forked from codechefPesuecc/CodeChef-PESUECC-Chapter
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathnext.config.ts
More file actions
62 lines (56 loc) · 2.34 KB
/
Copy pathnext.config.ts
File metadata and controls
62 lines (56 loc) · 2.34 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
import type { NextConfig } from "next";
import { buildTeamManifest } from "./scripts/build-team.mjs";
// Bundle the filesystem-backed team roster into a manifest before the build/dev
// server reads it — Cloudflare Workers have no filesystem (see src/app/team/lib.ts).
// Challenges are NOT bundled: they live in the database (see src/lib/challenges.ts)
// and are published with `npm run challenges:seed`, no redeploy required.
buildTeamManifest();
const isDev = process.env.NODE_ENV !== "production";
// Content-Security-Policy. `'unsafe-inline'` is required for Next's inline
// bootstrap scripts and CodeMirror/next-font's injected styles (no nonce plumbing
// yet); `'unsafe-eval'` is dev-only (HMR), and `upgrade-insecure-requests` is
// prod-only so it doesn't break http://localhost. challenges.cloudflare.com is
// allowed for Turnstile (active only when its keys are set).
const csp = [
"default-src 'self'",
"base-uri 'self'",
"object-src 'none'",
"frame-ancestors 'none'",
"form-action 'self'",
"img-src 'self' data: blob:",
"font-src 'self'",
"style-src 'self' 'unsafe-inline'",
`script-src 'self' 'unsafe-inline'${isDev ? " 'unsafe-eval'" : ""} https://challenges.cloudflare.com`,
"connect-src 'self' https://challenges.cloudflare.com",
"frame-src 'self' https://challenges.cloudflare.com",
"worker-src 'self' blob:",
"manifest-src 'self'",
...(isDev ? [] : ["upgrade-insecure-requests"]),
].join("; ");
const securityHeaders = [
{ key: "Content-Security-Policy", value: csp },
{
key: "Strict-Transport-Security",
value: "max-age=63072000; includeSubDomains; preload",
},
{ key: "X-Content-Type-Options", value: "nosniff" },
{ key: "X-Frame-Options", value: "DENY" },
{ key: "Referrer-Policy", value: "strict-origin-when-cross-origin" },
{
key: "Permissions-Policy",
value: "camera=(), microphone=(), geolocation=(), browsing-topics=()",
},
];
const nextConfig: NextConfig = {
// Pin the workspace root so Next.js doesn't infer it from a stray
// lockfile elsewhere on the machine (e.g. the user home directory).
turbopack: {
root: import.meta.dirname,
},
// Keep the native libSQL client out of the bundler; load it at runtime.
serverExternalPackages: ["@libsql/client", "libsql"],
async headers() {
return [{ source: "/:path*", headers: securityHeaders }];
},
};
export default nextConfig;