mir-frontend-vue-nuxt

Solid

Make It Right (Nuxt module). Nuxt 4.5 universal-rendering mechanics layered on the Vue tier — the failures that exist only because the same component code runs once in Nitro and again in the browser: bare $fetch in setup causing a double fetch; useAsyncData vs useFetch and the key/payload deduplication rules; module-scope state as a CROSS-REQUEST USER-DATA LEAK on the server (and CVE-2026-71316, where cached-route payload extraction served one user's SSR data to the next visitor); server-only vs client-only values and the hydration mismatch they produce; payload bloat from over-fetching in asyncData (pick/transform); Nitro server routes; runtimeConfig public vs private and what ships in the client payload; route middleware for auth and why client-side route middleware is never a security control (CVE-2026-53721 route-rule case bypass). Chains: mir-frontend → mir-frontend-vue → this. TRIGGER only when the Vue stack is Nuxt — a Nuxt page, layout, composable, server/api route, route middleware, plugin, Nuxt modu

Web & Frontend 15 stars 0 forks Updated 1 weeks ago Apache-2.0

Install

View on GitHub

Quality Score: 81/100

Stars 20%
40
Recency 20%
90
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# /mir-frontend-vue-nuxt · Make It Right (Nuxt) Bottom of the chain: `mir-frontend` (generic gates) → `mir-frontend-vue` (Vue reactivity) → **this** (Nuxt + Nitro mechanics). Run the gates first, load the Vue tier for reactivity, reach for this at Gate 5 (design), Gate 6 (implementation), and Gate 7 (review). **Vue-level concerns — `ref` vs `reactive`, `watch` vs `computed`, `provide`/`inject`, template refs — live in `mir-frontend-vue`, not here.** **Stack assumed**, versions verified 13 Aug 2026: Nuxt **4.5.2** (npm `latest`) · Vue 3.5.x · vue-router 5 (since Nuxt 4.4) · Nitro via `@nuxt/nitro-server` 4.5.2 over `nitropack` 2.13.x + h3 1.15.x · Vite 8 (Rolldown) or Rspack 2 · unhead v3. Node `^22.19.0 || ^24.11.0 || >=26.0.0`. - **Nuxt 3 reached end of life 31 July 2026** (3.21.11 is the last maintenance release). A Nuxt 3 app is an unpatched app — put that in the Gate 4 risk register, not in a footnote. **Version floor is 4.5.1**; anything below carries the July 2026 advisory set, including a cross-user data disclosure (see Security). - **Nuxt 5 is not released.** `future.compatibilityVersion: 5` opts into its breaking changes early. Do not put that flag in a Gate 5 design without labelling it a preview. ## The Nuxt footguns AI walks into ### 1. Universal rendering — know what runs twice Component `setup()` runs on the server to produce HTML, then runs **again** in the browser to hydrate. Anything non-deterministic between the two runs produces a hydration mismatch: ...

Details

Author
anantbhandarkar
Repository
anantbhandarkar/make-it-right
Created
3 months ago
Last Updated
1 weeks ago
Language
Python
License
Apache-2.0

Integrates with

Similar Skills

Semantically similar based on skill content — not just same category

Web & Frontend Solid

mir-frontend-vue

Make It Right (Vue reactivity tier). Vue 3.5 reactivity footguns shared across EVERY Vue meta-framework (Nuxt, Vite SPA, Quasar, legacy Vue CLI) — distinct from the generic frontend gates and from any one framework's mechanics. Covers where reactivity is silently lost (destructuring a reactive object, reassigning an array or object wholesale) and toRef/toRefs/toValue; computed purity — a side effect or fetch in a getter is a bug, because the getter is cached and may never re-run; watch vs watchEffect and pre/post/sync flush timing, deep-watch cost, and cleanup via onWatcherCleanup/effectScope plus the post-await registration trap; provide/inject typing and the non-reactive snapshot trap; v-for key correctness (index keys attach row state to the wrong row); defineModel; KeepAlive deactivation (onUnmounted never fires). Also carries Vue-runtime security: v-html, SSR cross-request state pollution from module-scope singletons, and VITE_-prefixed secrets in the client bundle. Chains: mir-frontend → this → mir-fron

15 Updated 1 weeks ago
anantbhandarkar
Web & Frontend Solid

mir-frontend-react-next

Make It Right (Next.js module). Next.js 16 App Router mechanics — the footguns that exist only in this meta-framework, not in React generally. Carries the Server/Client Component boundary and how one 'use client' pulls its entire import graph into the browser bundle; Server Actions as public POST endpoints that must re-authenticate and re-authorize on every call (hiding the button is not access control); proxy.ts as an optimistic redirect and never the sole auth gate — this framework has a repeating middleware-bypass advisory class (CVE-2025-29927, CVE-2026-45109); the opt-in caching layers after Next 16 ('use cache', cacheComponents, cacheTag, revalidateTag vs updateTag vs revalidatePath); request waterfalls from sequential awaits in nested layouts; and NEXT_PUBLIC_ vars inlined at build time. Chains: mir-frontend → mir-frontend-react → this. TRIGGER only when the React meta-framework is Next.js — work in app/, page.tsx, layout.tsx, route.ts, proxy.ts or middleware.ts, any 'use server' file, next.config.ts,

15 Updated 1 weeks ago
anantbhandarkar
Web & Frontend Solid

mir-frontend-vanilla

Make It Right (vanilla JS / no-framework reactivity tier). Plain-DOM footguns that no reactive library is present to hide. Covers event listeners never removed (the #1 leak) and AbortController as the removal mechanism; detached DOM nodes retained by a closure or a module-scope map; Intersection/Mutation/ResizeObservers never disconnected and timers that outlive their element; innerHTML as an XSS sink and the current alternatives (textContent, Element.setHTML + Sanitizer, Trusted Types CSP); manual state/DOM divergence and the idempotent render-from-state discipline; custom-element lifecycle and upgrade timing, shadow DOM style/focus/ARIA consequences; stale-response-overwrites-fresh-response fetch races; and manual focus management (focus after route change, dialog focus traps, aria-live). Chains: mir-frontend → this. TRIGGER when the UI is built with plain DOM APIs and no reactive library — vanilla JS/TypeScript, jQuery-era code, hand-written Web Components, a static site with its own script, a browser-exte

15 Updated 1 weeks ago
anantbhandarkar