278)
* fix(react-start-rsc): re-export renderable types from public entries
* changeset - patch
* ci: changeset release
* fix: disabled topLevelVar (#7293)
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* ci: changeset release
* fix: fix exports for react-start so useServerFn is available with RSC (#7292)
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
* feat: match params (#7263)
* ci: changeset release
* fix(start-plugin-core): sort server fn manifest entries for deterministic build output (#7287)
Co-authored-by: Dor Alagem <doralagem@MacBook-Pro-sl-Dor.local>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Manuel Schiller <meisterpink@gmail.com>
* docs: remove redundant code example from query integration doc (#7298)
* ci: changeset release
* fix: Ignore fully type-only imports and re-exports when collecting im… (#7305)
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* ci: changeset release
* feat: `strict: false` for server functions (#7277)
* feat: `strict: false` for server functions
Add a `strict` option to `createServerFn` for type-level server function serialization checks
* feat: `strict: false` for server functions [Self-Healing CI Rerun]
---------
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
* ci: changeset release
* fix: parse params union inference (#7306)
* ci: changeset release
* feat: rsc css (#7310)
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* ci: changeset release
* fix(router-plugin): isolate route metadata per plugin instance (#7313)
* ci: changeset release
* docs: Improve key differences b/w Start Server Functions and Next.js Server Actions (#7312)
* fix(deps): move fetchdts from devDependencies to dependencies (#7317)
* Revise bug report template for clarity and requirements
Updated the bug report template to clarify the requirements for a reproducer project and modified some labels and descriptions for better clarity.
* ci: changeset release
* chore: fix duplicate "the" typo across router packages (#7323)
* feat: early hints (#7324)
* ci: changeset release
* feat: Link header (#7327)
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
* ci: changeset release
* docs(skills): address 8 agent failure modes from user feedback (#7314)
* docs(skills): address 8 agent failure modes from external feedback
Adds new start-core/auth-server-primitives skill (sessions, cookies,
OAuth+PKCE, password-reset enumeration defense, CSRF, rate limiting,
session rotation) and updates 8 existing skills + matching docs to fix
patterns where agents produce insecure or wrong-framework output.
Skill changes:
- new: start-core/auth-server-primitives (server half of auth)
- router-core/auth-and-guards: route guard != RPC guard
- start-core/server-functions: wrong import path, RPC auth required,
Cache-Control public is a cross-tenant leak, wrong-framework patterns
- start-core/middleware: wrong import path, sendContext shape vs access
(3-layer wrong/still-wrong/correct), authMiddleware framing
- start-core/execution-model: file markers (server-only/client-only),
module-level process.env is undefined under Worker SSR
- start-core/deployment: cloudflare env-at-request-time
- router-core/ssr: wrong file structures (next.js, react-router-dom)
- router-core/type-safety: wrong-framework imports + structures
Docs updated to mirror each skill change so source-of-truth and the
intent-indexed skill stay in sync. New authentication-server-primitives
guide is the long-form companion to the new skill.
intent validate: 30 skill files pass (was 29).
* ci: apply automated fixes
* docs(skills): address coderabbit review feedback
- Fix internal docs links to use correct relative paths instead of an
absolute /start/latest/... URL and missing one ../ segment
- Remove blank line inside auth-and-guards blockquote (markdownlint MD028)
- Restore overload pattern in type-safety ValidateNavigateOptions and
ValidateRedirectOptions examples; the casts I had introduced stripped
generic context and contradicted the skill's own no-cast rule
- Add db.sessions.revokeAllForUser before create in login rotation
snippets so the example matches the prose
- Soften useServerFn guidance: it's required only when the server
function throws redirect/notFound; plain-data calls work directly and
via useMutation/useQuery
* ci: apply automated fixes
* docs(skills): compress type-safety to stay under 500-line cap
Prettier's autofix expanded my single-line overload signatures across
multiple lines, pushing the file over the 500-line limit. Drop the
redundant fetchOrRedirect example (same pattern as useDelayedNavigate)
and describe ValidateRedirectOptions usage in prose instead.
* docs(skills): CSRF origin check should compare full origin, not host alone
Comparing only new URL(origin).host against APP_HOST silently accepts a
mismatched scheme — http://example.com would pass a check meant for
https://example.com. Compare the full origin (scheme + host + port)
against APP_ORIGIN instead. Same fix in skill and docs.
* docs(skills): make useDelayedNavigate callback truly return void
The callback returned the result of setTimeout (a timer handle), not
void as the public overload's return type implied. Wrap in a block so
the example matches the declared return type.
Skipped the related nitpick to add a separate redirect example — the
existing prose already describes the same overload pattern, and a
duplicate example would push the file close to the 500-line cap that
prettier autofix has been bumping us against.
