Route path-addressed server function calls - #332

Merged
ryansolid merged 3 commits into
nextfrom
server-function-path-addressing
Aug 28, 2026
Merged

Route path-addressed server function calls#332
ryansolid merged 3 commits into
nextfrom
server-function-path-addressing

Conversation

@ryansolid

@ryansolidryansolid commented Aug 27, 2026

Copy link
Copy Markdown
Member

Summary

Downstream adoption of solidjs/solid#3076: a server function call's address is now <endpoint>/<id> with arguments in the query, and the X-Server-Function-Id header and ?id= fallback left the wire.

  • Dev middleware (server-functions/index.ts): the endpoint gate matched the pathname exactly, so path-addressed calls fell through to SSR. It now matches by mount prefix (exact or endpoint + '/'), for both the base-prefixed and base-stripped forms. The module-preload function id comes from the path segment; the header and ?id= forms stay as fallbacks for a client runtime older than the addressing change.
  • Generated dispatch gate (ssr/index.ts): the emitted dispatchRequest composed server functions only at pathname === endpoint; it now prefix-matches the same way. A bare-mount request still routes to the runtime handler, which answers the 404 — a misaddressed post fails through the endpoint rather than rendering a page at it.

Draft until

@solidjs/web publishes the addressing change (anything newer than 2.0.0-rc.3). The plugin change is backward-compatible on its own — exact-match and the fallback id channels keep an older runtime working.

Test plan

  • Verified end-to-end against the fullstack-tanstack template with the solid next runtime linked in: GET-declared reads over /_server/<id> (GET returns data + default no-store, HEAD returns bodyless 200), undeclared reads gated (403/405), and the unscripted no-JS form POST flow (303 + flash cookie) all dispatch through the dev middleware.
  • Cypress example suite against the published @solidjs/web@2.0.0-rc.4 (dist-tag next), plus the full release gate: ssr 12/12 + boundary 8/8, css-matrix 82/82 + bridge 19/19, start-ssr 366/366 + http-bridge 10/10, start-client 45/45, start-env 47/47, vite-8 vitest 1/1, cypress 1/1. The ride commit moves the workspace catalog to ^2.0.0-rc.4 and switches the start-ssr suite's synthetic dispatches to the path form — rc.4's published handler resolves the id from the path alone, so the legacy ?id= shape it used no longer answers.

Companion PR: solidjs/solid-router#590.

Made with Cursor

solidjs/solid#3076 moved the function id into the path
(`<endpoint>/<id>`), retiring the X-Server-Function-Id header and the
`?id=` query fallback. The dev middleware and the generated
dispatchRequest gate matched the endpoint pathname exactly, so the new
addresses fell through to SSR; both now match by mount prefix (exact or
`endpoint + '/'`). The dev middleware's module-preload id comes from
the path segment, with the header and `?id=` forms kept as fallbacks
for a client runtime older than the addressing change.
Verified end-to-end against the fullstack-tanstack template with the
solid `next` runtime linked in: GET-declared reads (GET and HEAD),
405/403 gating, and the unscripted no-JS form POST flow (303 + flash)
all dispatch through the new addresses in dev.
Co-authored-by: Cursor <cursoragent@cursor.com>
@changeset-bot

changeset-botBot commented Aug 27, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eaea1d4

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@solidjs/vite-pluginMinor

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Aug 27, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@solidjs/vite-plugin@332

commit: eaea1d4

…table
Co-authored-by: Cursor <cursoragent@cursor.com>
@ryansolid

Copy link
Copy Markdown
MemberAuthor

Per review: the header/?id= fallbacks in the dev middleware are marked TRANSITIONAL and scoped to the RC window only — they get dropped before the 3.0 stable release. Path addressing is the only wire format from stable on.

rc.4 publishes the path-addressed server function calls this branch
routes (solidjs/solid#3076): the client computes `<endpoint>/<id>` and
the published server handler resolves the id from the path alone — the
X-Server-Function-Id header and `?id=` forms are gone from the runtime,
not just retired client-side. The workspace catalog moves to
^2.0.0-rc.4 (minimumReleaseAgeExclude extended per the existing
pattern), and the start-ssr suite's synthetic dispatches switch from
`?id=` to the path form, since the published handler no longer answers
the legacy shape. The plugin's own transitional fallbacks stay: they
serve runtimes older than the addressing change, which the peer range
still admits.
Full gate green against published rc.4 (no linking): ssr 12/12 +
boundary 8/8, css-matrix 82/82 + bridge 19/19, start-ssr 366/366 +
http-bridge 10/10, start-client 45/45, start-env 47/47, vite-8 vitest
1/1, cypress e2e 1/1.
Co-authored-by: Cursor <cursoragent@cursor.com>
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Added@​solidjs/​diagnostics@​2.0.0-rc.4761009991100

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnMedium
Low adoption: npm @solidjs/diagnostics

Location:Package overview

From:package.jsonnpm/@solidjs/diagnostics@2.0.0-rc.4

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@solidjs/diagnostics@2.0.0-rc.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@ryansolid
ryansolid marked this pull request as ready for review August 28, 2026 22:00
@ryansolid
ryansolid merged commit 54fcdfb into nextAug 28, 2026
6 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ryansolid
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Route path-addressed server function calls - #332

Merged
ryansolid merged 3 commits into
nextfrom
server-function-path-addressing
Aug 28, 2026
Merged

Route path-addressed server function calls#332
ryansolid merged 3 commits into
nextfrom
server-function-path-addressing

Conversation

@ryansolid

@ryansolidryansolid commented Aug 27, 2026

Copy link
Copy Markdown
Member

Summary

Downstream adoption of solidjs/solid#3076: a server function call's address is now <endpoint>/<id> with arguments in the query, and the X-Server-Function-Id header and ?id= fallback left the wire.

  • Dev middleware (server-functions/index.ts): the endpoint gate matched the pathname exactly, so path-addressed calls fell through to SSR. It now matches by mount prefix (exact or endpoint + '/'), for both the base-prefixed and base-stripped forms. The module-preload function id comes from the path segment; the header and ?id= forms stay as fallbacks for a client runtime older than the addressing change.
  • Generated dispatch gate (ssr/index.ts): the emitted dispatchRequest composed server functions only at pathname === endpoint; it now prefix-matches the same way. A bare-mount request still routes to the runtime handler, which answers the 404 — a misaddressed post fails through the endpoint rather than rendering a page at it.

Draft until

@solidjs/web publishes the addressing change (anything newer than 2.0.0-rc.3). The plugin change is backward-compatible on its own — exact-match and the fallback id channels keep an older runtime working.

Test plan

  • Verified end-to-end against the fullstack-tanstack template with the solid next runtime linked in: GET-declared reads over /_server/<id> (GET returns data + default no-store, HEAD returns bodyless 200), undeclared reads gated (403/405), and the unscripted no-JS form POST flow (303 + flash cookie) all dispatch through the dev middleware.
  • Cypress example suite against the published @solidjs/web@2.0.0-rc.4 (dist-tag next), plus the full release gate: ssr 12/12 + boundary 8/8, css-matrix 82/82 + bridge 19/19, start-ssr 366/366 + http-bridge 10/10, start-client 45/45, start-env 47/47, vite-8 vitest 1/1, cypress 1/1. The ride commit moves the workspace catalog to ^2.0.0-rc.4 and switches the start-ssr suite's synthetic dispatches to the path form — rc.4's published handler resolves the id from the path alone, so the legacy ?id= shape it used no longer answers.

Companion PR: solidjs/solid-router#590.

Made with Cursor

solidjs/solid#3076 moved the function id into the path
(`<endpoint>/<id>`), retiring the X-Server-Function-Id header and the
`?id=` query fallback. The dev middleware and the generated
dispatchRequest gate matched the endpoint pathname exactly, so the new
addresses fell through to SSR; both now match by mount prefix (exact or
`endpoint + '/'`). The dev middleware's module-preload id comes from
the path segment, with the header and `?id=` forms kept as fallbacks
for a client runtime older than the addressing change.
Verified end-to-end against the fullstack-tanstack template with the
solid `next` runtime linked in: GET-declared reads (GET and HEAD),
405/403 gating, and the unscripted no-JS form POST flow (303 + flash)
all dispatch through the new addresses in dev.
Co-authored-by: Cursor <cursoragent@cursor.com>
@changeset-bot

changeset-botBot commented Aug 27, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eaea1d4

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@solidjs/vite-pluginMinor

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Aug 27, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@solidjs/vite-plugin@332

commit: eaea1d4

…table
Co-authored-by: Cursor <cursoragent@cursor.com>
@ryansolid

Copy link
Copy Markdown
MemberAuthor

Per review: the header/?id= fallbacks in the dev middleware are marked TRANSITIONAL and scoped to the RC window only — they get dropped before the 3.0 stable release. Path addressing is the only wire format from stable on.

rc.4 publishes the path-addressed server function calls this branch
routes (solidjs/solid#3076): the client computes `<endpoint>/<id>` and
the published server handler resolves the id from the path alone — the
X-Server-Function-Id header and `?id=` forms are gone from the runtime,
not just retired client-side. The workspace catalog moves to
^2.0.0-rc.4 (minimumReleaseAgeExclude extended per the existing
pattern), and the start-ssr suite's synthetic dispatches switch from
`?id=` to the path form, since the published handler no longer answers
the legacy shape. The plugin's own transitional fallbacks stay: they
serve runtimes older than the addressing change, which the peer range
still admits.
Full gate green against published rc.4 (no linking): ssr 12/12 +
boundary 8/8, css-matrix 82/82 + bridge 19/19, start-ssr 366/366 +
http-bridge 10/10, start-client 45/45, start-env 47/47, vite-8 vitest
1/1, cypress e2e 1/1.
Co-authored-by: Cursor <cursoragent@cursor.com>
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Added@​solidjs/​diagnostics@​2.0.0-rc.4761009991100

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnMedium
Low adoption: npm @solidjs/diagnostics

Location:Package overview

From:package.jsonnpm/@solidjs/diagnostics@2.0.0-rc.4

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@solidjs/diagnostics@2.0.0-rc.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@ryansolid
ryansolid marked this pull request as ready for review August 28, 2026 22:00
@ryansolid
ryansolid merged commit 54fcdfb into nextAug 28, 2026
6 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ryansolid
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Route path-addressed server function calls - #332

Merged
ryansolid merged 3 commits into
nextfrom
server-function-path-addressing
Aug 28, 2026
Merged

Route path-addressed server function calls#332
ryansolid merged 3 commits into
nextfrom
server-function-path-addressing

Conversation

@ryansolid

@ryansolidryansolid commented Aug 27, 2026

Copy link
Copy Markdown
Member

Summary

Downstream adoption of solidjs/solid#3076: a server function call's address is now <endpoint>/<id> with arguments in the query, and the X-Server-Function-Id header and ?id= fallback left the wire.

