What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A Content-Security-Policy (CSP) header does not blank a Next.js page by itself. It makes the browser refuse specific resources that the policy does not allow. If one of those refused resources is a script the page needs to run, the HTML may render but never become interactive, and on some pages the visible result looks like an empty screen. The fix starts with the browser’s own violation messages, not with loosening the policy.

This guide shows how to confirm that CSP is the cause, identify the exact blocked resource and directive, correct the policy without weakening it blindly, and rule out hydration errors and edge or CDN changes that can produce the same symptom.

Why a CSP header can stop a Next.js page from working

CSP is enforced by the browser. Each directive lists the sources the browser may load a resource from or run code from. When a page requests something outside those sources, the browser blocks it and logs a violation. For a Next.js page, the blocked item is often a script that the framework needs during hydration, the step where React attaches event handlers to server-rendered HTML. Without that script, the markup can be present while buttons, navigation, and data loading do nothing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Two things make this confusing. First, a blank screen is not specific: it can come from CSP, from a hydration mismatch, or from a proxy that rewrote the HTML. Second, the header is often added in one place while another layer already sends a policy. Your job is to find which policy, which directive, and which resource are involved before changing anything.

#1 Best Overall
Anker USB C to Ethernet Adapter, Portable 1 Gbps Network Hub
  • The Anker Advantage: Join the 65 million+ powered by our leading technology.
  • Instant Internet: Connect to the internet instantly from virtually any USB-C 3.0 device, and enjoy stable connection speeds of up to 1 Gbps.
  • Lightweight and Compact: The space-saving and portable design measures just over half an inch thick and weighs about the same as a AA battery.
  • Premium Build: Features a sleek aluminum exterior and braided-nylon cable to complement the design of high-end devices.
  • What You Get: PowerExpand USB-C to Gigabit Ethernet Adapter, welcome guide, 18-month worry-free warranty, and friendly customer service.

Confirm CSP is the cause

Work through these steps in order. Each one either proves the cause or rules it out.

  1. Reproduce with developer tools open. Open the affected URL in a fresh tab with DevTools open (F12 or Ctrl+Shift+I on Windows and Linux, Cmd+Option+I on macOS). Go to the Console tab and reload. Look for messages that begin with a CSP violation, and record the blocked URL or inline script, the directive named in the message, and the page URL.
  2. Inspect the document response headers. Go to the Network tab, select the HTML document request (the first entry for the page URL), and open the Headers section. Record every Content-Security-Policy and every Content-Security-Policy-Report-Only header. Check the HTML <head> for a <meta http-equiv="Content-Security-Policy"> element as well.
  3. Identify all layers that add a policy. A CDN, reverse proxy, load balancer, or hosting platform can add its own header alongside the one in your Next.js configuration. Multiple policies all apply, and each one can only further restrict what the page may do. A script is allowed only if every applicable policy permits it.
  4. Match the violation to code the page needs. A violation is not automatically the reason for the blank screen. Check whether the blocked resource is one of your application scripts, a framework script, a stylesheet, or an analytics or third-party request that the page can survive without.
  5. Check for a hydration error. If the violations are unrelated to the page’s critical scripts, or there are none, go to the hydration section below before editing any policy.

Read the violation and map it to a directive

The directive named in the console message tells you which part of the policy to change. The most common ones in this situation are listed below.