* docs(skills): fix two real bugs in auth-server-primitives examples
1. Cookie parser truncated values containing '='. Signed cookies, JWTs,
and base64-padded values all use '='. Use indexOf to split on the
FIRST '=' only.
2. Login example short-circuited verifyPasswordHash on user-not-found,
contradicting the prose's "same time, same error" claim — the
no-user branch returned instantly while wrong-password spent ~100ms
hashing, leaking account existence over the wire. Always verify
against a hash; use a precomputed DUMMY_PASSWORD_HASH when the user
is missing, then combine with the user-exists bit for the final ok.
Same fixes in the SKILL.md and the docs companion.
* docs(skills): address manuel's review on react-specific guides
- middleware.md, server-functions.md: drop cross-framework <framework>
placeholders; this is the React-specific guide, just say
@tanstack/react-start
- execution-model.md: drop the same trailing line about solid-start /
vue-start paths
- hosting.md: remove the Cloudflare env-handling subsection — the
general per-request rule lives in environment-variables.md and
doesn't need to be repeated under a specific host
- environment-variables.md: mention the cloudflare:workers env binding
as the canonical Cloudflare way to read env (including module scope),
per Manuel's link to the Cloudflare docs
- deployment skill: same upgrade — show the cloudflare:workers env
pattern alongside the per-request handler approach
* docs(skills): drop redundant server-only marker in session example
The file already imports from @tanstack/react-start/server, which is
on import protection's default client-deny specifier list. The
side-effect marker is redundant — drop it. Same fix in skill and docs.
* docs(skills): drop wrong-import-path mistakes — TS already catches them
Manuel pointed out that TypeScript catches both common wrong paths:
'@tanstack/react-router' has no exported member createServerFn /
createMiddleware, and '@tanstack/start' is "Cannot find module". Skill
space is precious; the items don't earn their slot if tsc handles them.
Removed:
- Common Mistake "Wrong import path" from server-functions and
middleware skills (renumbered the remaining mistakes)
- The matching top-of-file CRITICAL line in both skills
- The "Import path" callouts in the middleware and server-functions
docs
---------
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* remove old intent artifacts (#7333)
* fix(start-server-core): fall back to GET handler for HEAD requests (RFC 9110 §9.3.2) (#7325)
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* ci: changeset release
* test: add reproducer for #2514 (#7336)
* test: reproducer for #2547 (#7337)
* fix: fix plain TypeScript parser handling (#7342)
* ci: changeset release
* fix: disable rsbuild server compression (#7348)
* fix: update deps (#7340)
* ci: changeset release
* update bundlesize benchmark (#7356)
* fix: Bump jiti to 2.7.0 (#7355)
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
* ci: apply automated fixes
* ci: changeset release
* Document server function strict serialization options (#7358)
* Document server function strict option
Agent-Logs-Url: https://github.com/TanStack/router/sessions/8deabe7a-7412-455e-9111-97a13cb4582e
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
* Refine strict docs wording
Agent-Logs-Url: https://github.com/TanStack/router/sessions/e2857d6e-314e-496c-b99b-78c207c28c77
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
* feat(start): CSRF middleware (#7373)
* fix(router-core): fix missing closing paren in CSS.supports check for view transition types (#7369)
* fix: fix jiti usage for tsconfig paths (#7382)
* Enable jiti tsconfig path aliases
Agent-Logs-Url: https://github.com/TanStack/router/sessions/0a481c9b-eb97-4543-acc5-71d43b97d386
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
* Use fixture for jiti tsconfig aliases
Agent-Logs-Url: https://github.com/TanStack/router/sessions/182b9baa-9e54-4813-a322-c33a1da5417d
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
* Track fixture path alias helper
Agent-Logs-Url: https://github.com/TanStack/router/sessions/182b9baa-9e54-4813-a322-c33a1da5417d
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
* Add router-generator changeset
Agent-Logs-Url: https://github.com/TanStack/router/sessions/ab1a42cc-7326-4e36-a656-f01179221cee
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
* Format virtual config fixture
Agent-Logs-Url: https://github.com/TanStack/router/sessions/22194166-b3a7-431e-b723-ad594d4b0405
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
* Update bundle-size.yml
* Update labeler.yml
* Update bundle-size.yml
* ci: add pinGitHubActionDigests (#7387)
* chore(deps): pin dependencies (#7388)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* minor semver bump to all packages (#7395)
* ci: zizmor (#7389)
* chore(pnpm): update pnpm to v11 (#7392)
* chore: add CODEOWNERS file (#7394)
* chore: add CODEOWNERS file
* chore: add Nx and NPMRC
* Update .github/CODEOWNERS
---------
Co-authored-by: Nicolas Beaussart <nic.beaussart@gmail.com>
* fix: revert plugin changes, createCsrfMiddleware compilation, fix HMR tests (#7400)
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Manuel Schiller <manuel.schiller@caligano.de>
* ci: align release workflow to query (#7404)
* ci: Version Packages (#7405)
ci: changeset release
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* feat(start): add inline CSS runtime controls and asset URL templates (#7380)
* ci: Version Packages (#7407)
* fix: Fix literal underscore paths under pathless layouts (#7408)
