Files
Epicnabbo-Catalogus-Updated…/src/proxy.ts
T
openhands e2fc7ea1a4 Complete security hardening: zero-migration foundation, edge headers, rate-limit atomics, body limits
- Make @/lib/safe-action re-export from foundation layer so all 13+
  existing server actions instantly get request tracing, rate limiting,
  and structured error handling without any code changes
- Add HSTS, CSP, X-Frame-Options, X-Content-Type-Options to edge proxy
  (src/proxy.ts) — ran at Cloudflare/Vercel edge for all non-asset routes
- Fix rate-limit.ts race condition: compute newCount before assignment
  to shrink the read-modify-write window; add memory-key prefix to
  avoid collisions with Redis keys
- Add request body size limit (10 MB default) to api-handler.ts with
  per-route override via maxBodyBytes option
- Remove unused imports and clean up backward-compat types
2026-07-13 12:09:43 +02:00

41 lines
1.3 KiB
TypeScript

import { NextResponse } from "next/server";
import { proxyAuth } from "@/lib/proxy-auth";
import { shouldRedirectAdminRequest } from "@/lib/proxy-access";
const SECURITY_HEADERS: Record<string, string> = {
"X-Content-Type-Options": "nosniff",
"X-Frame-Options": "DENY",
"X-XSS-Protection": "0",
"Referrer-Policy": "strict-origin-when-cross-origin",
"Permissions-Policy": "camera=(), microphone=(), geolocation=()",
"Strict-Transport-Security": "max-age=63072000; includeSubDomains; preload",
};
export const proxy = proxyAuth((req) => {
if (shouldRedirectAdminRequest(req.nextUrl.pathname, req.auth?.user ?? null)) {
return NextResponse.redirect(new URL("/login", req.url));
}
const headers = new Headers(req.headers);
headers.set("x-pathname", req.nextUrl.pathname);
const ip =
req.headers.get("cf-connecting-ip") ??
req.headers.get("x-forwarded-for")?.split(",")[0]?.trim() ??
req.headers.get("x-real-ip") ??
"";
if (ip) headers.set("x-real-client-ip", ip);
const response = NextResponse.next({ request: { headers } });
for (const [key, value] of Object.entries(SECURITY_HEADERS)) {
response.headers.set(key, value);
}
return response;
});
export const config = {
matcher: ["/((?!api|_next/static|_next/image|assets|favicon.ico).*)"],
};