-
Notifications
You must be signed in to change notification settings - Fork 111
Expand file tree
/
Copy pathnext.config.js
More file actions
91 lines (88 loc) · 2.7 KB
/
Copy pathnext.config.js
File metadata and controls
91 lines (88 loc) · 2.7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
const withBundleAnalyzer = require("@next/bundle-analyzer")({
enabled: process.env.ANALYZE === "true",
});
const { withSentryConfig } = require("@sentry/nextjs");
/** @type {import('next').NextConfig} */
const nextConfig = {
images: {
// Recipient avatars fall back to Gravatar; served unoptimized so no image
// requests are proxied through the Next.js optimizer.
remotePatterns: [
{
protocol: "https",
hostname: "www.gravatar.com",
pathname: "/avatar/**",
},
],
},
async headers() {
return [
{
// Applied to every route; the more specific /embed/:id rule below
// overrides X-Frame-Options for that one path.
source: "/:path*",
headers: [
{ key: "X-Frame-Options", value: "DENY" },
{ key: "X-Content-Type-Options", value: "nosniff" },
{ key: "Referrer-Policy", value: "strict-origin-when-cross-origin" },
{
key: "Strict-Transport-Security",
value: "max-age=63072000; includeSubDomains; preload",
},
{
key: "Permissions-Policy",
value: "camera=(), microphone=(), geolocation=(), payment=(self)",
},
],
},
{
source: "/sw.js",
headers: [
{ key: "Cache-Control", value: "no-cache, no-store, must-revalidate" },
{ key: "Service-Worker-Allowed", value: "/" },
],
},
{
source: "/embed/:id",
headers: [
{ key: "X-Frame-Options", value: "ALLOWALL" },
],
},
];
},
webpack: (config, { isServer }) => {
if (!isServer) {
// sodium-native is a Node.js native module — exclude from browser bundle
config.resolve.fallback = {
...config.resolve.fallback,
fs: false,
net: false,
tls: false,
};
}
// Exclude sodium-native from webpack entirely
config.externals = [
...(Array.isArray(config.externals) ? config.externals : []),
"sodium-native",
];
// @apm-js-collab/tracing-hooks is an optional Sentry internal — skip it
config.resolve.alias = {
...config.resolve.alias,
"@apm-js-collab/tracing-hooks": false,
};
return config;
},
};
const sentryWebpackPluginOptions = {
org: process.env.SENTRY_ORG,
project: process.env.SENTRY_PROJECT,
authToken: process.env.SENTRY_AUTH_TOKEN,
// Only upload source maps when a real DSN is configured (i.e. in CI / production)
silent: true,
disableServerWebpackPlugin: !process.env.NEXT_PUBLIC_SENTRY_DSN,
disableClientWebpackPlugin: !process.env.NEXT_PUBLIC_SENTRY_DSN,
};
module.exports = withSentryConfig(
withBundleAnalyzer(nextConfig),
sentryWebpackPluginOptions
);