chore: remove standalone output mode, fix Sentry DSN validation, add dev CSP unsafe-inline for styles
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m15s

- Remove output: 'standalone' from next.config.ts to allow normal 'next start'
- Allow empty SENTRY_DSN/NEXT_PUBLIC_SENTRY_DSN in env validation (zod)
- Add 'unsafe-inline' to style-src CSP only in development for Turbopack HMR
- Clear placeholder Sentry DSN values from .env
This commit is contained in:
openhands committed 2026-08-01 21:30:51 +02:00
1 parent ff1fa319a5
commit 0d6032d444
4 files changed
+5 -5

No files matched your search

-3
View File
@@ -32,9 +32,6 @@ const nextConfig: NextConfig = {
// Disable Next.js telemetry and browser sourcemaps in production // Disable Next.js telemetry and browser sourcemaps in production
productionBrowserSourceMaps: false, productionBrowserSourceMaps: false,
// Standalone output for smaller, faster Docker deployments and cold starts
output: "standalone",
experimental: { experimental: {
useTypeScriptCli: true, useTypeScriptCli: true,
}, },
+2
View File
@@ -15,6 +15,8 @@ if (dsn) {
"AbortError", "AbortError",
"NEXT_REDIRECT", "NEXT_REDIRECT",
"NEXT_NOT_FOUND", "NEXT_NOT_FOUND",
"UnrecognizedActionError",
"Server Action.*was not found on the server",
], ],
beforeSend: redactSentryEvent, beforeSend: redactSentryEvent,
}); });
+2 -2
View File
@@ -92,8 +92,8 @@ const schema = z
// Logging level. // Logging level.
LOG_LEVEL: z.enum(["debug", "info", "warn", "error"]).optional(), LOG_LEVEL: z.enum(["debug", "info", "warn", "error"]).optional(),
// Optional Sentry — no-op when unset. // Optional Sentry — no-op when unset.
SENTRY_DSN: z.string().url().optional(), SENTRY_DSN: z.string().url().optional().or(z.literal("")),
NEXT_PUBLIC_SENTRY_DSN: z.string().url().optional(), NEXT_PUBLIC_SENTRY_DSN: z.string().url().optional().or(z.literal("")),
SENTRY_ORG: z.string().optional(), SENTRY_ORG: z.string().optional(),
SENTRY_PROJECT: z.string().optional(), SENTRY_PROJECT: z.string().optional(),
SENTRY_AUTH_TOKEN: z.string().optional(), SENTRY_AUTH_TOKEN: z.string().optional(),
+1
View File
@@ -20,6 +20,7 @@ export function buildContentSecurityPolicy(nonce: string): string {
"'self'", "'self'",
`'nonce-${nonce}'`, `'nonce-${nonce}'`,
"https://fonts.googleapis.com", "https://fonts.googleapis.com",
...(isDev ? ["'unsafe-inline'"] : []),
].join(" "); ].join(" ");
return [ return [