feat: security audit, rate limiting, server-side pricing, html escaping and security headers
This commit is contained in:
@@ -5,6 +5,21 @@ const withBundleAnalyzer = bundleAnalyzer({
|
||||
enabled: process.env.ANALYZE === 'true',
|
||||
});
|
||||
|
||||
const cspHeader = `
|
||||
default-src 'self';
|
||||
script-src 'self' 'unsafe-eval' 'unsafe-inline' https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.googletagmanager.com https://www.clarity.ms;
|
||||
style-src 'self' 'unsafe-inline';
|
||||
img-src 'self' blob: data: https://images.unsplash.com https://placehold.co https://c.bing.com https://www.google-analytics.com;
|
||||
font-src 'self';
|
||||
connect-src 'self' https://www.google-analytics.com https://*.clarity.ms;
|
||||
frame-src 'self' https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/;
|
||||
object-src 'none';
|
||||
base-uri 'self';
|
||||
form-action 'self';
|
||||
frame-ancestors 'none';
|
||||
upgrade-insecure-requests;
|
||||
`.replace(/\s{2,}/g, ' ').trim();
|
||||
|
||||
const nextConfig: NextConfig = {
|
||||
experimental: {
|
||||
optimizeCss: true,
|
||||
@@ -25,6 +40,9 @@ const nextConfig: NextConfig = {
|
||||
{ key: 'X-Frame-Options', value: 'DENY' },
|
||||
{ key: 'X-XSS-Protection', value: '1; mode=block' },
|
||||
{ key: 'Referrer-Policy', value: 'strict-origin-when-cross-origin' },
|
||||
{ key: 'Content-Security-Policy', value: cspHeader },
|
||||
{ key: 'Strict-Transport-Security', value: 'max-age=31536000; includeSubDomains; preload' },
|
||||
{ key: 'Permissions-Policy', value: 'camera=(), microphone=(), geolocation=()' },
|
||||
],
|
||||
},
|
||||
];
|
||||
|
||||
Reference in New Issue
Block a user