chore: CSP script nonces, deploy health check, dead-code cleanup

Add per-request CSP nonces (drop script unsafe-inline), post-deploy /api/health gate, bump next-auth to beta.32, and remove unused motion/cache/permission helpers.

Co-authored-by: Cursor <[email protected]>
This commit is contained in:
SimoandCursor committed 2026-07-21 20:27:08 +02:00
1 parent c46dadeda4
commit 9b47668fe9
20 files changed
+141 -358

No files matched your search

+6
View File
@@ -1,4 +1,5 @@
import { NextResponse } from "next/server";
import { buildContentSecurityPolicy, createCspNonce } from "@/lib/csp";
import { shouldRedirectAdminRequest } from "@/lib/proxy-access";
import { proxyAuth } from "@/lib/proxy-auth";
@@ -18,8 +19,12 @@ export const proxy = proxyAuth((req) => {
return NextResponse.redirect(new URL("/login", req.url));
}
const nonce = createCspNonce();
const csp = buildContentSecurityPolicy(nonce);
const headers = new Headers(req.headers);
headers.set("x-pathname", req.nextUrl.pathname);
headers.set("x-nonce", nonce);
const ip =
req.headers.get("cf-connecting-ip") ??
@@ -33,6 +38,7 @@ export const proxy = proxyAuth((req) => {
for (const [key, value] of Object.entries(SECURITY_HEADERS)) {
response.headers.set(key, value);
}
response.headers.set("Content-Security-Policy", csp);
return response;
});