fix: prevent duplicate iframes on CldUploadWidget unmount/remount - #658
Merged
Merged
Conversation
When CldUploadWidget unmounts and remounts, next/script's onLoad fires again. The triggerOnIdle callback had no guard against the component unmounting before the idle callback fired, allowing a zombie widget to be created with an orphaned iframe. Add an isMounted ref that gates both handleOnLoad and the idle callback. Set isMounted=true on mount; false + destroy on cleanup, in that order. Closes #587. Supersedes #588.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Collaborator
Author
|
supersedes #588 |
12 tasks
eportis-cloudinary
added a commit
that referenced
this pull request
Sep 25, 2026
Brings 146 commits from main onto the v7 branch, including Next.js 16 compatibility (#657), the Node 20/22 CI matrix (#656), the Trusted Publishers release plumbing, and three recent fixes: duplicate iframes on CldUploadWidget unmount (#658), open() called before the widget script loads (#659), and the docs Table component (#661). Conflicts resolved as follows: - CldVideoPlayer.tsx: union. Kept beta's 'use client' and named-only react import, added main's useState, which the merged body needs for isScriptLoaded/playerInitialized. - next-cloudinary/package.json: kept beta's preconstruct build config, exports map, files and 7.0.0-beta.11 version; adopted the repository field main added in 554e2a0. - package.json: kept @preconstruct/cli (beta's build needs it); dropped @colbyfayock/semantic-release-pnpm, which the merged .releaserc no longer references; took main's semantic-release 25 and @semantic-release/npm 13. - pnpm-workspace.yaml: beta's list, which adds the test app - required because beta's test:app builds it via pnpm rather than npm install. - tests/nextjs-app/package.json: main's Next 16 / React 19 versions plus beta's next-cloudinary workspace link. - CHANGELOG.md: kept both release histories. - pnpm-lock.yaml: regenerated against the merged manifests. Also fixes CldUploadWidget.tsx, which git auto-merged without conflicting but produced broken output: beta had dropped the default React import while main's useUploadWidgetId helper calls React.useId and React.useRef. The combination built fine and failed at prerender with "ReferenceError: React is not defined". Restored the default import. Caught by test:app, not by the unit tests. Note: .releaserc auto-merged to main's @semantic-release/npm, which drops beta's publishBranch "main|beta" setting. Branch gating now comes from the top-level branches config alone.
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
When
CldUploadWidgetunmounts and remounts,next/script'sonLoadcallback fires again (the script is already cached in the browser, but the callback re-registers on remount). The existingtriggerOnIdlecallback had no guard against the component unmounting before the idle callback fired, thus allowing a zombie widget instance to be created with an orphaned iframe in the DOM.Root cause:
triggerOnIdledefers widget creation asynchronously viarequestIdleCallback. If the component unmounts during that window, the cleanup runs (widget.current = undefined), but the pending idle callback still fires, passes the!widget.currentcheck, and creates a new widget on an unmounted component.Fix: Add an
isMountedref that gates both thehandleOnLoadentry point and the async idle callback. The single cleanupuseEffectsetsisMounted.current = falsebefore callingwidget.current?.destroy(), ensuring no in-flight callbacks can recreate the widget after cleanup.A manual test page has been added at
tests/nextjs-app/app/test-widget/page.tsxto verify the fix via unmount/remount cycling in the browser.Issue Ticket Number
Fixes #587. Supersedes #588.
Type of change
Checklist