Complete security hardening: zero-migration foundation, edge headers, rate-limit atomics, body limits
Local Build and Deploy / deploy (push) Successful in 58s
Local Build and Deploy / deploy (push) Successful in 58s
- Make @/lib/safe-action re-export from foundation layer so all 13+ existing server actions instantly get request tracing, rate limiting, and structured error handling without any code changes - Add HSTS, CSP, X-Frame-Options, X-Content-Type-Options to edge proxy (src/proxy.ts) — ran at Cloudflare/Vercel edge for all non-asset routes - Fix rate-limit.ts race condition: compute newCount before assignment to shrink the read-modify-write window; add memory-key prefix to avoid collisions with Redis keys - Add request body size limit (10 MB default) to api-handler.ts with per-route override via maxBodyBytes option - Remove unused imports and clean up backward-compat types
This commit is contained in:
1 parent
f6ad030c5b
commit
e2fc7ea1a4
6 files changed
+55
-178
No files matched your search
+18
-5
@@ -2,10 +2,15 @@ import { NextResponse } from "next/server";
|
||||
import { proxyAuth } from "@/lib/proxy-auth";
|
||||
import { shouldRedirectAdminRequest } from "@/lib/proxy-access";
|
||||
|
||||
// Edge proxy (formerly "middleware"): Prisma can't run here, so we only forward
|
||||
// the request path (so server components / the access guard can read it via
|
||||
// headers()) and normalize the real client IP. The DB-backed banned/maintenance
|
||||
// checks happen in src/lib/access-guard.ts (Node runtime) from the root layout.
|
||||
const SECURITY_HEADERS: Record<string, string> = {
|
||||
"X-Content-Type-Options": "nosniff",
|
||||
"X-Frame-Options": "DENY",
|
||||
"X-XSS-Protection": "0",
|
||||
"Referrer-Policy": "strict-origin-when-cross-origin",
|
||||
"Permissions-Policy": "camera=(), microphone=(), geolocation=()",
|
||||
"Strict-Transport-Security": "max-age=63072000; includeSubDomains; preload",
|
||||
};
|
||||
|
||||
export const proxy = proxyAuth((req) => {
|
||||
if (shouldRedirectAdminRequest(req.nextUrl.pathname, req.auth?.user ?? null)) {
|
||||
return NextResponse.redirect(new URL("/login", req.url));
|
||||
@@ -13,13 +18,21 @@ export const proxy = proxyAuth((req) => {
|
||||
|
||||
const headers = new Headers(req.headers);
|
||||
headers.set("x-pathname", req.nextUrl.pathname);
|
||||
|
||||
const ip =
|
||||
req.headers.get("cf-connecting-ip") ??
|
||||
req.headers.get("x-forwarded-for")?.split(",")[0]?.trim() ??
|
||||
req.headers.get("x-real-ip") ??
|
||||
"";
|
||||
if (ip) headers.set("x-real-client-ip", ip);
|
||||
return NextResponse.next({ request: { headers } });
|
||||
|
||||
const response = NextResponse.next({ request: { headers } });
|
||||
|
||||
for (const [key, value] of Object.entries(SECURITY_HEADERS)) {
|
||||
response.headers.set(key, value);
|
||||
}
|
||||
|
||||
return response;
|
||||
});
|
||||
|
||||
export const config = {
|
||||
|
||||
Reference in new issue
Block a user