Files
EpicNext-Cms/src/proxy.ts
T
Simo 8abfe352ef
CI / check (push) Successful in 3m15s
CI / deploy (push) Successful in 1m19s
CI / publish-container (push) Successful in 48s
fix(security): authorize site uploads and harden tokens, media and request identity
2026-09-13 19:24:43 +02:00

59 lines
1.9 KiB
TypeScript

import { NextResponse } from "next/server";
import { getToken } from "next-auth/jwt";
import { env } from "@/env";
import { buildContentSecurityPolicy, createCspNonce } from "@/lib/csp";
import { shouldRedirectAdminRequest } from "@/lib/proxy-access";
const SECURITY_HEADERS: Record<string, string> = {
"X-Content-Type-Options": "nosniff",
"X-Frame-Options": "DENY",
"X-XSS-Protection": "0",
"Referrer-Policy": "strict-origin-when-cross-origin",
"Permissions-Policy": "camera=(), microphone=(), geolocation=()",
"Strict-Transport-Security": "max-age=63072000; includeSubDomains; preload",
};
export const proxy = async (req: import("next/server").NextRequest) => {
const token = await getToken({
req,
secret: env.AUTH_SECRET,
secureCookie: true,
});
if (shouldRedirectAdminRequest(req.nextUrl.pathname, token)) {
return NextResponse.redirect(new URL("/login", req.url));
}
const nonce = createCspNonce();
const csp = buildContentSecurityPolicy(nonce);
const headers = new Headers(req.headers);
headers.set("x-pathname", req.nextUrl.pathname);
headers.set("x-nonce", nonce);
// A client may supply this legacy derived header; no consumer should trust it.
headers.delete("x-real-client-ip");
const response = NextResponse.next({ request: { headers } });
// HTML is never cached (browser/CDN/edge) so that after a deploy the page
// always references the current build's chunks. Static assets are
// content-hashed + immutable and can be cached aggressively; a stale HTML
// document would reference chunk URLs that no longer exist after a rebuild.
response.headers.set(
"Cache-Control",
"private, no-cache, no-store, max-age=0, must-revalidate",
);
for (const [key, value] of Object.entries(SECURITY_HEADERS)) {
response.headers.set(key, value);
}
response.headers.set("Content-Security-Policy", csp);
return response;
};
export const config = {
matcher: ["/((?!api|_next/static|_next/image|assets|favicon.ico).*)"],
};