Files
EpicNext-Cms/next.config.ts
T
openhands 0d6032d444
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m15s
chore: remove standalone output mode, fix Sentry DSN validation, add dev CSP unsafe-inline for styles
- Remove output: 'standalone' from next.config.ts to allow normal 'next start'
- Allow empty SENTRY_DSN/NEXT_PUBLIC_SENTRY_DSN in env validation (zod)
- Add 'unsafe-inline' to style-src CSP only in development for Turbopack HMR
- Clear placeholder Sentry DSN values from .env
2026-08-01 21:30:51 +02:00

94 lines
2.5 KiB
TypeScript

import withBundleAnalyzer from "@next/bundle-analyzer";
import { withSentryConfig } from "@sentry/nextjs";
import type { NextConfig } from "next";
import createNextIntlPlugin from "next-intl/plugin";
const securityHeaders = [
{ key: "X-DNS-Prefetch-Control", value: "on" },
{
key: "Strict-Transport-Security",
value: "max-age=63072000; includeSubDomains; preload",
},
{ key: "X-Frame-Options", value: "DENY" },
{ key: "X-Content-Type-Options", value: "nosniff" },
{ key: "Referrer-Policy", value: "strict-origin-when-cross-origin" },
{
key: "Permissions-Policy",
value: "camera=(), microphone=(), geolocation=(), interest-cohort=()",
},
// CSP is set per-request in src/proxy.ts with a script nonce (no 'unsafe-inline' for scripts).
];
const nextConfig: NextConfig = {
turbopack: {},
serverExternalPackages: ["mariadb", "lzma", "sharp", "pino", "pino-pretty"],
// Enable React Compiler for automatic memoization
reactCompiler: true,
// Compress responses with gzip/brotli
compress: true,
// Disable Next.js telemetry and browser sourcemaps in production
productionBrowserSourceMaps: false,
experimental: {
useTypeScriptCli: true,
},
// Add caching headers for static assets
async headers() {
return [
{
source: "/(.*)",
headers: securityHeaders,
},
{
source: "/assets/(.*)",
headers: [
{
key: "Cache-Control",
value: "public, max-age=31536000, immutable",
},
],
},
{
source: "/images/(.*)",
headers: [{ key: "Cache-Control", value: "public, max-age=86400" }],
},
];
},
};
// next-intl WITHOUT i18n routing — locale comes from the NEXT_LOCALE cookie via
// src/i18n/request.ts, so URLs and the access-guard middleware stay unchanged.
const withNextIntl = createNextIntlPlugin("./src/i18n/request.ts");
const config = withNextIntl(nextConfig);
// Source-map upload + release creation need SENTRY_AUTH_TOKEN.
// Without it, keep the SDK wrapper but skip remote Sentry build steps
// so CI/prod compile stays quiet (runtime DSN still works independently).
const sentryAuthToken = process.env.SENTRY_AUTH_TOKEN;
const withBA = withBundleAnalyzer({
enabled: process.env.ANALYZE === "true",
});
export default withBA(
withSentryConfig(config, {
org: process.env.SENTRY_ORG,
project: process.env.SENTRY_PROJECT,
authToken: sentryAuthToken,
silent: !process.env.CI || !sentryAuthToken,
widenClientFileUpload: true,
sourcemaps: {
disable: !sentryAuthToken,
},
release: {
create: Boolean(sentryAuthToken),
},
telemetry: false,
}),
);