Skip to content

fix: allow importing the bundle without a DOM - #210

Merged
Kikobeats merged 1 commit into
microlinkhq:masterfrom
theluckystrike:fix/ssr-document
Oct 3, 2026
Merged

Kikobeats merged 1 commit into
microlinkhq:masterfrom
theluckystrike:fix/ssr-document

Conversation

@theluckystrike

@theluckystrike theluckystrike commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #149

What

require('@microlink/react-json-view') throws ReferenceError: document is not defined in Node. So the package breaks during SSR, for example in Next.js.

Why

dist/main.js is built with webpack for the web target. For react-textarea-autosize, webpack picks its browser build. That build runs this line when the module loads:

var isIE = !!document.documentElement.currentStyle

The package also ships a default build that checks typeof document !== 'undefined' first. That one works in both Node and the browser.

How

One alias in webpack/webpack.config.js points react-textarea-autosize at its default build. Nothing in src changes. In the browser it behaves the same. The minified bundle grows from 110501 to 112002 bytes.

Tests

New test test/tests/js/Bundle-test.js builds the bundle with the real webpack config. Then it runs it in a fresh vm context with no window or document.

Before the fix:

0 passing
1 failing
ReferenceError: document is not defined

After the fix the full suite passes, 204 tests. I also checked the built dist/main.js by hand on Node 25:

  • require('./dist/main.js') works
  • renderToString of <ReactJsonView src={{ a: 1 }} /> returns HTML
  • import('./index.mjs') works
  • rendering into a jsdom page still works

standard reports no new findings on the changed files.

Summary by CodeRabbit

  • Bug Fixes
    • Improved server-side rendering compatibility by preventing browser-only code from running during package imports.
  • Tests
    • Added a check that the bundled package can be loaded without browser globals.

The webpack build picked the browser build of react-textarea-autosize,
which reads document at import time. Bundle its default build instead,
which checks for document first.

Fixes microlinkhq#149

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Oct 3, 2026

Copy link
Copy Markdown

@theluckystrike is attempting to deploy a commit to the Microlink Team on Vercel.

A member of the Team first needs to authorize it.

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: e28bc6a3-5918-4597-9459-7cc53983f6c3
📥 Commits

Reviewing files that changed from the base of the PR and between 1dcdcfe and 07a8970.

📒 Files selected for processing (2)
  • test/tests/js/Bundle-test.js
  • webpack/webpack.config.js

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.


📝 Walkthrough

Walkthrough

Webpack now resolves react-textarea-autosize through its default entry. A bundle test builds the output and checks that its default export is a function when evaluated without window or document.

Changes

SSR bundle import

Layer / File(s) Summary
Dependency resolution and bundle validation
webpack/webpack.config.js, test/tests/js/Bundle-test.js
Webpack aliases react-textarea-autosize to its default entry. The test builds the bundle without minification, evaluates it in a VM context without DOM globals, checks that the default export is a function, and removes temporary output.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix · Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to 07a89

The change lets the bundle be imported without a DOM by using the default build of react-textarea-autosize. No actionable merge-blocking risk remains.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 07a89

The change is narrowly scoped to server-compatible bundle loading. No new privileged capability or boundary bypass was identified. Verification remains limited because the exact dependency entry and generated bundle were unavailable.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The affected scope is consumers of the generated package bundle, including applications importing it during server rendering. Successful DOM-free loading is a compatibility expansion, not evidence of a new remotely accessible endpoint.

Trust Boundaries and Controls

  • inferred — The observed alias is fixed by build configuration rather than consumer input, and the VM executes locally generated test output. These paths do not establish an attacker-controlled module selector or additional runtime authority. This conclusion is bounded to the inspected configuration and test, not the unavailable dependency implementation.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly states the main change: enabling bundle imports without a DOM.
Linked Issues check ✅ Passed Issue #149 requires the package to import without browser globals during server-side evaluation. The webpack alias in webpack/webpack.config.js selects the dependency build that checks for `document…
Out of Scope Changes check ✅ Passed The webpack alias and bundle test both address issue #149 by preventing and checking DOM access during bundle evaluation. The reported changes show no unrelated modifications.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@vercel

vercel Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
react-json-view Ready Ready Preview Oct 3, 2026 8:43am UTC

Request Review

@Kikobeats

Copy link
Copy Markdown
Member

Awesome, thanks!

@Kikobeats
Kikobeats merged commit f3fa2dc into microlinkhq:master Oct 3, 2026
4 checks passed

This branch was successfully deployed

1 active deployment
Preview — 07a89708 Deployed Oct 3, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ReferenceError: document is not defined when importing the package in Next.js (SSR / RSC)

2 participants