  • Dev middleware (server-functions/index.ts): the endpoint gate matched the pathname exactly, so path-addressed calls fell through to SSR. It now matches by mount prefix (exact or endpoint + '/'), for both the base-prefixed and base-stripped forms. The module-preload function id comes from the path segment; the header and ?id= forms stay as fallbacks for a client runtime older than the addressing change.
  • Generated dispatch gate (ssr/index.ts): the emitted dispatchRequest composed server functions only at pathname === endpoint; it now prefix-matches the same way. A bare-mount request still routes to the runtime handler, which answers the 404 — a misaddressed post fails through the endpoint rather than rendering a page at it.

Draft until

@solidjs/web publishes the addressing change (anything newer than 2.0.0-rc.3). The plugin change is backward-compatible on its own — exact-match and the fallback id channels keep an older runtime working.

Test plan

  • Verified end-to-end against the fullstack-tanstack template with the solid next runtime linked in: GET-declared reads over /_server/<id> (GET returns data + default no-store, HEAD returns bodyless 200), undeclared reads gated (403/405), and the unscripted no-JS form POST flow (303 + flash cookie) all dispatch through the dev middleware.
  • Cypress example suite against the published @solidjs/web@2.0.0-rc.4 (dist-tag next), plus the full release gate: ssr 12/12 + boundary 8/8, css-matrix 82/82 + bridge 19/19, start-ssr 366/366 + http-bridge 10/10, start-client 45/45, start-env 47/47, vite-8 vitest 1/1, cypress 1/1. The ride commit moves the workspace catalog to ^2.0.0-rc.4 and switches the start-ssr suite's synthetic dispatches to the path form — rc.4's published handler resolves the id from the path alone, so the legacy ?id= shape it used no longer answers.

Companion PR: solidjs/solid-router#590.

Made with Cursor

solidjs/solid#3076 moved the function id into the path
(`<endpoint>/<id>`), retiring the X-Server-Function-Id header and the
`?id=` query fallback. The dev middleware and the generated
dispatchRequest gate matched the endpoint pathname exactly, so the new
addresses fell through to SSR; both now match by mount prefix (exact or
`endpoint + '/'`). The dev middleware's module-preload id comes from
the path segment, with the header and `?id=` forms kept as fallbacks
for a client runtime older than the addressing change.
Verified end-to-end against the fullstack-tanstack template with the
solid `next` runtime linked in: GET-declared reads (GET and HEAD),
405/403 gating, and the unscripted no-JS form POST flow (303 + flash)
all dispatch through the new addresses in dev.
Co-authored-by: Cursor <cursoragent@cursor.com>
@changeset-bot

changeset-botBot commented Aug 27, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eaea1d4

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@solidjs/vite-pluginMinor

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Aug 27, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@solidjs/vite-plugin@332

commit: eaea1d4

…table
Co-authored-by: Cursor <cursoragent@cursor.com>
@ryansolid

Copy link
Copy Markdown
MemberAuthor

Per review: the header/?id= fallbacks in the dev middleware are marked TRANSITIONAL and scoped to the RC window only — they get dropped before the 3.0 stable release. Path addressing is the only wire format from stable on.

rc.4 publishes the path-addressed server function calls this branch
routes (solidjs/solid#3076): the client computes `<endpoint>/<id>` and
the published server handler resolves the id from the path alone — the
X-Server-Function-Id header and `?id=` forms are gone from the runtime,
not just retired client-side. The workspace catalog moves to
^2.0.0-rc.4 (minimumReleaseAgeExclude extended per the existing
pattern), and the start-ssr suite's synthetic dispatches switch from
`?id=` to the path form, since the published handler no longer answers
the legacy shape. The plugin's own transitional fallbacks stay: they
serve runtimes older than the addressing change, which the peer range
still admits.
Full gate green against published rc.4 (no linking): ssr 12/12 +
boundary 8/8, css-matrix 82/82 + bridge 19/19, start-ssr 366/366 +
http-bridge 10/10, start-client 45/45, start-env 47/47, vite-8 vitest
1/1, cypress e2e 1/1.
Co-authored-by: Cursor <cursoragent@cursor.com>
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Added@​solidjs/​diagnostics@​2.0.0-rc.4761009991100

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnMedium
Low adoption: npm @solidjs/diagnostics

Location:Package overview

From:package.jsonnpm/@solidjs/diagnostics@2.0.0-rc.4

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@solidjs/diagnostics@2.0.0-rc.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@ryansolid
ryansolid marked this pull request as ready for review August 28, 2026 22:00
@ryansolid
ryansolid merged commit 54fcdfb into nextAug 28, 2026
6 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ryansolid
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Route path-addressed server function calls - #332

Merged
ryansolid merged 3 commits into
nextfrom
server-function-path-addressing
Aug 28, 2026
Merged

Route path-addressed server function calls#332
ryansolid merged 3 commits into
nextfrom
server-function-path-addressing

Conversation

@ryansolid

@ryansolidryansolid commented Aug 27, 2026

Copy link
Copy Markdown
Member

Summary

Downstream adoption of solidjs/solid#3076: a server function call's address is now <endpoint>/<id> with arguments in the query, and the X-Server-Function-Id header and ?id= fallback left the wire.

