chore(security): remove Decap CMS and add baseline security headers - #12
Conversation
- Remove public/decapcms/. It was publicly served at /decapcms/, loaded Netlify Identity and an unpinned decap-cms build from unpkg, and could not work on the template's Cloudflare deploy (git-gateway needs Netlify Identity). Its config also wrote to src/content/post (the post loader reads src/data/post), had no draft field, and committed straight to main. - Add X-Content-Type-Options, X-Frame-Options (SAMEORIGIN), and Referrer-Policy to public/_headers for prerendered pages and assets, and in middleware for on-demand responses (including /redirect). Permissions-Policy is intentionally omitted: IframeEmbed grants camera/microphone/geolocation to embedded CRM forms.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8e6784ed00
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| /* | ||
| X-Content-Type-Options: nosniff | ||
| X-Frame-Options: SAMEORIGIN | ||
| Referrer-Policy: strict-origin-when-cross-origin |
There was a problem hiding this comment.
Configure headers for every supported deployment
These headers rely on the provider-specific _headers convention, so they are absent when the prerendered site is deployed through other supported paths. In particular, the Vercel deployment is governed by vercel.json, which still configures only cache headers, while the bundled Docker image serves dist through nginx/nginx.conf without any add_header directives; middleware cannot add headers to those statically served responses. Add equivalent rules to those deployment configurations so Vercel and Docker users actually receive the advertised baseline.
Useful? React with 👍 / 👎.


Summary
Reduces the template's public attack surface. Companion to #11, the
/redirectfix. The two PRs touch different parts ofsrc/middleware.tsand should merge in either order.Remove
public/decapcms/Every template site served this CMS publicly at
/decapcms/, and it couldn't have worked:decap-cms@^3build from unpkg, so a third-party CDN script ran on the site.backend: git-gatewayneeds Netlify Identity. The template deploys to Cloudflare.src/content/post, but the post loader readssrc/data/post.draftfield and committed straight tomain.If a client needs a CMS later, the suggested replacement is a git-based CMS with a GitHub backend (e.g. Sveltia CMS) that opens a PR for every edit.
Baseline security headers
X-Content-Type-Options: nosniffX-Frame-Options: SAMEORIGIN: blocks framing and clickjacking by other sites. The site's own iframes, like GTM, Termly, and CRM forms, still work.Referrer-Policy: strict-origin-when-cross-originThese are set in
public/_headersfor prerendered pages and assets, and insrc/middleware.tsfor on-demand responses, including/redirect.Left out on purpose:
Permissions-Policy:IframeEmbed.astrogrants camera, microphone, and geolocation to embedded CRM forms.Testing
npm run build✓,astro check0 errors.wrangler dev --local: headers present on/,/about/, and/redirect/?source=/go, and/decapcms/returns 404. The only ESLint error inmiddleware.ts(unusedreferrer) was already onmain, and #11 removes it.🤖 Generated with Claude Code