-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathnext.config.ts
More file actions
95 lines (91 loc) · 2.65 KB
/
Copy pathnext.config.ts
File metadata and controls
95 lines (91 loc) · 2.65 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
import type { NextConfig } from "next";
const nextConfig: NextConfig = {
output: "standalone",
poweredByHeader: false, // Don't expose Next.js version
// CORS configuration
async headers() {
return [
{
// Apply security headers to all routes
source: "/(.*)",
headers: [
{
key: "X-Content-Type-Options",
value: "nosniff", // Prevent MIME type sniffing
},
{
key: "X-Frame-Options",
value: "DENY", // Prevent clickjacking attacks
},
{
key: "X-XSS-Protection",
value: "1; mode=block", // Enable browser XSS filters
},
{
key: "Referrer-Policy",
value: "strict-origin-when-cross-origin", // Control referrer information
},
{
key: "Permissions-Policy",
value: "geolocation=(), microphone=(), camera=()", // Disable unused APIs
},
{
key: "Strict-Transport-Security",
value: "max-age=31536000; includeSubDomains; preload", // Force HTTPS for 1 year
},
// CORS headers - restrict to same origin by default
{
key: "Access-Control-Allow-Origin",
value: process.env.CORS_ORIGIN || "null", // Same-origin only by default
},
{
key: "Access-Control-Allow-Methods",
value: "GET, POST, PUT, DELETE, OPTIONS",
},
{
key: "Access-Control-Allow-Headers",
value: "Content-Type, Authorization, X-Requested-With",
},
{
key: "Access-Control-Max-Age",
value: "86400", // 24 hours
},
],
},
{
// API routes get stricter CSP
source: "/api/:path*",
headers: [
{
key: "Content-Security-Policy",
value: "default-src 'none'; script-src 'self'; style-src 'self'", // No inline scripts
},
],
},
{
// Cache busting for static assets
source: "/_next/static/:path*",
headers: [
{
key: "Cache-Control",
value: "public, max-age=31536000, immutable", // 1 year for immutable assets
},
],
},
];
},
async redirects() {
// In production, force HTTPS (requires proper reverse proxy setup)
if (process.env.NODE_ENV === "production" && !process.env.ALLOW_HTTP) {
return [
{
source: "/",
destination: "https://:host",
permanent: true,
},
];
}
return [];
},
};
export default nextConfig;