* ci: Version Packages (#7409)
ci: changeset release
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* feat(router-core): params.priority route option as tie breaker in matching algorithm (#7411)
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* ci: Version Packages (#7413)
* fix(router-core): hydrate before initial client route match (#7416)
* ci: Version Packages (#7417)
* fix(router-plugin): detect typed root route context for HMR (#7420)
* ci: Version Packages (#7421)
* fix: fix route mismatch warnings and HMR route indexes (#7422)
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* ci: Version Packages (#7423)
* security: stricter pnpm config blockExoticSubdeps & trustPolicy (#7425)
* docs(start): use router package for module declaration to type the request context (#7427)
* feat: deferred hydration (#7362)
* feat: deferred hydration
* fix
* tests
* solid tests
* Changes before error encountered
Agent-Logs-Url: https://github.com/TanStack/router/sessions/5263c469-75c2-4470-bd4c-86f9b43964f4
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
* chore: address hydration review follow-ups
Agent-Logs-Url: https://github.com/TanStack/router/sessions/16e27113-ff01-4de8-aded-b9be9f6dd4ff
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
* fix(start-client-core): correct import order in hydrateStart.ts
Co-authored-by: schiller-manuel <schiller-manuel@users.noreply.github.com>
* chore: remove tracked nx self-healing artifacts
Agent-Logs-Url: https://github.com/TanStack/router/sessions/95750760-1348-437c-8f73-cc45e899003a
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
Co-authored-by: schiller-manuel <schiller-manuel@users.noreply.github.com>
* chore: update @swc/core in example/react/quickstart-webpack-file-based (#7434)
* chore: update @swc/core in example/react/quickstart-webpack-file-based
* chore: update @swc/core in example/react/quickstart-webpack-file-based [Self-Healing CI Rerun]
---------
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
* docs(start): compare deferred hydration to Astro islands (#7438)
Adds a short mental-model section answering the common question
about how TanStack Start's deferred hydration relates to Astro
islands.
* docs(start): compare deferred hydration to React selective hydration (#7442)
Adds a short comparison section answering the common question about how
TanStack Start's deferred hydration relates to React 18's selective
hydration. The framing: selective hydration controls the order of
inevitable hydration work; deferred hydration controls whether and when
that work happens at all.
* chore: update chokidar to v5 (#7439)
* chore: update @rolldown/pluginutils to 1.0.1 (#7440)
* chore: update zod to v4.4.3 (#7441)
* chore: update zod to v4.4.3
* fix(start): preserve route path defaults
* fix(examples): resolve zod 4 build failures
* chore: update express and webpack-dev-server (#7443)
* chore: update express to v5.2.1
* chore: update webpack-dev-server to v5.2.4
* ci: Version Packages (#7435)
ci: changeset release
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* chore: ignore nx generated folders (#7451)
* perf: optimize and test rewrite (#7448)
optimize and test rewrite
* fix: fix scroll restoration issues (#7447)
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* ci: Version Packages (#7452)
* fix: Fix escaped underscore index route generation (#7453)
* ci: Version Packages (#7454)
* ci: fix release notes diff range after Release PR flow (#7456)
* fix(start): explicitly re-export public API to survive SSR cold-start cycle (#7466)
* fix: Fix hash scrolling with `resetScroll={false}` (#7464)
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
* chore: enforce pnpm 11 (#7465)
* ci: Version Packages (#7467)
* chore: only run autofix on PRs (#7469)
* feat(start): support rsbuild iife client output (#7477)
* ci: Version Packages (#7478)
* fix: bundled dev support for vite (#7482)
* ci: Version Packages (#7483)
* fix(start): avoid encoded virtual adapter ids in vite dev (#7484)
* fix release (#7487)
* ci: Version Packages (#7485)
* chore: migrate changesets changelog generator (#7490)
* fix: Fix Hydrate re-exports to avoid circular HMR updates (#7492)
* ci: Version Packages (#7493)
* fix(start): emit boot-sibling chunks as scripts for IIFE entries (#7501)
Co-authored-by: Keven Arroyo <kevenarroyo@microsoft.com>
* ci: Version Packages (#7502)
* chore: stabilize tests (#7503)
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* fix: fix streaming (#7497)
* ci: Version Packages (#7504)
ci: changeset release
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* ci: update all actions (#7506)
* ci: update all actions
* disable package manager cache
* fix: fix primitive beforeLoad errors (#7505)
* fix: fix primitive beforeLoad errors
* ci: apply automated fixes
---------
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* ci: Version Packages (#7508)
* feat(rsbuild): add RSC support (#7509)
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* ci: Version Packages (#7513)
* fix(solid): resolve Solid 2 merge issues
* ci: apply automated fixes
* use v2 query
* fix solid v2 imports
* solid v2 port of new e2e
* solid v2
* nxignore solid v1 peer deps
* use "@rsbuild/plugin-solid": "^2.0.0-beta.0",
* fix hydrationscript
* add nohydration
* remove early return
* fix: solid-start hydration
* fix: update createEffect to return true for hydration signals
* remove nxignore
* add back nxignore for 3rdparty deps
* $_TSR stub to fix serialization tests
* Revert "$_TSR stub to fix serialization tests"
This reverts commit ef802e9.
