chore: CSP script nonces, deploy health check, dead-code cleanup
Add per-request CSP nonces (drop script unsafe-inline), post-deploy /api/health gate, bump next-auth to beta.32, and remove unused motion/cache/permission helpers. Co-authored-by: Cursor <[email protected]>
This commit is contained in:
1 parent
c46dadeda4
commit
9b47668fe9
20 files changed
+141
-358
No files matched your search
@@ -1,16 +1,4 @@
|
||||
import { NextResponse } from "next/server";
|
||||
import { ZodError, type z } from "zod";
|
||||
import { reportError } from "@/lib/report-error";
|
||||
|
||||
/** Throwable API error with HTTP status code */
|
||||
export class ApiError extends Error {
|
||||
status: number;
|
||||
constructor(message: string, status: number = 400) {
|
||||
super(message);
|
||||
this.name = "ApiError";
|
||||
this.status = status;
|
||||
}
|
||||
}
|
||||
|
||||
/** Standard success response: { ok: true, ...data } */
|
||||
export function apiOk(data?: Record<string, unknown>) {
|
||||
@@ -21,32 +9,3 @@ export function apiOk(data?: Record<string, unknown>) {
|
||||
export function apiError(message: string, status: number = 400) {
|
||||
return NextResponse.json({ error: message }, { status });
|
||||
}
|
||||
|
||||
/** Validation error from Zod: { error: fieldErrors } with 400 */
|
||||
export function apiValidationError(zodError: z.ZodError) {
|
||||
return NextResponse.json(
|
||||
{ error: zodError.flatten().fieldErrors },
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
|
||||
// TODO: Check of dit weg kan — niet geïmporteerd in de codebase
|
||||
export function handleApiError(error: unknown): Response {
|
||||
if (error instanceof ApiError) {
|
||||
return apiError(error.message, error.status);
|
||||
}
|
||||
if (error instanceof ZodError) {
|
||||
return apiValidationError(error);
|
||||
}
|
||||
// Prisma P2025 "Record not found"
|
||||
if (
|
||||
error instanceof Error &&
|
||||
(error.constructor.name === "PrismaClientKnownRequestError" ||
|
||||
error.name === "PrismaClientKnownRequestError") &&
|
||||
(error as Error & { code?: string }).code === "P2025"
|
||||
) {
|
||||
return apiError("Not found", 404);
|
||||
}
|
||||
reportError(error, "API error");
|
||||
return apiError("Internal server error", 500);
|
||||
}
|
||||
Reference in new issue
Block a user