Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 6 additions & 1 deletion public/_headers
Original file line number Diff line number Diff line change
@@ -1,2 +1,7 @@
/*
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
Referrer-Policy: strict-origin-when-cross-origin
Comment on lines +1 to +4

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Configure headers for every supported deployment

These headers rely on the provider-specific _headers convention, so they are absent when the prerendered site is deployed through other supported paths. In particular, the Vercel deployment is governed by vercel.json, which still configures only cache headers, while the bundled Docker image serves dist through nginx/nginx.conf without any add_header directives; middleware cannot add headers to those statically served responses. Add equivalent rules to those deployment configurations so Vercel and Docker users actually receive the advertised baseline.

Useful? React with 👍 / 👎.


/_astro/*
Cache-Control: public, max-age=31536000, immutable
Cache-Control: public, max-age=31536000, immutable
29 changes: 0 additions & 29 deletions public/decapcms/config.yml

This file was deleted.

14 changes: 0 additions & 14 deletions public/decapcms/index.html

This file was deleted.

27 changes: 25 additions & 2 deletions src/middleware.ts
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ export const onRequest = defineMiddleware(async (context, next) => {
if (import.meta.env.DEV) {
console.log('[Redirect Middleware] Skipping redirect page:', pathname);
}
return next();
return withSecurityHeaders(await next());
}

// Debug logging (remove in production if desired)
Expand Down Expand Up @@ -120,5 +120,28 @@ export const onRequest = defineMiddleware(async (context, next) => {
}

// No redirect found, continue with normal request handling
return next();
return withSecurityHeaders(await next());
});

/**
* Baseline security headers for on-demand (Worker-rendered) responses.
* Prerendered pages and static assets get the same set from public/_headers.
* Keep the two lists in sync.
*/
const SECURITY_HEADERS: Record<string, string> = {
'X-Content-Type-Options': 'nosniff',
'X-Frame-Options': 'SAMEORIGIN',
'Referrer-Policy': 'strict-origin-when-cross-origin',
};

function withSecurityHeaders(response: Response): Response {
try {
for (const [name, value] of Object.entries(SECURITY_HEADERS)) response.headers.set(name, value);
return response;
} catch {
// Some responses have immutable headers; copy into a mutable response instead
const copy = new Response(response.body, response);
for (const [name, value] of Object.entries(SECURITY_HEADERS)) copy.headers.set(name, value);
return copy;
}
}
Loading