fix: address code review findings from 2026-08-17
- scope no-cache headers to non-static routes (restore immutable asset caching) - reset cached rejected MongoDB promise so retries can succeed - use last X-Forwarded-For entry in Content Editor rate limiter (anti-spoofing) - remove weak Mongo defaults from compose files (fail loudly on missing env) - move staging banner text to common.json content - read APP_PORT from env file in deploy.sh healthcheck - filter network noise from staging smoke console assertions Closes MITHOME-48, MITHOME-49, MITHOME-50, MITHOME-51, MITHOME-52, MITHOME-53, MITHOME-54
This commit is contained in:
+11
-1
@@ -37,7 +37,8 @@ const nextConfig: NextConfig = {
|
||||
async headers() {
|
||||
return [
|
||||
{
|
||||
source: '/(.*)',
|
||||
// Security headers apply to every route, including static assets.
|
||||
source: '/:path*',
|
||||
headers: [
|
||||
{
|
||||
key: 'X-Frame-Options',
|
||||
@@ -51,6 +52,15 @@ const nextConfig: NextConfig = {
|
||||
key: 'Referrer-Policy',
|
||||
value: 'origin-when-cross-origin',
|
||||
},
|
||||
],
|
||||
},
|
||||
{
|
||||
// WHY: no-cache must not hit hashed build assets (_next/static) or
|
||||
// optimized images (_next/image); they are content-addressed and rely on
|
||||
// long-lived caching. Overriding them would re-download the bundle on
|
||||
// every page load.
|
||||
source: '/((?!_next/static|_next/image).*)',
|
||||
headers: [
|
||||
{
|
||||
key: 'Cache-Control',
|
||||
value: 'private, no-cache, must-revalidate, max-age=0',
|
||||
|
||||
Reference in New Issue
Block a user