- Remove import.meta.dirname from turbopack config (unnecessary filesystem op) - Add /*turbopackIgnore: true*/ to 3 path.join calls in upload-import.ts that were missing the comment, causing Turbopack to trace the whole project unintentionally
97 lines
2.5 KiB
TypeScript
97 lines
2.5 KiB
TypeScript
import type { NextConfig } from "next";
|
|
import { withSentryConfig } from "@sentry/nextjs";
|
|
import createNextIntlPlugin from "next-intl/plugin";
|
|
import withBundleAnalyzer from "@next/bundle-analyzer";
|
|
|
|
const securityHeaders = [
|
|
{ key: "X-DNS-Prefetch-Control", value: "on" },
|
|
{
|
|
key: "Strict-Transport-Security",
|
|
value: "max-age=63072000; includeSubDomains; preload",
|
|
},
|
|
{ key: "X-Frame-Options", value: "DENY" },
|
|
{ key: "X-Content-Type-Options", value: "nosniff" },
|
|
{ key: "Referrer-Policy", value: "strict-origin-when-cross-origin" },
|
|
{
|
|
key: "Permissions-Policy",
|
|
value: "camera=(), microphone=(), geolocation=(), interest-cohort=()",
|
|
},
|
|
// CSP is set per-request in src/proxy.ts with a script nonce (no 'unsafe-inline' for scripts).
|
|
];
|
|
|
|
const nextConfig: NextConfig = {
|
|
turbopack: {},
|
|
serverExternalPackages: [
|
|
"@prisma/adapter-mariadb",
|
|
"mariadb",
|
|
"@prisma/client",
|
|
"lzma",
|
|
"sharp",
|
|
"pino",
|
|
"pino-pretty",
|
|
],
|
|
|
|
// Enable React Compiler for automatic memoization
|
|
reactCompiler: true,
|
|
|
|
// Compress responses with gzip
|
|
compress: true,
|
|
|
|
// Disable Next.js telemetry
|
|
productionBrowserSourceMaps: false,
|
|
output: "standalone",
|
|
|
|
// Add caching headers for static assets
|
|
async headers() {
|
|
return [
|
|
{
|
|
source: "/(.*)",
|
|
headers: securityHeaders,
|
|
},
|
|
{
|
|
source: "/assets/(.*)",
|
|
headers: [
|
|
{
|
|
key: "Cache-Control",
|
|
value: "public, max-age=31536000, immutable",
|
|
},
|
|
],
|
|
},
|
|
{
|
|
source: "/images/(.*)",
|
|
headers: [{ key: "Cache-Control", value: "public, max-age=86400" }],
|
|
},
|
|
];
|
|
},
|
|
};
|
|
|
|
// next-intl WITHOUT i18n routing — locale comes from the NEXT_LOCALE cookie via
|
|
// src/i18n/request.ts, so URLs and the access-guard middleware stay unchanged.
|
|
const withNextIntl = createNextIntlPlugin("./src/i18n/request.ts");
|
|
|
|
const config = withNextIntl(nextConfig);
|
|
|
|
// Source-map upload + release creation need SENTRY_AUTH_TOKEN.
|
|
// Without it, keep the SDK wrapper but skip remote Sentry build steps
|
|
// so CI/prod compile stays quiet (runtime DSN still works independently).
|
|
const sentryAuthToken = process.env.SENTRY_AUTH_TOKEN;
|
|
|
|
const withBA = withBundleAnalyzer({
|
|
enabled: process.env.ANALYZE === "true",
|
|
});
|
|
|
|
export default withBA(withSentryConfig(config, {
|
|
org: process.env.SENTRY_ORG,
|
|
project: process.env.SENTRY_PROJECT,
|
|
authToken: sentryAuthToken,
|
|
silent: !process.env.CI,
|
|
widenClientFileUpload: true,
|
|
sourcemaps: {
|
|
disable: !sentryAuthToken,
|
|
},
|
|
release: {
|
|
create: Boolean(sentryAuthToken),
|
|
},
|
|
telemetry: false,
|
|
}));
|