chore: CSP script nonces, deploy health check, dead-code cleanup

Add per-request CSP nonces (drop script unsafe-inline), post-deploy /api/health gate, bump next-auth to beta.32, and remove unused motion/cache/permission helpers.

Co-authored-by: Cursor <[email protected]>
This commit is contained in:
SimoandCursor committed 2026-07-21 20:27:08 +02:00
1 parent c46dadeda4
commit 9b47668fe9
20 files changed
+141 -358

No files matched your search

+12
View File
@@ -62,4 +62,16 @@ describe("production deploy workflow", () => {
'export NEXT_PUBLIC_APP_VERSION="$' + "{APP_VERSION}\"",
);
});
it("runs an HTTP health check before declaring deploy success", () => {
expect(workflow).toContain("/api/health");
expect(workflow).toContain('"database":true');
const deployJob = workflow.slice(workflow.indexOf("\n deploy:"));
const startAt = deployJob.indexOf("systemctl start atom-nexst.service");
const healthAt = deployJob.indexOf("/api/health");
const successAt = deployJob.indexOf("--- Deployed successfully ---");
expect(startAt).toBeGreaterThan(-1);
expect(healthAt).toBeGreaterThan(startAt);
expect(successAt).toBeGreaterThan(healthAt);
});
});