import type { NextConfig } from "next"; // NOTE: The Content-Security-Policy is set per-request in `proxy.ts` (Next // middleware) so `script-src` can carry a per-request nonce instead of // 'unsafe-inline'. A static header here cannot carry a per-request nonce and // would conflict with the middleware, so it is intentionally omitted below. const nextConfig: NextConfig = { // Emit a self-contained server bundle at .next/standalone so the Docker // image (deployed to DigitalOcean App Platform) ships only the files needed to run `node server.js`. output: "standalone", // Strict security headers applied to every route. async headers() { return [ { source: "/(.*)", headers: [ { key: "X-Content-Type-Options", value: "nosniff" }, { key: "X-Frame-Options", value: "DENY" }, // no-referrer prevents the tenant-portal token (carried in the URL) // from leaking to third parties via the Referer header. { key: "Referrer-Policy", value: "no-referrer" }, { key: "Strict-Transport-Security", value: "max-age=63072000; includeSubDomains; preload", }, { key: "X-DNS-Prefetch-Control", value: "off" }, ], }, ]; }, }; export default nextConfig;