* fix: update solid selective ssr links
* fix: stream solid Await fallback
* align solid-start basic by removing test:e2e
* remove unusese build:prerender build:spa
* fix: clean up solid hydrate fallback dom
* fix: resolve solid wrapper children
* fix: stabilize serialization stream e2e test
* fix: keep SSR globals through document parse
* html standard mode
* clean
* fix: pass solid ssr manifest
* use await fallback
---------
Co-authored-by: Tanner Linsley <tannerlinsley@gmail.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Manuel Schiller <manuel.schiller@caligano.de>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Flo <fpellet@ensc.fr>
Co-authored-by: James Howard <james@reetgood.co.uk>
Co-authored-by: schiller-manuel <schiller-manuel@users.noreply.github.com>
Co-authored-by: nx-cloud[bot] <71083854+nx-cloud[bot]@users.noreply.github.com>
Co-authored-by: Mohamed Khaled <mohamedkhaled012@yahoo.com>
Co-authored-by: Birk Skyum <74932975+birkskyum@users.noreply.github.com>
Co-authored-by: schiller-manuel <6340397+schiller-manuel@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Ulrich Stark <github@ustark.de>
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Co-authored-by: CodeRabbit <noreply@coderabbit.ai>
Co-authored-by: MoonBrillante <32852571+MoonBrillante@users.noreply.github.com>
Co-authored-by: Coding Cossack <108333654+CodingCossack@users.noreply.github.com>
Co-authored-by: Nicolas Beaussart <nic.beaussart@gmail.com>
Co-authored-by: Pavan Shinde <pavann97@gmail.com>
Co-authored-by: mixelburg <52622705+mixelburg@users.noreply.github.com>
Co-authored-by: Mukunda Rao Katta <mukunda.vjcs6@gmail.com>
Co-authored-by: Sarah Gerrard <gerrardsarah@gmail.com>
Co-authored-by: neverland <chenjiahan.jait@bytedance.com>
Co-authored-by: Keven Arroyo <dake.3601@gmail.com>
Co-authored-by: Sean Cassiere <33615041+SeanCassiere@users.noreply.github.com>
Co-authored-by: Abhishek Raj <abhi@raj.me>
Co-authored-by: Dominik Dorfmeister 🔮 <office@dorfmeister.cc>
Co-authored-by: Birk Skyum <birk.skyum@pm.me>
Co-authored-by: Keven Arroyo <kevenarroyo@microsoft.com>
Co-authored-by: Dor Alagem <dor3382@gmail.com>
Co-authored-by: Dor Alagem <doralagem@MacBook-Pro-sl-Dor.local>
Co-authored-by: Manuel Schiller <meisterpink@gmail.com>
Co-authored-by: Franklin Shera <fshera96@gmail.com>
Co-authored-by: Tom Smithhisler <tomsmithhisler@gmail.com>
Co-authored-by: dfedoryshchev <64079946+dfedoryshchev@users.noreply.github.com>
Co-authored-by: Sarah Gerrard <hello@sarahgerrard.me>
Co-authored-by: Zelys <zelys@dfkhelper.com>
Co-authored-by: Shkumbin Hasani <34962865+shkumbinhasani@users.noreply.github.com>
Co-authored-by: Lachlan Collins <1667261+lachlancollins@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Harry Whorlow <79278353+harry-whorlow@users.noreply.github.com>
Co-authored-by: Corbin Crutchley <git@crutchcorn.dev>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@schiller-manuel@dake3601