Add per-request CSP nonces (drop script unsafe-inline), post-deploy /api/health gate, bump next-auth to beta.32, and remove unused motion/cache/permission helpers. Co-authored-by: Cursor <[email protected]>
43 lines
1.0 KiB
TypeScript
43 lines
1.0 KiB
TypeScript
import "server-only";
|
|
|
|
import Redis from "ioredis";
|
|
|
|
const globalForRedis = globalThis as unknown as {
|
|
redis?: Redis | null;
|
|
redisMissingWarned?: boolean;
|
|
};
|
|
|
|
function createRedis(): Redis | null {
|
|
const url = process.env.REDIS_URL;
|
|
if (!url) {
|
|
if (
|
|
process.env.NODE_ENV === "production" &&
|
|
!globalForRedis.redisMissingWarned
|
|
) {
|
|
globalForRedis.redisMissingWarned = true;
|
|
console.error(
|
|
"[redis] REDIS_URL is unset in production. Rate limits and shared caches fall back to in-process memory and will not work correctly across multiple instances.",
|
|
);
|
|
}
|
|
return null;
|
|
}
|
|
try {
|
|
const client = new Redis(url, {
|
|
maxRetriesPerRequest: 3,
|
|
retryStrategy(times) {
|
|
if (times > 3) return null;
|
|
return Math.min(times * 200, 2000);
|
|
},
|
|
lazyConnect: true,
|
|
});
|
|
client.on("error", () => {});
|
|
return client;
|
|
} catch {
|
|
return null;
|
|
}
|
|
}
|
|
|
|
export const redis: Redis | null =
|
|
globalForRedis.redis !== undefined ? globalForRedis.redis : createRedis();
|
|
if (globalForRedis.redis === undefined) globalForRedis.redis = redis;
|