chore: CSP script nonces, deploy health check, dead-code cleanup

Add per-request CSP nonces (drop script unsafe-inline), post-deploy /api/health gate, bump next-auth to beta.32, and remove unused motion/cache/permission helpers.

Co-authored-by: Cursor <[email protected]>
This commit is contained in:
SimoandCursor committed 2026-07-21 20:27:08 +02:00
1 parent c46dadeda4
commit 9b47668fe9
20 files changed
+141 -358

No files matched your search

+24 -1
View File
@@ -2,6 +2,7 @@
import Image from "next/image";
import Link from "next/link";
import Script from "next/script";
import { useTranslations } from "next-intl";
import { useActionState, useState } from "react";
import { register } from "@/actions/register";
@@ -10,9 +11,15 @@ interface RegisterFormProps {
hotelName: string;
captcha: { provider: string; siteKey?: string };
error?: string;
nonce?: string;
}
export function RegisterForm({ hotelName, captcha, error }: RegisterFormProps) {
export function RegisterForm({
hotelName,
captcha,
error,
nonce,
}: RegisterFormProps) {
const t = useTranslations("pages.register");
const showCaptcha = captcha.provider !== "none" && !!captcha.siteKey;
const [serverError, formAction, isPending] = useActionState(register, null);
@@ -20,6 +27,22 @@ export function RegisterForm({ hotelName, captcha, error }: RegisterFormProps) {
return (
<div className="mx-auto w-full max-w-[800px]">
{showCaptcha && captcha.provider === "turnstile" ? (
<Script
src="https://challenges.cloudflare.com/turnstile/v0/api.js"
async
defer
nonce={nonce}
/>
) : null}
{showCaptcha && captcha.provider === "recaptcha" ? (
<Script
src="https://www.google.com/recaptcha/api.js"
async
defer
nonce={nonce}
/>
) : null}
{/* Header Banner */}
<div
className="relative overflow-hidden bg-center bg-cover rounded-t-lg"
-31
View File
@@ -22,34 +22,3 @@ export function Reveal({ children, className, delay = 0 }: RevealProps) {
</motion.div>
);
}
export function RevealStagger({ children, className }: RevealProps) {
return (
<motion.div
className={className}
initial="hidden"
whileInView="visible"
viewport={{ once: true, margin: "-50px" }}
variants={{
hidden: {},
visible: { transition: { staggerChildren: 0.08, delayChildren: 0.05 } },
}}
>
{children}
</motion.div>
);
}
export function RevealItem({ children, className }: RevealProps) {
return (
<motion.div
className={className}
variants={{
hidden: { opacity: 0, y: 20 },
visible: { opacity: 1, y: 0, transition: { duration: 0.35 } },
}}
>
{children}
</motion.div>
);
}