  • Dev middleware (server-functions/index.ts): the endpoint gate matched the pathname exactly, so path-addressed calls fell through to SSR. It now matches by mount prefix (exact or endpoint + '/'), for both the base-prefixed and base-stripped forms. The module-preload function id comes from the path segment; the header and ?id= forms stay as fallbacks for a client runtime older than the addressing change.
  • Generated dispatch gate (ssr/index.ts): the emitted dispatchRequest composed server functions only at pathname === endpoint; it now prefix-matches the same way. A bare-mount request still routes to the runtime handler, which answers the 404 — a misaddressed post fails through the endpoint rather than rendering a page at it.

Draft until

@solidjs/web publishes the addressing change (anything newer than 2.0.0-rc.3). The plugin change is backward-compatible on its own — exact-match and the fallback id channels keep an older runtime working.

Test plan

  • Verified end-to-end against the fullstack-tanstack template with the solid next runtime linked in: GET-declared reads over /_server/<id> (GET returns data + default no-store, HEAD returns bodyless 200), undeclared reads gated (403/405), and the unscripted no-JS form POST flow (303 + flash cookie) all dispatch through the dev middleware.
  • Cypress example suite against the published @solidjs/web@2.0.0-rc.4 (dist-tag next), plus the full release gate: ssr 12/12 + boundary 8/8, css-matrix 82/82 + bridge 19/19, start-ssr 366/366 + http-bridge 10/10, start-client 45/45, start-env 47/47, vite-8 vitest 1/1, cypress 1/1. The ride commit moves the workspace catalog to ^2.0.0-rc.4 and switches the start-ssr suite's synthetic dispatches to the path form — rc.4's published handler resolves the id from the path alone, so the legacy ?id= shape it used no longer answers.

Companion PR: solidjs/solid-router#590.

Made with Cursor

solidjs/solid#3076 moved the function id into the path
(`<endpoint>/<id>`), retiring the X-Server-Function-Id header and the
`?id=` query fallback. The dev middleware and the generated
dispatchRequest gate matched the endpoint pathname exactly, so the new
addresses fell through to SSR; both now match by mount prefix (exact or
`endpoint + '/'`). The dev middleware's module-preload id comes from
the path segment, with the header and `?id=` forms kept as fallbacks
for a client runtime older than the addressing change.
Verified end-to-end against the fullstack-tanstack template with the
solid `next` runtime linked in: GET-declared reads (GET and HEAD),
405/403 gating, and the unscripted no-JS form POST flow (303 + flash)
all dispatch through the new addresses in dev.
Co-authored-by: Cursor <cursoragent@cursor.com>
@changeset-bot

changeset-botBot commented Aug 27, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eaea1d4

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@solidjs/vite-pluginMinor

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Aug 27, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@solidjs/vite-plugin@332

commit: eaea1d4

…table
Co-authored-by: Cursor <cursoragent@cursor.com>
@ryansolid

Copy link
Copy Markdown
MemberAuthor

Per review: the header/?id= fallbacks in the dev middleware are marked TRANSITIONAL and scoped to the RC window only — they get dropped before the 3.0 stable release. Path addressing is the only wire format from stable on.

rc.4 publishes the path-addressed server function calls this branch
routes (solidjs/solid#3076): the client computes `<endpoint>/<id>` and
the published server handler resolves the id from the path alone — the
X-Server-Function-Id header and `?id=` forms are gone from the runtime,
not just retired client-side. The workspace catalog moves to
^2.0.0-rc.4 (minimumReleaseAgeExclude extended per the existing
pattern), and the start-ssr suite's synthetic dispatches switch from
`?id=` to the path form, since the published handler no longer answers
the legacy shape. The plugin's own transitional fallbacks stay: they
serve runtimes older than the addressing change, which the peer range
still admits.
Full gate green against published rc.4 (no linking): ssr 12/12 +
boundary 8/8, css-matrix 82/82 + bridge 19/19, start-ssr 366/366 +
http-bridge 10/10, start-client 45/45, start-env 47/47, vite-8 vitest
1/1, cypress e2e 1/1.
Co-authored-by: Cursor <cursoragent@cursor.com>
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Added@​solidjs/​diagnostics@​2.0.0-rc.4761009991100

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnMedium
Low adoption: npm @solidjs/diagnostics

Location:Package overview

From:package.jsonnpm/@solidjs/diagnostics@2.0.0-rc.4

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@solidjs/diagnostics@2.0.0-rc.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@ryansolid
ryansolid marked this pull request as ready for review August 28, 2026 22:00
@ryansolid
ryansolid merged commit 54fcdfb into nextAug 28, 2026
6 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ryansolid
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Route path-addressed server function calls - #332

Merged
ryansolid merged 3 commits into
nextfrom
server-function-path-addressing
Aug 28, 2026
Merged

Route path-addressed server function calls#332
ryansolid merged 3 commits into
nextfrom
server-function-path-addressing

Conversation

@ryansolid

@ryansolidryansolid commented Aug 27, 2026

Copy link
Copy Markdown
Member

Summary

Downstream adoption of solidjs/solid#3076: a server function call's address is now <endpoint>/<id> with arguments in the query, and the X-Server-Function-Id header and ?id= fallback left the wire.

