-
Notifications
You must be signed in to change notification settings - Fork 26
Expand file tree
/
Copy pathnext.config.js
More file actions
40 lines (38 loc) · 1.85 KB
/
Copy pathnext.config.js
File metadata and controls
40 lines (38 loc) · 1.85 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
// Security headers applied to every response. We deliberately do NOT set a
// restrictive script-src/style-src CSP here: the app relies on inline styles,
// Next.js inline bootstrap scripts, the crawlproof.com analytics script, and
// Supabase image/websocket origins, so an enforcing CSP would break it. We only
// set `frame-ancestors` (clickjacking protection) plus the other low-risk
// hardening headers. HSTS only affects HTTPS responses (ignored over the Tor
// http onion service, which is fine).
const securityHeaders = [
{ key: 'Strict-Transport-Security', value: 'max-age=31536000; includeSubDomains' },
{ key: 'X-Content-Type-Options', value: 'nosniff' },
{ key: 'X-Frame-Options', value: 'SAMEORIGIN' },
{ key: 'Content-Security-Policy', value: "frame-ancestors 'self'" },
{ key: 'Referrer-Policy', value: 'strict-origin-when-cross-origin' },
{ key: 'Permissions-Policy', value: 'geolocation=(), browsing-topics=()' },
];
/** @type {import('next').NextConfig} */
const nextConfig = {
reactStrictMode: true,
// The image runs the standalone server under Bun (`bun server.js` from
// entrypoint.sh): server.js plus only the dependencies it imports.
output: 'standalone',
// Trace from this directory, never a lockfile further up the disk.
outputFileTracingRoot: new URL('.', import.meta.url).pathname,
// /api/plugins lists community-plugins/*/plugin.json from process.cwd() at
// request time; the tracer only follows imports, so name the files.
outputFileTracingIncludes: {
'/api/plugins': ['./community-plugins/**/*'],
},
// Linting is a dev/CI concern — don't let an ESLint error (e.g. a parse
// error in an unused util) fail the production build / Railway deploy.
eslint: {
ignoreDuringBuilds: true,
},
async headers() {
return [{ source: '/:path*', headers: securityHeaders }];
},
};
export default nextConfig;