Fix login CSP and auth host trust
This commit is contained in:
1 parent
83d1483ecd
commit
c9d951aa86
2 files changed
+2
-2
No files matched your search
+1
-1
@@ -15,7 +15,7 @@ const securityHeaders = [
|
||||
key: "Content-Security-Policy",
|
||||
value: [
|
||||
"default-src 'self'",
|
||||
"script-src 'self' https://challenges.cloudflare.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/",
|
||||
"script-src 'self' 'unsafe-inline' https://challenges.cloudflare.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://static.cloudflareinsights.com",
|
||||
"style-src 'self' 'unsafe-inline'",
|
||||
"img-src 'self' data: blob: https:",
|
||||
"frame-src 'self' https://challenges.cloudflare.com https://www.google.com/recaptcha/",
|
||||
|
||||
+1
-1
@@ -42,7 +42,7 @@ async function verify2faCode(userId: number, code: string): Promise<boolean> {
|
||||
}
|
||||
|
||||
export const { handlers, signIn, signOut, auth } = NextAuth({
|
||||
trustHost: process.env.NODE_ENV === "development",
|
||||
trustHost: true,
|
||||
session: { strategy: "jwt", maxAge: 24 * 60 * 60 },
|
||||
pages: { signIn: "/login" },
|
||||
providers: [
|
||||
|
||||
Reference in new issue
Block a user