Compare two requests, not two screenshots
Keep the synthetic source image URL and the failing application image request separate. A source URL opening in a logged-in browser does not show that the server-side optimizer can retrieve it. Record the optimizer status, configured remote pattern and framework version without copying signed URL tokens.
- Check protocol, hostname, port, pathname and query restrictions against the intended source.
- Check whether the source needs browser cookies or another authentication header.
- Record whether the failure is a rejected URL, failed source fetch or layout problem.
Keep the permission narrow
The official Image reference allows precise remotePatterns and warns that the default loader does not forward authentication headers. Adjusting an approved host/path pattern and designing authenticated private-image delivery are different tasks. Do not expand to a wildcard host or make a private bucket public merely to obtain a rendered picture.
- A signed image URL can be a bearer credential: use invented or disposable test assets.
- Choosing unoptimized changes the delivery and optimization path; it does not authorise access to private content.
- Check the installed version before copying current configuration syntax.
- A narrow initial pattern is not the whole fetch boundary: the current reference says redirects from an allowed source are not checked against remotePatterns again. Inspect the final redirect destination and the installed version's supported redirect policy.
A useful synthetic regression
Propose one allowed synthetic host/path that must render, one directly requested unapproved host/path that must be rejected and one allowed synthetic URL redirecting to a test destination. Assert the redirect case against the installed version's agreed redirect policy rather than assuming the unapproved destination is always blocked. Test the original page at the agreed sizes and retain the network outcome as well as a screenshot. If the request needs authentication, settle the access design separately before implementation. No image repair or browser check has been executed for this candidate.
- Keep expected aspect ratio and dimensions explicit.
- Check that a failed image does not remove its useful alternative text.
Non-fit, safety and priced route
An ordinary deterministic configuration defect that can be reproduced with public synthetic images may fit fix-one-bug-with-regression-test, from £295 after bounded reproduction and a fixed quote. A new private-image feature involving personal/profile data or changes to personal-data access handling requires a separate security review and separately agreed scope; synthetic assets do not remove that exclusion. Only a qualifying feature that changes neither payment nor personal-data handling may fit ship-one-feature-with-running-preview, from £750, with agreed criteria, a fixed quote, an existing isolated, private, access-controlled and time-limited preview route, and two revision rounds. Payment for that work follows passing checks and the buyer's sign-off. An apparent cross-account disclosure or remote-fetch abuse requires the customer's security process, not the routine bug offer.
- Send framework version, redacted status and the expected image behaviour, not source code, private URLs or credentials.
- The prices are proposed and untested; account access and live publication remain separately controlled.
Sources and limits
- Next.js: Image component; MIT-licensed project documentation Checked 2026-10-11.
- remotePatterns restrict remote image sources by URL components.
- The default optimization loader does not forward authentication headers to the source image.
- unoptimized serves the source image without the normal optimization path.
- Redirects from an allowed remote source are followed without revalidating remotePatterns at the redirect destination.
- Current documentation says the default loader follows up to three redirects and maximumRedirects can reduce or disable them; installed versions can differ.
- Current reproducible-bug offer Checked 2026-10-11.