Skip to content

Content-hash the Vite JS island bundles (stale-edge risk on ~50 /js/*.js) #1604

Description

@jung-thomas

Problem

The ~50 Vue island bundles are emitted by Vite with stable [name].js filenames (hugo-apps/vite.config.ts, output.entryFileNames: '[name].js') into hugo/static/js/, e.g. /js/navigator.js, /js/me.js, /js/joule.js. Layouts reference these by hardcoded stable path.

This is the same class of bug as the 2026-08-10 giant-logo incident (PR #1601 / #1603 fixed the CSS side): a CDN edge (Akamai on PROD) can serve a stale cached JS bundle against freshly-updated HTML. JS staleness is arguably worse than CSS — a stale bundle means broken interactivity, not just wrong styling.

Current mitigation is insufficient

Many templates append ?v={{ now.Unix }}, but that only busts the query string — the path is still stable, and a CDN keyed on path (ignoring query) can still serve stale. Several island scripts have no buster at all.

Proposed fix

  1. Change hugo-apps/vite.config.ts entryFileNames to '[name]-[hash].js' (chunks already hashed).
  2. Emit/consume Vite's manifest.json so Hugo templates resolve the hashed filename instead of hardcoding /js/<name>.js. Options: a Hugo data-file lookup partial, or a small build step that rewrites references.
  3. Update every <script src> in hugo/layouts/** to go through that lookup.
  4. Once hashed, these can safely get a long max-age/immutable in approuter/xs-app.json (currently public, max-age=3600 for all /js/*).

Scope

~50 entry bundles + all layout references. Bigger than a one-liner — needs the manifest plumbing. Split from the CSS fingerprinting (PR #1601, #1603) deliberately.

Also see

Companion follow-up: move/switch joule.css + sap-fundamental.css to fingerprintable resources.Get (separate issue). Assets CAP hardcodes at runtime (content-store.js, concept-list-page.js, catalog-renderer.js) can't be fingerprinted and need the CDN cache-policy fix (honor-origin / short-TTL-with-revalidation on /css/* + /js/*).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions