next.config.ts 1.9 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758
  1. import type { NextConfig } from 'next'
  2. import createNextIntlPlugin from 'next-intl/plugin'
  3. const withNextIntl = createNextIntlPlugin()
  4. const nextConfig: NextConfig = {
  5. output: 'standalone',
  6. images: {
  7. remotePatterns: [],
  8. },
  9. allowedDevOrigins: ['10.0.0.217', '192.168.30.111'],
  10. experimental: {
  11. proxyClientMaxBodySize: '2gb',
  12. },
  13. async headers() {
  14. return [
  15. // Every response. Later, more specific entries win on the same key, so
  16. // the status-report share below still gets its stricter values.
  17. {
  18. source: '/(.*)',
  19. headers: [
  20. { key: 'X-Content-Type-Options', value: 'nosniff' },
  21. // Nothing off this origin may frame the app; the app frames its own
  22. // previews and print views, so same-origin stays allowed.
  23. { key: 'X-Frame-Options', value: 'SAMEORIGIN' },
  24. { key: 'Referrer-Policy', value: 'strict-origin-when-cross-origin' },
  25. // Camera and microphone are used by our own pages (scanning, photos,
  26. // recordings); an embedded third-party frame gets neither.
  27. {
  28. key: 'Permissions-Policy',
  29. value: 'camera=(self), microphone=(self), geolocation=(self)',
  30. },
  31. ],
  32. },
  33. {
  34. source: '/share/status-report/:path*',
  35. headers: [
  36. { key: 'X-Robots-Tag', value: 'noindex, nofollow, noarchive, nosnippet' },
  37. { key: 'X-Frame-Options', value: 'DENY' },
  38. { key: 'Referrer-Policy', value: 'no-referrer' },
  39. { key: 'Cache-Control', value: 'no-store, no-cache, must-revalidate, private' },
  40. { key: 'X-Content-Type-Options', value: 'nosniff' },
  41. ],
  42. },
  43. ]
  44. },
  45. async rewrites() {
  46. return [
  47. // Old /api/files/ URLs stored in the DB before the protected/ restructure
  48. {
  49. source: '/api/files/:path*',
  50. destination: '/api/protected/files/:path*',
  51. },
  52. ]
  53. },
  54. }
  55. export default withNextIntl(nextConfig)