Commit Graph
9 Commits
Author SHA1 Message Date
SimoandCursor 9b47668fe9 chore: CSP script nonces, deploy health check, dead-code cleanup
Add per-request CSP nonces (drop script unsafe-inline), post-deploy /api/health gate, bump next-auth to beta.32, and remove unused motion/cache/permission helpers.

Co-authored-by: Cursor <[email protected]>
2026-07-21 20:27:08 +02:00
openhands df38dccbf1 style: format code biome
Local Build and Deploy / deploy (push) Failing after 46s
2026-07-13 21:57:41 +02:00
openhands e2fc7ea1a4 Complete security hardening: zero-migration foundation, edge headers, rate-limit atomics, body limits
Local Build and Deploy / deploy (push) Successful in 58s
- Make @/lib/safe-action re-export from foundation layer so all 13+
  existing server actions instantly get request tracing, rate limiting,
  and structured error handling without any code changes
- Add HSTS, CSP, X-Frame-Options, X-Content-Type-Options to edge proxy
  (src/proxy.ts) — ran at Cloudflare/Vercel edge for all non-asset routes
- Fix rate-limit.ts race condition: compute newCount before assignment
  to shrink the read-modify-write window; add memory-key prefix to
  avoid collisions with Redis keys
- Add request body size limit (10 MB default) to api-handler.ts with
  per-route override via maxBodyBytes option
- Remove unused imports and clean up backward-compat types
2026-07-13 12:09:43 +02:00
Simo cdf180ee3f fix: isolate proxy session decoding
Local Build and Deploy / deploy (push) Successful in 1m2s
2026-07-12 13:39:25 +02:00
Simo c4bf6488d0 fix: use canonical Auth.js session in proxy
Remote Build and Deploy / deploy (push) Successful in 43s
2026-07-11 22:55:26 +02:00
Simo cfa7998dd7 fix: detect deployed Auth.js session cookie
Remote Build and Deploy / deploy (push) Successful in 44s
2026-07-11 22:46:04 +02:00
Simo 02bbcba240 fix: decode production admin session cookie
Remote Build and Deploy / deploy (push) Successful in 47s
2026-07-11 22:42:19 +02:00
Simo 17264dfc06 fix: protect admin routes and ignore local docs 2026-07-11 21:35:37 +02:00
Simo 3e8fb794d9 Rename edge middleware.ts -> proxy.ts (Next 16 convention)
Next 16 deprecated the middleware file convention in favour of proxy.ts
with an exported `proxy` function. Same header-forwarding logic and
matcher; clears the build-time deprecation warning.
2026-06-28 16:07:42 +02:00