  • Dev middleware (server-functions/index.ts): the endpoint gate matched the pathname exactly, so path-addressed calls fell through to SSR. It now matches by mount prefix (exact or endpoint + '/'), for both the base-prefixed and base-stripped forms. The module-preload function id comes from the path segment; the header and ?id= forms stay as fallbacks for a client runtime older than the addressing change.
  • Generated dispatch gate (ssr/index.ts): the emitted dispatchRequest composed server functions only at pathname === endpoint; it now prefix-matches the same way. A bare-mount request still routes to the runtime handler, which answers the 404 — a misaddressed post fails through the endpoint rather than rendering a page at it.

Draft until

@solidjs/web publishes the addressing change (anything newer than 2.0.0-rc.3). The plugin change is backward-compatible on its own — exact-match and the fallback id channels keep an older runtime working.

Test plan

  • Verified end-to-end against the fullstack-tanstack template with the solid next runtime linked in: GET-declared reads over /_server/<id> (GET returns data + default no-store, HEAD returns bodyless 200), undeclared reads gated (403/405), and the unscripted no-JS form POST flow (303 + flash cookie) all dispatch through the dev middleware.
  • Cypress example suite against the published @solidjs/web@2.0.0-rc.4 (dist-tag next), plus the full release gate: ssr 12/12 + boundary 8/8, css-matrix 82/82 + bridge 19/19, start-ssr 366/366 + http-bridge 10/10, start-client 45/45, start-env 47/47, vite-8 vitest 1/1, cypress 1/1. The ride commit moves the workspace catalog to ^2.0.0-rc.4 and switches the start-ssr suite's synthetic dispatches to the path form — rc.4's published handler resolves the id from the path alone, so the legacy ?id= shape it used no longer answers.

Companion PR: solidjs/solid-router#590.

Made with Cursor

solidjs/solid#3076 moved the function id into the path
(`<endpoint>/<id>`), retiring the X-Server-Function-Id header and the
`?id=` query fallback. The dev middleware and the generated
dispatchRequest gate matched the endpoint pathname exactly, so the new
addresses fell through to SSR; both now match by mount prefix (exact or
`endpoint + '/'`). The dev middleware's module-preload id comes from
the path segment, with the header and `?id=` forms kept as fallbacks
for a client runtime older than the addressing change.
Verified end-to-end against the fullstack-tanstack template with the
solid `next` runtime linked in: GET-declared reads (GET and HEAD),
405/403 gating, and the unscripted no-JS form POST flow (303 + flash)
all dispatch through the new addresses in dev.
Co-authored-by: Cursor <cursoragent@cursor.com>
@changeset-bot

changeset-botBot commented Aug 27, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eaea1d4

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@solidjs/vite-pluginMinor

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Aug 27, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@solidjs/vite-plugin@332

commit: eaea1d4

…table
Co-authored-by: Cursor <cursoragent@cursor.com>
@ryansolid

Copy link
Copy Markdown
MemberAuthor

Per review: the header/?id= fallbacks in the dev middleware are marked TRANSITIONAL and scoped to the RC window only — they get dropped before the 3.0 stable release. Path addressing is the only wire format from stable on.

rc.4 publishes the path-addressed server function calls this branch
routes (solidjs/solid#3076): the client computes `<endpoint>/<id>` and
the published server handler resolves the id from the path alone — the
X-Server-Function-Id header and `?id=` forms are gone from the runtime,
not just retired client-side. The workspace catalog moves to
^2.0.0-rc.4 (minimumReleaseAgeExclude extended per the existing
pattern), and the start-ssr suite's synthetic dispatches switch from
`?id=` to the path form, since the published handler no longer answers
the legacy shape. The plugin's own transitional fallbacks stay: they
serve runtimes older than the addressing change, which the peer range
still admits.
Full gate green against published rc.4 (no linking): ssr 12/12 +
boundary 8/8, css-matrix 82/82 + bridge 19/19, start-ssr 366/366 +
http-bridge 10/10, start-client 45/45, start-env 47/47, vite-8 vitest
1/1, cypress e2e 1/1.
Co-authored-by: Cursor <cursoragent@cursor.com>
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Added@​solidjs/​diagnostics@​2.0.0-rc.4761009991100

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnMedium
Low adoption: npm @solidjs/diagnostics

Location:Package overview

From:package.jsonnpm/@solidjs/diagnostics@2.0.0-rc.4

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@solidjs/diagnostics@2.0.0-rc.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@ryansolid
ryansolid marked this pull request as ready for review August 28, 2026 22:00
@ryansolid
ryansolid merged commit 54fcdfb into nextAug 28, 2026
6 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ryansolid
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Route path-addressed server function calls - #332

Merged
ryansolid merged 3 commits into
nextfrom
server-function-path-addressing
Aug 28, 2026
Merged

Route path-addressed server function calls#332
ryansolid merged 3 commits into
nextfrom
server-function-path-addressing

Conversation

@ryansolid

@ryansolidryansolid commented Aug 27, 2026

Copy link
Copy Markdown
Member

Summary

Downstream adoption of solidjs/solid#3076: a server function call's address is now <endpoint>/<id> with arguments in the query, and the X-Server-Function-Id header and ?id= fallback left the wire.

