csp fix removed matcher

This commit is contained in:
2025-04-14 18:00:30 +01:00
parent 99e2db34ae
commit 8f1b2b63b4
2 changed files with 27 additions and 25 deletions
+1 -1
View File
@@ -50,7 +50,7 @@ export const Tracking = ({ googleTagManagerID, nonce, cookieObj }) => {
);
};
export const TrackingNoScript = ({ nonce, googleTagManagerID }) => (
export const TrackingNoScript = ({ googleTagManagerID, nonce }) => (
<Fragment>
<noscript>
<iframe
+26 -24
View File
@@ -2,21 +2,23 @@ import { NextResponse } from "next/server";
export function middleware(request) {
const nonce = Buffer.from(crypto.randomUUID()).toString("base64");
const cspHeader = `
const cspHeader =
`
default-src 'self';
script-src 'self' 'nonce-${nonce}' 'strict-dynamic' https: http: ${
process.env.NODE_ENV === "production" ? "" : `'unsafe-eval'`
};
process.env.NODE_ENV === "production" ? "" : `'unsafe-eval'`
};
style-src 'self' 'unsafe-eval' 'unsafe-inline';
img-src 'self' blob: data:;
img-src 'self' 'unsafe-inline' https://www.gov.wales https://gov.wales https://fonts.gstatic.com https://www.googletagmanager.com blob: data:;
connect-src 'self' http://127.0.0.1 https://uksouth-1.in.applicationinsights.azure.com https://ukwest-0.in.applicationinsights.azure.com https://js.monitor.azure.com https://region1.google-analytics.com;
font-src 'self' https://pro.fontawesome.com/ https://fonts.gstatic.com/ ;
object-src 'none';
base-uri 'self';
form-action 'self' ${process.env.NEXTAUTH_URL};
form-action 'self' ` +
process.env.NEXTAUTH_URL +
`;
frame-ancestors 'none';
upgrade-insecure-requests;
frame-src https://datamap.gov.wales;
`;
// csp += `base-uri 'self';`;
@@ -57,21 +59,21 @@ export function middleware(request) {
return response;
}
export const config = {
matcher: [
/*
* Match all request paths except for the ones starting with:
* - api (API routes)
* - _next/static (static files)
* - _next/image (image optimization files)
* - favicon.ico (favicon file)
*/
{
source: "/((?!api|_next/static|_next/image|favicon.ico).*)",
missing: [
{ type: "header", key: "next-router-prefetch" },
{ type: "header", key: "purpose", value: "prefetch" },
],
},
],
};
// export const config = {
// matcher: [
// /*
// * Match all request paths except for the ones starting with:
// * - api (API routes)
// * - _next/static (static files)
// * - _next/image (image optimization files)
// * - favicon.ico (favicon file)
// */
// {
// source: "/((?!api|_next/static|_next/image|favicon.ico).*)",
// missing: [
// { type: "header", key: "next-router-prefetch" },
// { type: "header", key: "purpose", value: "prefetch" },
// ],
// },
// ],
// };