import type { NextConfig } from "next"; import { withSentryConfig } from "@sentry/nextjs"; // NOTE: The Content-Security-Policy is set per-request in `proxy.ts` (Next // middleware) so `script-src` can carry a per-request nonce instead of // 'unsafe-inline'. A static header here cannot carry a per-request nonce and // would conflict with the middleware, so it is intentionally omitted below. const nextConfig: NextConfig = { // Emit a self-contained server bundle at .next/standalone so the Docker // image (deployed to DigitalOcean App Platform) ships only the files needed to run `node server.js`. output: "standalone", // Strict security headers applied to every route. async headers() { return [ { source: "/(.*)", headers: [ { key: "X-Content-Type-Options", value: "nosniff" }, { key: "X-Frame-Options", value: "DENY" }, // no-referrer prevents the tenant-portal token (carried in the URL) // from leaking to third parties via the Referer header. { key: "Referrer-Policy", value: "no-referrer" }, { key: "Strict-Transport-Security", value: "max-age=63072000; includeSubDomains; preload", }, { key: "X-DNS-Prefetch-Control", value: "off" }, ], }, ]; }, }; export default withSentryConfig(nextConfig, { org: "phluit", project: "property-management-network", // Only print source-map upload logs in CI. silent: !process.env.CI, // Upload a wider set of client source maps for readable stack traces. widenClientFileUpload: true, // Tree-shake Sentry's debug logger to shrink the client bundle. disableLogger: true, // Source-map upload runs at build time only when SENTRY_AUTH_TOKEN is set; // without it the build still succeeds (stack traces just aren't un-minified). });