  • Dev middleware (server-functions/index.ts): the endpoint gate matched the pathname exactly, so path-addressed calls fell through to SSR. It now matches by mount prefix (exact or endpoint + '/'), for both the base-prefixed and base-stripped forms. The module-preload function id comes from the path segment; the header and ?id= forms stay as fallbacks for a client runtime older than the addressing change.
  • Generated dispatch gate (ssr/index.ts): the emitted dispatchRequest composed server functions only at pathname === endpoint; it now prefix-matches the same way. A bare-mount request still routes to the runtime handler, which answers the 404 — a misaddressed post fails through the endpoint rather than rendering a page at it.

Draft until

@solidjs/web publishes the addressing change (anything newer than 2.0.0-rc.3). The plugin change is backward-compatible on its own — exact-match and the fallback id channels keep an older runtime working.

Test plan

  • Verified end-to-end against the fullstack-tanstack template with the solid next runtime linked in: GET-declared reads over /_server/<id> (GET returns data + default no-store, HEAD returns bodyless 200), undeclared reads gated (403/405), and the unscripted no-JS form POST flow (303 + flash cookie) all dispatch through the dev middleware.
  • Cypress example suite against the published @solidjs/web@2.0.0-rc.4 (dist-tag next), plus the full release gate: ssr 12/12 + boundary 8/8, css-matrix 82/82 + bridge 19/19, start-ssr 366/366 + http-bridge 10/10, start-client 45/45, start-env 47/47, vite-8 vitest 1/1, cypress 1/1. The ride commit moves the workspace catalog to ^2.0.0-rc.4 and switches the start-ssr suite's synthetic dispatches to the path form — rc.4's published handler resolves the id from the path alone, so the legacy ?id= shape it used no longer answers.

Companion PR: solidjs/solid-router#590.

Made with Cursor

solidjs/solid#3076 moved the function id into the path
(`<endpoint>/<id>`), retiring the X-Server-Function-Id header and the
`?id=` query fallback. The dev middleware and the generated
dispatchRequest gate matched the endpoint pathname exactly, so the new
addresses fell through to SSR; both now match by mount prefix (exact or
`endpoint + '/'`). The dev middleware's module-preload id comes from
the path segment, with the header and `?id=` forms kept as fallbacks
for a client runtime older than the addressing change.
Verified end-to-end against the fullstack-tanstack template with the
solid `next` runtime linked in: GET-declared reads (GET and HEAD),
405/403 gating, and the unscripted no-JS form POST flow (303 + flash)
all dispatch through the new addresses in dev.
Co-authored-by: Cursor <cursoragent@cursor.com>
@changeset-bot

changeset-botBot commented Aug 27, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eaea1d4

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@solidjs/vite-pluginMinor

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Aug 27, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@solidjs/vite-plugin@332

commit: eaea1d4

…table
Co-authored-by: Cursor <cursoragent@cursor.com>
@ryansolid

Copy link
Copy Markdown
MemberAuthor

Per review: the header/?id= fallbacks in the dev middleware are marked TRANSITIONAL and scoped to the RC window only — they get dropped before the 3.0 stable release. Path addressing is the only wire format from stable on.

rc.4 publishes the path-addressed server function calls this branch
routes (solidjs/solid#3076): the client computes `<endpoint>/<id>` and
the published server handler resolves the id from the path alone — the
X-Server-Function-Id header and `?id=` forms are gone from the runtime,
not just retired client-side. The workspace catalog moves to
^2.0.0-rc.4 (minimumReleaseAgeExclude extended per the existing
pattern), and the start-ssr suite's synthetic dispatches switch from
`?id=` to the path form, since the published handler no longer answers
the legacy shape. The plugin's own transitional fallbacks stay: they
serve runtimes older than the addressing change, which the peer range
still admits.
Full gate green against published rc.4 (no linking): ssr 12/12 +
boundary 8/8, css-matrix 82/82 + bridge 19/19, start-ssr 366/366 +
http-bridge 10/10, start-client 45/45, start-env 47/47, vite-8 vitest
1/1, cypress e2e 1/1.
Co-authored-by: Cursor <cursoragent@cursor.com>
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Added@​solidjs/​diagnostics@​2.0.0-rc.4761009991100

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnMedium
Low adoption: npm @solidjs/diagnostics

Location:Package overview

From:package.jsonnpm/@solidjs/diagnostics@2.0.0-rc.4

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@solidjs/diagnostics@2.0.0-rc.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@ryansolid
ryansolid marked this pull request as ready for review August 28, 2026 22:00
@ryansolid
ryansolid merged commit 54fcdfb into nextAug 28, 2026
6 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ryansolid
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Route path-addressed server function calls - #332

Merged
ryansolid merged 3 commits into
nextfrom
server-function-path-addressing
Aug 28, 2026
Merged

Route path-addressed server function calls#332
ryansolid merged 3 commits into
nextfrom
server-function-path-addressing

Conversation

@ryansolid

@ryansolidryansolid commented Aug 27, 2026

Copy link
Copy Markdown
Member

Summary

Downstream adoption of solidjs/solid#3076: a server function call's address is now <endpoint>/<id> with arguments in the query, and the X-Server-Function-Id header and ?id= fallback left the wire.