Rank #2
Sale
UGREEN USB C to Ethernet Adapter, Plug and Play 1Gbps Aluminum Adapter
  • USB-C Meets 1000Mbps Ethernet in Seconds:UGREEN usb c to ethernet adapter supports fast speeds up to 1000Mbps and is backward compatible with 100/10Mbps network. Perfect for work, gaming, streaming, or downloading with a stable, reliable wired connection
  • Extend a Ethernet Port for Your Device:This ethernet to usb c adds a Gigabit RJ45 port to your device. It’s the perfect solution for new laptops without built-in Ethernet, devices with damaged LAN ports, or when WiFi is unavailable or unstable
  • Plug and Play: This Ethernet adapter is driver-free for Windows 11/10/8.1/8, macOS, Chrome OS, and Android. Drivers are required for Windows XP/7/Vista and Linux, and can be easily installed using our instructions. LED indicator shows status at a glance
  • Small Adapter, Big Attention to Detail: The usb c to ethernet features a durable aluminum alloy case for faster heat dissipation than plastic. Its reinforced cable tail and wear-resistant port ensure long-lasting durability. Compact size and easy to carry
  • Widely Compatible: The usbc to ethernet adapter is compatible with most laptops, tablets, smartphones, Nintendo Switch, and Steam Deck with USB-C or Thunderbolt 4/3 port, like MacBook Pro/Air, XPS, iPhone 17/16/15 Pro/Pro Max, Mac Mini, Chromebook, iPad
Directive named in the violation What it controls What to check first
script-src Sources for JavaScript, including inline scripts and eval-style execution, when no more specific directive applies Whether the blocked script is external or inline, and whether it has a permitted nonce or hash
script-src-elem Sources for <script> elements specifically The origin of the external script file, or whether an inline script element lacks a valid nonce
style-src Sources for stylesheets and inline styles Whether a CSS-in-JS library or inline style injection is being blocked
connect-src Sources for network requests made from script, such as fetch, XHR, and WebSocket connections Whether a data API, auth endpoint, or analytics endpoint is blocked

The MDN script-src reference describes how JavaScript sources are restricted and how inline script is treated. Use it to confirm why a given inline script is blocked before you decide how to authorize it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose the right kind of policy

There are two implementation choices for a Next.js app, and they differ in how the policy is delivered and what must stay in sync.

Rank #3
Amazon Basics Aluminum USB-C to RJ45 Gigabit Ethernet Adapter, Portable, Fast Network, Grey, 2.07 x 0.81 x 0.6 inches
  • Adapter for converting a USB 3.1 Type-C port to a RJ45 Gigabit Ethernet port
  • Integrated Ethernet port supports 10M/100M/1000M bandwidth; offers instant Internet connection to the host
  • USB-C input allows for reversible plugging; offers complete compatibility with current computers and devices; compatible with Nintendo Switch
  • Ready to use, right out of the box; no external power adapter needed
  • Slim, compact size and lightweight aluminum housing for easy portability
Approach How it is delivered Best fit Main cost
Static policy A fixed Content-Security-Policy value set through the headers() option in next.config.js for matching paths Applications that do not need per-response nonces and whose script sources are known in advance Any inline script must be authorized another way, and the rule set must be kept narrow by hand
Nonce-based policy A fresh nonce generated per request, placed in the response policy and on each rendered script element Applications that need inline scripts from the framework or application while still avoiding 'unsafe-inline' Requires dynamic rendering for the affected pages and a per-response match between header and markup

Static policy for pages without nonces

Next.js documents setting response headers through next.config.js for paths you specify. Keep the match deliberate. A document-level CSP belongs on HTML documents, and the Next.js Pages Router CSP guide recommends excluding static assets and prefetch requests that do not need the policy. Applying one broad rule to every request can add headers to files where they serve no purpose and make failures harder to read.

Nonce-based policy

The Next.js 14 Pages Router CSP guide shows the pattern. A nonce is generated in Middleware for each request, the CSP is set on the request that is passed to the framework and on the response, and the nonce is exposed to a Server Component or to next/script. The guide states the rule plainly: “Every time a page is viewed, a fresh nonce should be generated.” That requirement also means the pages involved must be dynamically rendered, because a statically generated page cannot receive a new nonce for each view.

