Fix login CSP and auth host trust
This commit is contained in:
1 parent
83d1483ecd
commit
c9d951aa86
2 files changed
+2
-2
No files matched your search
+1
-1
@@ -15,7 +15,7 @@ const securityHeaders = [
|
|||||||
key: "Content-Security-Policy",
|
key: "Content-Security-Policy",
|
||||||
value: [
|
value: [
|
||||||
"default-src 'self'",
|
"default-src 'self'",
|
||||||
"script-src 'self' https://challenges.cloudflare.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/",
|
"script-src 'self' 'unsafe-inline' https://challenges.cloudflare.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://static.cloudflareinsights.com",
|
||||||
"style-src 'self' 'unsafe-inline'",
|
"style-src 'self' 'unsafe-inline'",
|
||||||
"img-src 'self' data: blob: https:",
|
"img-src 'self' data: blob: https:",
|
||||||
"frame-src 'self' https://challenges.cloudflare.com https://www.google.com/recaptcha/",
|
"frame-src 'self' https://challenges.cloudflare.com https://www.google.com/recaptcha/",
|
||||||
|
|||||||
+1
-1
@@ -42,7 +42,7 @@ async function verify2faCode(userId: number, code: string): Promise<boolean> {
|
|||||||
}
|
}
|
||||||
|
|
||||||
export const { handlers, signIn, signOut, auth } = NextAuth({
|
export const { handlers, signIn, signOut, auth } = NextAuth({
|
||||||
trustHost: process.env.NODE_ENV === "development",
|
trustHost: true,
|
||||||
session: { strategy: "jwt", maxAge: 24 * 60 * 60 },
|
session: { strategy: "jwt", maxAge: 24 * 60 * 60 },
|
||||||
pages: { signIn: "/login" },
|
pages: { signIn: "/login" },
|
||||||
providers: [
|
providers: [
|
||||||
|
|||||||
Reference in new issue
Block a user