Files
petfeed/next.config.ts
T
admin f559b3d68e feat(observability): add Sentry error monitoring (@sentry/nextjs)
Server, edge, and client instrumentation wired up via SENTRY_DSN /
NEXT_PUBLIC_SENTRY_DSN. Fully inert without a DSN configured (verified
with a clean local build + full test suite) — safe to ship ahead of
actually having a Sentry project. Source-map upload is opt-in via
SENTRY_AUTH_TOKEN (kept out of the Docker build-arg chain since build
args land in image layer history; only the public DSN is a build arg).
2026-08-10 12:57:42 +02:00

91 lines
3.4 KiB
TypeScript

import type { NextConfig } from "next";
import createNextIntlPlugin from "next-intl/plugin";
import { withSentryConfig } from "@sentry/nextjs";
const withNextIntl = createNextIntlPlugin("./src/i18n/request.ts");
function getSupabaseHostname(): string {
const url = process.env.NEXT_PUBLIC_SUPABASE_URL;
if (url) {
try { return new URL(url).hostname; } catch { /* fall through */ }
}
return "*.supabase.co";
}
// Drafted but NOT wired into headers() yet — enabling it blanked the entire
// app (ClerkProvider wraps the whole tree in layout.tsx; a blocked resource
// during its client-side init throws, and nothing catches it, so the app
// crashes to a blank page instead of just breaking the login widget).
// Confirmed live on 2026-08-10 that disabling this CSP fixes it; adding
// wss://clerk.pawfeed.org to connect-src did NOT fix it, so the real blocked
// directive is still unidentified. Next attempt should ship as
// Content-Security-Policy-Report-Only first (with a /api/csp-report endpoint)
// to see actual violation reports before enforcing on production again.
function buildCsp(): string {
const supabase = `https://${getSupabaseHostname()}`;
const directives: Record<string, string[]> = {
"default-src": ["'self'"],
"script-src": ["'self'", "https://clerk.pawfeed.org"],
// Radix/shadcn primitives set inline style="" attributes for positioning —
// no nonce mechanism covers style attributes, so 'unsafe-inline' is required here.
"style-src": ["'self'", "'unsafe-inline'"],
"img-src": ["'self'", "data:", supabase, "https://image.mux.com", "https://img.clerk.com"],
"font-src": ["'self'", "data:"],
"media-src": ["'self'", "blob:", "https://stream.mux.com"],
"worker-src": ["'self'", "blob:"],
"connect-src": [
"'self'",
"https://clerk.pawfeed.org",
"wss://clerk.pawfeed.org",
"https://accounts.pawfeed.org",
supabase,
"https://stream.mux.com",
"https://image.mux.com",
"https://litix.io",
"https://storage.googleapis.com",
],
"frame-src": ["'self'", "https://clerk.pawfeed.org"],
"frame-ancestors": ["'none'"],
"object-src": ["'none'"],
"base-uri": ["'self'"],
};
return Object.entries(directives)
.map(([key, values]) => `${key} ${values.join(" ")}`)
.join("; ");
}
const nextConfig: NextConfig = {
output: "standalone",
allowedDevOrigins: ["192.168.1.92"],
images: {
remotePatterns: [
{ protocol: "https", hostname: getSupabaseHostname() },
],
},
async headers() {
return [
{
source: "/(.*)",
headers: [
{ key: "X-Content-Type-Options", value: "nosniff" },
{ key: "X-Frame-Options", value: "DENY" },
{ key: "Referrer-Policy", value: "strict-origin-when-cross-origin" },
{ key: "Permissions-Policy", value: "camera=(), microphone=(), geolocation=()" },
{ key: "Strict-Transport-Security", value: "max-age=31536000; includeSubDomains" },
],
},
];
},
};
export default withSentryConfig(withNextIntl(nextConfig), {
org: process.env.SENTRY_ORG,
project: process.env.SENTRY_PROJECT,
authToken: process.env.SENTRY_AUTH_TOKEN,
silent: true,
// No auth token configured on this self-hosted deploy yet — skip
// source-map upload rather than failing the Docker build.
sourcemaps: { disable: !process.env.SENTRY_AUTH_TOKEN },
disableLogger: true,
});