Rank #4
Sale
TP-Link USB C to Ethernet Adapter (UE300C), Compact, Plug & Play
  • 𝐇𝐢𝐠𝐡-𝐒𝐩𝐞𝐞𝐝 𝐔𝐒𝐁-𝐂 𝐄𝐭𝐡𝐞𝐫𝐧𝐞𝐭 𝐀𝐝𝐚𝐩𝐭𝐞𝐫 - Instantly transform your laptop or tablet’s USB-C port into a reliable wired connection with a 10/100/1000 Mbps RJ45 Ethernet port. Perfect for replacing unstable Wi-Fi in situations that require uninterrupted connectivity, such as online meetings, gaming, and media streaming.
  • 𝐔𝐒𝐁-𝐂 𝟑.𝟎 𝐟𝐨𝐫 𝐅𝐚𝐬𝐭𝐞𝐫, 𝐌𝐨𝐫𝐞 𝐒𝐭𝐚𝐛𝐥𝐞 𝐂𝐨𝐧𝐧𝐞𝐜𝐭𝐢𝐨𝐧𝐬 - Experience full Gigabit Ethernet performance over your laptop’s USB-C 3.0 port and elevate your browsing experience to transfer files, play games, video chat, and stream HD videos seamlessly. (To reach 1Gbps, please use CAT6 or up Ethernet cables.)
  • 𝐔𝐥𝐭𝐫𝐚-𝐂𝐨𝐦𝐩𝐚𝐜𝐭 𝐚𝐧𝐝 𝐅𝐨𝐥𝐝𝐚𝐛𝐥𝐞 𝐃𝐞𝐬𝐢𝐠𝐧 - At just 2.8 x 1.0 x 0.6 inches, the UE300C slips easily into your laptop bag or pocket. The lightweight yet durable build makes it perfect for travel, remote work, or quick setup in conference rooms.
  • 𝐏𝐥𝐮𝐠 𝐚𝐧𝐝 𝐏𝐥𝐚𝐲- No driver required for Windows 11/10/8.1/8/7, macOS, Chrome OS, and Linux (Ubuntu). Simply connect and enjoy instant wired internet access without complicated setup.
  • 𝐁𝐫𝐨𝐚𝐝 𝐃𝐞𝐯𝐢𝐜𝐞 𝐂𝐨𝐦𝐩𝐚𝐭𝐢𝐛𝐢𝐥𝐢𝐭𝐲- Works seamlessly with most USB-C devices, including MacBook Pro/Air, iPad Pro, Dell XPS, Surface Laptop, Chromebook, and more—making it a versatile network upgrade for home, office, or on-the-go use.

When you use this approach, check these points:

  • The nonce in the Content-Security-Policy response header matches the nonce attribute on the rendered script elements for the same response.
  • The nonce is generated per request, not once at build time or per deployment.
  • The value is a random, unpredictable string. Next.js reports an error for nonces containing <, >, or &, and recommends a randomly generated UUID. Do not build nonces from user input or other untrusted data.
  • Any CDN or page cache is not serving an HTML response whose nonce no longer matches the header sent with it. A nonce is only useful for the single response it was generated for, so cached markup with an old nonce will be blocked.

The next/script component forwards additional DOM attributes such as nonce. Its loading strategies (beforeInteractive, afterInteractive, and lazyOnload) change when a script runs, not whether CSP allows it. The worker strategy is experimental and is not supported with the App Router. Changing a strategy will not fix a script that the policy blocks.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why a broad allowlist is the wrong first move

Adding 'unsafe-inline', 'unsafe-eval', https:, or a wildcard source can make the blank page go away, but it reduces the protection the header was added to provide. Use these only after you have identified the blocked resource and confirmed that a narrower change cannot work. The correct change is usually one of the following: add the specific origin of a required external script, add a correctly applied nonce or hash for a specific inline script, or remove a conflicting policy from one of the layers.

