Fix login CSP and auth host trust

This commit is contained in:
openhands committed 2026-07-04 20:04:44 +02:00
1 parent 83d1483ecd
commit c9d951aa86
2 files changed
+2 -2

No files matched your search

+1 -1
View File
@@ -15,7 +15,7 @@ const securityHeaders = [
key: "Content-Security-Policy",
value: [
"default-src 'self'",
"script-src 'self' https://challenges.cloudflare.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/",
"script-src 'self' 'unsafe-inline' https://challenges.cloudflare.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://static.cloudflareinsights.com",
"style-src 'self' 'unsafe-inline'",
"img-src 'self' data: blob: https:",
"frame-src 'self' https://challenges.cloudflare.com https://www.google.com/recaptcha/",
+1 -1
View File
@@ -42,7 +42,7 @@ async function verify2faCode(userId: number, code: string): Promise<boolean> {
}
export const { handlers, signIn, signOut, auth } = NextAuth({
trustHost: process.env.NODE_ENV === "development",
trustHost: true,
session: { strategy: "jwt", maxAge: 24 * 60 * 60 },
pages: { signIn: "/login" },
providers: [