Security+UX: Add DOMPurify XSS protection, security headers, admin auth gate, import file size limit, due date color coding, swipe/scroll conflict prevention

This commit is contained in:
Wonhee Han
2026-08-20 22:58:47 +09:00
parent 765f670ef0
commit dd01a8ec69
8 changed files with 136 additions and 22 deletions
+18 -1
View File
@@ -2,13 +2,30 @@ import type { NextConfig } from "next";
const nextConfig: NextConfig = {
output: "standalone",
// PWA service worker (manual - no next-pwa needed)
async headers() {
return [
{
source: "/manifest.json",
headers: [{ key: "Content-Type", value: "application/manifest+json" }],
},
{
// 모든 라우트에 보안 헤더 적용
source: "/(.*)",
headers: [
{ key: "X-Frame-Options", value: "DENY" },
{ key: "X-Content-Type-Options", value: "nosniff" },
{ key: "X-XSS-Protection", value: "1; mode=block" },
{ key: "Referrer-Policy", value: "strict-origin-when-cross-origin" },
{
key: "Permissions-Policy",
value: "camera=(), microphone=(), geolocation=()",
},
{
key: "Strict-Transport-Security",
value: "max-age=63072000; includeSubDomains; preload",
},
],
},
];
},
};