Best Value
Sale
uni USB C to Ethernet Adapter 1Gbps, Driver Free RJ45 to USB C for Laptop
  • 【1Gbps LAN to USB-C Adapter】Obtain stable connection speeds up to 1Gbps; downward compatible with 100Mbps/10Mbps networks. Our Type-C to LAN Gigabit Ethernet (RJ45) Network Adapter supports large downloads at maximum speeds without interruption. (To reach 1Gbps, make sure to use CAT6 & up Ethernet cables.)
  • 【Reliable & Endurance Connectivity】Designed specifically for plug-and-play connection between USB-C devices and wired network, provides gigabit ethernet connectivity even when wireless connectivity is Inconsistent or over extended.
  • 【Thoughtful Design】Compact and lightweight, with a user-friendly non-slip design for easier plugging and unplugging. Braided nylon cable for extra durability. Premium aluminum casing for better heat dissipation. High-quality USB-C connector provides snug connection with your devices for stable signal transfer. Design to make it easy to connect USB peripherals without blocking adjacent USB-C ports
  • 【Wide Compatibility】Compatible with iPhone 15/16 Pro/Max, MacBook Pro 16''/15” (2023/2022/2021/2020/2019/2018/2017), MacBook (2019/2018/2017), MacBook Air 13” (2022/2018), iPad Pro (2022/2020/2018); XPS 13/15/17; Surface Book 2; Google Pixelbook, Chromebook, Pixel, Pixel 2; Asus ZenBook. Compatible with Samsung S20/S10/S9/S8/S8+, Note 8/9, Galaxy Tablet Tab A 10.5, and many other USB-C laptops, tablets, and smartphones. (NOT compatible with Nintendo Switch.)
  • 【What You Get】 USB C to Ethernet Adapter 1 pack, An effortless 18-month 𝗐𝖺𝗋𝗋𝖺𝗇𝗍𝗒 and 24/7 professional customer service. If you have any questions, don't hesitate to get in touch with us, we solve most issues within 12 hours. Please rest assured we stand behind our products and customers.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Roll out the policy safely with report-only mode

Use Content-Security-Policy-Report-Only while you evaluate a policy. The browser reports violations without blocking the code, so you can see every resource the policy would stop before users see a blank page. The MDN CSP header reference documents this mode.

  1. Send the candidate policy as Content-Security-Policy-Report-Only and leave any enforced header out of the test.
  2. Load the main routes, then exercise the interactions that depend on JavaScript: navigation between pages, forms, client-side data loading, and any login or checkout flow.
  3. Review the console for violations on each route and note any blocked script that the page needs.
  4. Correct the policy for each legitimate blocked resource, using the narrowest source or a correctly matched nonce.
  5. Repeat until a full pass produces no violations for required resources, then switch the header name from Content-Security-Policy-Report-Only to Content-Security-Policy.
  6. After enforcement, load the same routes once more and check that the page becomes interactive.

Report-only results show what was blocked during your test session. They do not prove that every route and state will work under enforcement, so keep the test list broad.

When CSP is not the cause

If the console shows no violation for a required resource, or the page still fails after the policy is corrected, check the rendering path. The Next.js hydration error guide lists several causes of hydration errors, and each can produce a page that looks blank or stops responding:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Server and client render different output, for example because a value differs between the two environments.
  • Browser-only APIs such as window or localStorage are read during rendering.
  • Time-dependent values, such as the current time or random numbers, change between the server render and the client render.
  • Browser extensions modify the DOM before React hydrates it.
  • The CSS-in-JS setup does not produce the same styles on the server and client.
  • An edge or CDN layer modifies the HTML before it reaches the browser.

The edge or CDN case deserves a direct check. Compare the HTML your origin server returns with the HTML the browser receives. If a proxy inserts, removes, or rewrites script tags, or injects its own policy, the markup and the header can stop matching even when your application code is correct.

Version and documentation notes

The Pages Router CSP guide linked above is a versioned page. Its path includes /docs/14/, and it was last updated September 1, 2023. Its version history recommends Next.js 13.4.20 or later for proper nonce handling. Check the current documentation for the Next.js version your application actually installs before copying any example, because routing and middleware APIs have changed across releases. The current Next.js Scripts guide was updated February 27, 2026, and is the reference for next/script behavior in newer versions.

Quick Recap

Bestseller No. 1
Anker USB C to Ethernet Adapter, Portable 1 Gbps Network Hub
Anker USB C to Ethernet Adapter, Portable 1 Gbps Network Hub
The Anker Advantage: Join the 65 million+ powered by our leading technology.
$25.99
Bestseller No. 3
Amazon Basics Aluminum USB-C to RJ45 Gigabit Ethernet Adapter, Portable, Fast Network, Grey, 2.07 x 0.81 x 0.6 inches
Amazon Basics Aluminum USB-C to RJ45 Gigabit Ethernet Adapter, Portable, Fast Network, Grey, 2.07 x 0.81 x 0.6 inches
Adapter for converting a USB 3.1 Type-C port to a RJ45 Gigabit Ethernet port; Ready to use, right out of the box; no external power adapter needed
$23.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.