-
Notifications
You must be signed in to change notification settings - Fork 1
/
next.config.cjs
130 lines (120 loc) · 3.42 KB
/
next.config.cjs
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
// @ts-check
/**
* Run `build` or `dev` with `SKIP_ENV_VALIDATION` to skip env validation.
* This is especially useful for Docker builds.
*/
!process.env.SKIP_ENV_VALIDATION && (await import('./src/env.mjs'));
// next.config.js
const runtimeCaching = require('next-pwa/cache');
const crypto = require('crypto');
const withPWA = require('next-pwa')({
dest: 'public',
disable: process.env.NODE_ENV === 'development',
runtimeCaching,
fallbacks: {
// image: '/static/images/fallback.png',
font: '/static/font/fallback.woff2'
}
});
const prod = process.env.NODE_ENV === 'production';
const cshHash = crypto.createHash('sha256');
// const ContentSecurityPolicy = `
// default-src 'self';
// img-src * 'self' https://*.google-analytics.com https://*.googletagmanager.com data: https:;
// script-src 'self' 'unsafe-inline' https://*.googletagmanager.com;
// connect-src 'self' vitals.vercel-insights.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com;
// style-src 'self';
// font-src 'self' data:;
// `;
const ContentSecurityPolicy = `
default-src 'self';
script-src 'self' 'unsafe-eval' 'unsafe-inline' giscus.app www.googletagmanager.com www.google-analytics.com;
style-src 'self' 'unsafe-inline' https://*.googletagmanager.com;
img-src * blob: data:;
media-src 'none';
connect-src 'self' vitals.vercel-insights.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com data:;
font-src 'self' data:
`;
const securityHeaders = [
// https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP
{
key: 'Content-Security-Policy',
value: ContentSecurityPolicy.replace(/\n/g, '')
},
// https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy
{
key: 'Referrer-Policy',
value: 'strict-origin-when-cross-origin'
},
// https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options
{
key: 'X-Frame-Options',
value: 'DENY'
},
// https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options
{
key: 'X-Content-Type-Options',
value: 'nosniff'
},
// https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-DNS-Prefetch-Control
{
key: 'X-DNS-Prefetch-Control',
value: 'on'
},
// https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security
{
key: 'Strict-Transport-Security',
value: 'max-age=31536000; includeSubDomains'
},
// https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Feature-Policy
{
key: 'Permissions-Policy',
value: 'camera=(), microphone=(), geolocation=()'
}
];
module.exports = withPWA({
output: 'standalone',
swcMinify: true,
reactStrictMode: true,
pageExtensions: ['ts', 'tsx', 'js', 'jsx', 'md', 'mdx'],
images: {
domains: [
'static.almondhydroponics.com',
'res.cloudinary.com',
'avatars.githubusercontent.com',
'lh3.googleusercontent.com',
'dev-to-uploads.s3.amazonaws.com'
]
},
eslint: {
ignoreDuringBuilds: true
},
poweredByHeader: false,
async headers() {
return [
{
source: '/(.*)',
headers: securityHeaders
}
];
},
webpack: (config, { dev, isServer }) => {
config.module.rules.push({
test: /\.(png|jpe?g|gif|mp4)$/i,
use: [
{
loader: 'file-loader',
options: {
publicPath: '/_next',
name: 'static/media/[name].[hash].[ext]'
}
}
]
});
config.module.rules.push({
test: /\.svg$/,
use: ['@svgr/webpack']
});
return config;
}
});