chore: patch deps, CSP style nonces, otplib 13, and PR CI
Co-authored-by: Cursor <[email protected]>
This commit is contained in:
1 parent
87bda8dbef
commit
2ff08e5127
11 files changed
+239
-160
No files matched your search
+11
-5
@@ -1,8 +1,7 @@
|
||||
/**
|
||||
* Build a Content-Security-Policy value.
|
||||
* Scripts: nonce for Next.js / first-party inline; host allowlists for captcha,
|
||||
* Cloudflare Insights, and TinyMCE CDN. style-src keeps 'unsafe-inline' for
|
||||
* theme CSS variables (ThemeVars) — nonce styles are a follow-up.
|
||||
* Scripts/styles: per-request nonce for Next.js and ThemeVars inline tags.
|
||||
* style-src-attr keeps 'unsafe-inline' so React `style={{…}}` attributes work.
|
||||
*/
|
||||
export function buildContentSecurityPolicy(nonce: string): string {
|
||||
const isDev = process.env.NODE_ENV === "development";
|
||||
@@ -17,14 +16,21 @@ export function buildContentSecurityPolicy(nonce: string): string {
|
||||
...(isDev ? ["'unsafe-eval'"] : []),
|
||||
].join(" ");
|
||||
|
||||
const styleSrc = [
|
||||
"'self'",
|
||||
`'nonce-${nonce}'`,
|
||||
"https://fonts.googleapis.com",
|
||||
].join(" ");
|
||||
|
||||
return [
|
||||
"default-src 'self'",
|
||||
`script-src ${scriptSrc}`,
|
||||
"style-src 'self' 'unsafe-inline'",
|
||||
`style-src ${styleSrc}`,
|
||||
"style-src-attr 'unsafe-inline'",
|
||||
"img-src 'self' data: blob: https:",
|
||||
"frame-src 'self' https://challenges.cloudflare.com https://www.google.com/recaptcha/",
|
||||
"connect-src 'self' https: wss:",
|
||||
"font-src 'self' data:",
|
||||
"font-src 'self' data: https://fonts.gstatic.com",
|
||||
"object-src 'none'",
|
||||
"base-uri 'self'",
|
||||
"form-action 'self'",
|
||||
|
||||
Reference in new issue
Block a user