Commit Graph
12 Commits
Author SHA1 Message Date
openhands 080dc34e23 fix: never cache HTML so deploys always serve current chunks
CI / check (push) Successful in 30s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m2s
Anonymous HTML was sent with 'public, max-age=60, s-maxage=300,
stale-while-revalidate=300'. After a rebuild the old chunk URLs (keyed by
deploy id) are deleted, so any browser/CDN holding the stale HTML got 404s
for up to five minutes. Since the deploy id is the git commit, the HTML must
be re-fetched after every deploy; only content-hashed static assets should
be cached. Return no-store for all HTML documents.
2026-08-03 18:39:41 +02:00
openhands cc02851be3 perf(html): fix Cache-Control on response headers (was on request)
CI / check (push) Successful in 32s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m21s
2026-08-01 18:41:08 +02:00
openhands 7c1f8d709e perf(html): replace proxyAuth with getToken to remove set-cookie; add Cache-Control per auth state
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m20s
2026-08-01 18:37:19 +02:00
SimoandCursor 9b47668fe9 chore: CSP script nonces, deploy health check, dead-code cleanup
Add per-request CSP nonces (drop script unsafe-inline), post-deploy /api/health gate, bump next-auth to beta.32, and remove unused motion/cache/permission helpers.

Co-authored-by: Cursor <[email protected]>
2026-07-21 20:27:08 +02:00
openhands df38dccbf1 style: format code biome
Local Build and Deploy / deploy (push) Failing after 46s
2026-07-13 21:57:41 +02:00
openhands e2fc7ea1a4 Complete security hardening: zero-migration foundation, edge headers, rate-limit atomics, body limits
Local Build and Deploy / deploy (push) Successful in 58s
- Make @/lib/safe-action re-export from foundation layer so all 13+
  existing server actions instantly get request tracing, rate limiting,
  and structured error handling without any code changes
- Add HSTS, CSP, X-Frame-Options, X-Content-Type-Options to edge proxy
  (src/proxy.ts) — ran at Cloudflare/Vercel edge for all non-asset routes
- Fix rate-limit.ts race condition: compute newCount before assignment
  to shrink the read-modify-write window; add memory-key prefix to
  avoid collisions with Redis keys
- Add request body size limit (10 MB default) to api-handler.ts with
  per-route override via maxBodyBytes option
- Remove unused imports and clean up backward-compat types
2026-07-13 12:09:43 +02:00
Simo cdf180ee3f fix: isolate proxy session decoding
Local Build and Deploy / deploy (push) Successful in 1m2s
2026-07-12 13:39:25 +02:00
Simo c4bf6488d0 fix: use canonical Auth.js session in proxy
Remote Build and Deploy / deploy (push) Successful in 43s
2026-07-11 22:55:26 +02:00
Simo cfa7998dd7 fix: detect deployed Auth.js session cookie
Remote Build and Deploy / deploy (push) Successful in 44s
2026-07-11 22:46:04 +02:00
Simo 02bbcba240 fix: decode production admin session cookie
Remote Build and Deploy / deploy (push) Successful in 47s
2026-07-11 22:42:19 +02:00
Simo 17264dfc06 fix: protect admin routes and ignore local docs 2026-07-11 21:35:37 +02:00
Simo 3e8fb794d9 Rename edge middleware.ts -> proxy.ts (Next 16 convention)
Next 16 deprecated the middleware file convention in favour of proxy.ts
with an exported `proxy` function. Same header-forwarding logic and
matcher; clears the build-time deprecation warning.
2026-06-28 16:07:42 +02:00