  • Dev middleware (server-functions/index.ts): the endpoint gate matched the pathname exactly, so path-addressed calls fell through to SSR. It now matches by mount prefix (exact or endpoint + '/'), for both the base-prefixed and base-stripped forms. The module-preload function id comes from the path segment; the header and ?id= forms stay as fallbacks for a client runtime older than the addressing change.
  • Generated dispatch gate (ssr/index.ts): the emitted dispatchRequest composed server functions only at pathname === endpoint; it now prefix-matches the same way. A bare-mount request still routes to the runtime handler, which answers the 404 — a misaddressed post fails through the endpoint rather than rendering a page at it.

Draft until

@solidjs/web publishes the addressing change (anything newer than 2.0.0-rc.3). The plugin change is backward-compatible on its own — exact-match and the fallback id channels keep an older runtime working.

Test plan

  • Verified end-to-end against the fullstack-tanstack template with the solid next runtime linked in: GET-declared reads over /_server/<id> (GET returns data + default no-store, HEAD returns bodyless 200), undeclared reads gated (403/405), and the unscripted no-JS form POST flow (303 + flash cookie) all dispatch through the dev middleware.
  • Cypress example suite against the published @solidjs/web@2.0.0-rc.4 (dist-tag next), plus the full release gate: ssr 12/12 + boundary 8/8, css-matrix 82/82 + bridge 19/19, start-ssr 366/366 + http-bridge 10/10, start-client 45/45, start-env 47/47, vite-8 vitest 1/1, cypress 1/1. The ride commit moves the workspace catalog to ^2.0.0-rc.4 and switches the start-ssr suite's synthetic dispatches to the path form — rc.4's published handler resolves the id from the path alone, so the legacy ?id= shape it used no longer answers.

Companion PR: solidjs/solid-router#590.

Made with Cursor

solidjs/solid#3076 moved the function id into the path
(`<endpoint>/<id>`), retiring the X-Server-Function-Id header and the
`?id=` query fallback. The dev middleware and the generated
dispatchRequest gate matched the endpoint pathname exactly, so the new
addresses fell through to SSR; both now match by mount prefix (exact or
`endpoint + '/'`). The dev middleware's module-preload id comes from
the path segment, with the header and `?id=` forms kept as fallbacks
for a client runtime older than the addressing change.
Verified end-to-end against the fullstack-tanstack template with the
solid `next` runtime linked in: GET-declared reads (GET and HEAD),
405/403 gating, and the unscripted no-JS form POST flow (303 + flash)
all dispatch through the new addresses in dev.
Co-authored-by: Cursor <cursoragent@cursor.com>
@changeset-bot

changeset-botBot commented Aug 27, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eaea1d4

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@solidjs/vite-pluginMinor

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Aug 27, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@solidjs/vite-plugin@332

commit: eaea1d4

…table
Co-authored-by: Cursor <cursoragent@cursor.com>
@ryansolid

Copy link
Copy Markdown
MemberAuthor

Per review: the header/?id= fallbacks in the dev middleware are marked TRANSITIONAL and scoped to the RC window only — they get dropped before the 3.0 stable release. Path addressing is the only wire format from stable on.

rc.4 publishes the path-addressed server function calls this branch
routes (solidjs/solid#3076): the client computes `<endpoint>/<id>` and
the published server handler resolves the id from the path alone — the
X-Server-Function-Id header and `?id=` forms are gone from the runtime,
not just retired client-side. The workspace catalog moves to
^2.0.0-rc.4 (minimumReleaseAgeExclude extended per the existing
pattern), and the start-ssr suite's synthetic dispatches switch from
`?id=` to the path form, since the published handler no longer answers
the legacy shape. The plugin's own transitional fallbacks stay: they
serve runtimes older than the addressing change, which the peer range
still admits.
Full gate green against published rc.4 (no linking): ssr 12/12 +
boundary 8/8, css-matrix 82/82 + bridge 19/19, start-ssr 366/366 +
http-bridge 10/10, start-client 45/45, start-env 47/47, vite-8 vitest
1/1, cypress e2e 1/1.
Co-authored-by: Cursor <cursoragent@cursor.com>
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Added@​solidjs/​diagnostics@​2.0.0-rc.4761009991100

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnMedium
Low adoption: npm @solidjs/diagnostics

Location:Package overview

From:package.jsonnpm/@solidjs/diagnostics@2.0.0-rc.4

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@solidjs/diagnostics@2.0.0-rc.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@ryansolid
ryansolid marked this pull request as ready for review August 28, 2026 22:00
@ryansolid
ryansolid merged commit 54fcdfb into nextAug 28, 2026
6 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ryansolid
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Route path-addressed server function calls - #332

Merged
ryansolid merged 3 commits into
nextfrom
server-function-path-addressing
Aug 28, 2026
Merged

Route path-addressed server function calls#332
ryansolid merged 3 commits into
nextfrom
server-function-path-addressing

Conversation

@ryansolid

@ryansolidryansolid commented Aug 27, 2026

Copy link
Copy Markdown
Member

Summary

Downstream adoption of solidjs/solid#3076: a server function call's address is now <endpoint>/<id> with arguments in the query, and the X-Server-Function-Id header and ?id= fallback left the wire.

