fix: address code review findings from 2026-08-17

- scope no-cache headers to non-static routes (restore immutable asset caching)
- reset cached rejected MongoDB promise so retries can succeed
- use last X-Forwarded-For entry in Content Editor rate limiter (anti-spoofing)
- remove weak Mongo defaults from compose files (fail loudly on missing env)
- move staging banner text to common.json content
- read APP_PORT from env file in deploy.sh healthcheck
- filter network noise from staging smoke console assertions

Closes MITHOME-48, MITHOME-49, MITHOME-50, MITHOME-51, MITHOME-52, MITHOME-53, MITHOME-54
This commit is contained in:
Do Siki
2026-08-18 12:21:32 +02:00
parent 93aaa10a36
commit bd7287aa58
14 changed files with 115 additions and 17 deletions
+11 -1
View File
@@ -37,7 +37,8 @@ const nextConfig: NextConfig = {
async headers() {
return [
{
source: '/(.*)',
// Security headers apply to every route, including static assets.
source: '/:path*',
headers: [
{
key: 'X-Frame-Options',
@@ -51,6 +52,15 @@ const nextConfig: NextConfig = {
key: 'Referrer-Policy',
value: 'origin-when-cross-origin',
},
],
},
{
// WHY: no-cache must not hit hashed build assets (_next/static) or
// optimized images (_next/image); they are content-addressed and rely on
// long-lived caching. Overriding them would re-download the bundle on
// every page load.
source: '/((?!_next/static|_next/image).*)',
headers: [
{
key: 'Cache-Control',
value: 'private, no-cache, must-revalidate, max-age=0',