chore: CSP script nonces, deploy health check, dead-code cleanup
Add per-request CSP nonces (drop script unsafe-inline), post-deploy /api/health gate, bump next-auth to beta.32, and remove unused motion/cache/permission helpers. Co-authored-by: Cursor <[email protected]>
This commit is contained in:
1 parent
c46dadeda4
commit
9b47668fe9
20 files changed
+141
-358
No files matched your search
@@ -1,4 +1,5 @@
|
||||
import { NextResponse } from "next/server";
|
||||
import { buildContentSecurityPolicy, createCspNonce } from "@/lib/csp";
|
||||
import { shouldRedirectAdminRequest } from "@/lib/proxy-access";
|
||||
import { proxyAuth } from "@/lib/proxy-auth";
|
||||
|
||||
@@ -18,8 +19,12 @@ export const proxy = proxyAuth((req) => {
|
||||
return NextResponse.redirect(new URL("/login", req.url));
|
||||
}
|
||||
|
||||
const nonce = createCspNonce();
|
||||
const csp = buildContentSecurityPolicy(nonce);
|
||||
|
||||
const headers = new Headers(req.headers);
|
||||
headers.set("x-pathname", req.nextUrl.pathname);
|
||||
headers.set("x-nonce", nonce);
|
||||
|
||||
const ip =
|
||||
req.headers.get("cf-connecting-ip") ??
|
||||
@@ -33,6 +38,7 @@ export const proxy = proxyAuth((req) => {
|
||||
for (const [key, value] of Object.entries(SECURITY_HEADERS)) {
|
||||
response.headers.set(key, value);
|
||||
}
|
||||
response.headers.set("Content-Security-Policy", csp);
|
||||
|
||||
return response;
|
||||
});
|
||||
|
||||
Reference in new issue
Block a user