  • Dev middleware (server-functions/index.ts): the endpoint gate matched the pathname exactly, so path-addressed calls fell through to SSR. It now matches by mount prefix (exact or endpoint + '/'), for both the base-prefixed and base-stripped forms. The module-preload function id comes from the path segment; the header and ?id= forms stay as fallbacks for a client runtime older than the addressing change.
  • Generated dispatch gate (ssr/index.ts): the emitted dispatchRequest composed server functions only at pathname === endpoint; it now prefix-matches the same way. A bare-mount request still routes to the runtime handler, which answers the 404 — a misaddressed post fails through the endpoint rather than rendering a page at it.

Draft until

@solidjs/web publishes the addressing change (anything newer than 2.0.0-rc.3). The plugin change is backward-compatible on its own — exact-match and the fallback id channels keep an older runtime working.

Test plan

  • Verified end-to-end against the fullstack-tanstack template with the solid next runtime linked in: GET-declared reads over /_server/<id> (GET returns data + default no-store, HEAD returns bodyless 200), undeclared reads gated (403/405), and the unscripted no-JS form POST flow (303 + flash cookie) all dispatch through the dev middleware.
  • Cypress example suite against the published @solidjs/web@2.0.0-rc.4 (dist-tag next), plus the full release gate: ssr 12/12 + boundary 8/8, css-matrix 82/82 + bridge 19/19, start-ssr 366/366 + http-bridge 10/10, start-client 45/45, start-env 47/47, vite-8 vitest 1/1, cypress 1/1. The ride commit moves the workspace catalog to ^2.0.0-rc.4 and switches the start-ssr suite's synthetic dispatches to the path form — rc.4's published handler resolves the id from the path alone, so the legacy ?id= shape it used no longer answers.

Companion PR: solidjs/solid-router#590.

Made with Cursor

solidjs/solid#3076 moved the function id into the path
(`<endpoint>/<id>`), retiring the X-Server-Function-Id header and the
`?id=` query fallback. The dev middleware and the generated
dispatchRequest gate matched the endpoint pathname exactly, so the new
addresses fell through to SSR; both now match by mount prefix (exact or
`endpoint + '/'`). The dev middleware's module-preload id comes from
the path segment, with the header and `?id=` forms kept as fallbacks
for a client runtime older than the addressing change.
Verified end-to-end against the fullstack-tanstack template with the
solid `next` runtime linked in: GET-declared reads (GET and HEAD),
405/403 gating, and the unscripted no-JS form POST flow (303 + flash)
all dispatch through the new addresses in dev.
Co-authored-by: Cursor <cursoragent@cursor.com>
@changeset-bot

changeset-botBot commented Aug 27, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eaea1d4

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@solidjs/vite-pluginMinor

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Aug 27, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@solidjs/vite-plugin@332

commit: eaea1d4

…table
Co-authored-by: Cursor <cursoragent@cursor.com>
@ryansolid

Copy link
Copy Markdown
MemberAuthor

Per review: the header/?id= fallbacks in the dev middleware are marked TRANSITIONAL and scoped to the RC window only — they get dropped before the 3.0 stable release. Path addressing is the only wire format from stable on.

rc.4 publishes the path-addressed server function calls this branch
routes (solidjs/solid#3076): the client computes `<endpoint>/<id>` and
the published server handler resolves the id from the path alone — the
X-Server-Function-Id header and `?id=` forms are gone from the runtime,
not just retired client-side. The workspace catalog moves to
^2.0.0-rc.4 (minimumReleaseAgeExclude extended per the existing
pattern), and the start-ssr suite's synthetic dispatches switch from
`?id=` to the path form, since the published handler no longer answers
the legacy shape. The plugin's own transitional fallbacks stay: they
serve runtimes older than the addressing change, which the peer range
still admits.
Full gate green against published rc.4 (no linking): ssr 12/12 +
boundary 8/8, css-matrix 82/82 + bridge 19/19, start-ssr 366/366 +
http-bridge 10/10, start-client 45/45, start-env 47/47, vite-8 vitest
1/1, cypress e2e 1/1.
Co-authored-by: Cursor <cursoragent@cursor.com>
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Added@​solidjs/​diagnostics@​2.0.0-rc.4761009991100

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnMedium
Low adoption: npm @solidjs/diagnostics

Location:Package overview

From:package.jsonnpm/@solidjs/diagnostics@2.0.0-rc.4

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@solidjs/diagnostics@2.0.0-rc.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@ryansolid
ryansolid marked this pull request as ready for review August 28, 2026 22:00
@ryansolid
ryansolid merged commit 54fcdfb into nextAug 28, 2026
6 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ryansolid