Skip to content

chore(security): remove Decap CMS and add baseline security headers - #12

Merged
Kvrnn merged 1 commit into
mainfrom
chore/remove-decap-add-security-headers
Sep 28, 2026
Merged

Kvrnn merged 1 commit into
mainfrom
chore/remove-decap-add-security-headers

Conversation

@Kvrnn

@Kvrnn Kvrnn commented Sep 28, 2026

Copy link
Copy Markdown
Member

Summary

Reduces the template's public attack surface. Companion to #11, the /redirect fix. The two PRs touch different parts of src/middleware.ts and should merge in either order.

Remove public/decapcms/

Every template site served this CMS publicly at /decapcms/, and it couldn't have worked:

  • It loaded the Netlify Identity widget and an unpinned decap-cms@^3 build from unpkg, so a third-party CDN script ran on the site.
  • backend: git-gateway needs Netlify Identity. The template deploys to Cloudflare.
  • It wrote posts to src/content/post, but the post loader reads src/data/post.
  • It had no draft field and committed straight to main.

If a client needs a CMS later, the suggested replacement is a git-based CMS with a GitHub backend (e.g. Sveltia CMS) that opens a PR for every edit.

Baseline security headers

  • X-Content-Type-Options: nosniff
  • X-Frame-Options: SAMEORIGIN: blocks framing and clickjacking by other sites. The site's own iframes, like GTM, Termly, and CRM forms, still work.
  • Referrer-Policy: strict-origin-when-cross-origin

These are set in public/_headers for prerendered pages and assets, and in src/middleware.ts for on-demand responses, including /redirect.

Left out on purpose:

  • Permissions-Policy: IframeEmbed.astro grants camera, microphone, and geolocation to embedded CRM forms.
  • CSP: it needs testing against GTM, Termly, GoHighLevel, and Mux first.

Testing

npm run build ✓, astro check 0 errors. wrangler dev --local: headers present on /, /about/, and /redirect/?source=/go, and /decapcms/ returns 404. The only ESLint error in middleware.ts (unused referrer) was already on main, and #11 removes it.

🤖 Generated with Claude Code

- Remove public/decapcms/. It was publicly served at /decapcms/, loaded
  Netlify Identity and an unpinned decap-cms build from unpkg, and could
  not work on the template's Cloudflare deploy (git-gateway needs Netlify
  Identity). Its config also wrote to src/content/post (the post loader
  reads src/data/post), had no draft field, and committed straight to main.
- Add X-Content-Type-Options, X-Frame-Options (SAMEORIGIN), and
  Referrer-Policy to public/_headers for prerendered pages and assets, and
  in middleware for on-demand responses (including /redirect).
  Permissions-Policy is intentionally omitted: IframeEmbed grants
  camera/microphone/geolocation to embedded CRM forms.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-28T03:07:13.033489Z 8e6784e PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk: medium. Cursor Bugbot was not present after the first check poll, so that signal was skipped. Approved: the PR stays at or below the medium-risk threshold, no applicable approval policy requires human review, and no reviewers were assigned.

Open in Web View Automation 

Sent by Cursor Approval Agent: NST: PR Approver

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8e6784ed00

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread public/_headers
Comment on lines +1 to +4
/*
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
Referrer-Policy: strict-origin-when-cross-origin

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Configure headers for every supported deployment

These headers rely on the provider-specific _headers convention, so they are absent when the prerendered site is deployed through other supported paths. In particular, the Vercel deployment is governed by vercel.json, which still configures only cache headers, while the bundled Docker image serves dist through nginx/nginx.conf without any add_header directives; middleware cannot add headers to those statically served responses. Add equivalent rules to those deployment configurations so Vercel and Docker users actually receive the advertised baseline.

Useful? React with 👍 / 👎.

@Kvrnn
Kvrnn merged commit b7d1348 into main Sep 28, 2026
8 of 9 checks passed
@Kvrnn
Kvrnn deleted the chore/remove-decap-add-security-headers branch September 28, 2026 03:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant