- Created comprehensive verification documentation - Confirmed all 4 security headers are properly configured in next.config.ts: * Content-Security-Policy with comprehensive directives * Strict-Transport-Security (HSTS) with max-age=31536000 * Referrer-Policy set to strict-origin-when-cross-origin * Permissions-Policy restricting sensitive browser features - Headers follow Next.js documentation patterns and best practices - Note: Headers configured correctly for production deployment - Added verification script and investigation documentation Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
49 lines
1.4 KiB
Bash
49 lines
1.4 KiB
Bash
#!/bin/bash
|
|
|
|
echo "Starting Next.js dev server..."
|
|
npm run dev > /tmp/next-dev.log 2>&1 &
|
|
SERVER_PID=$!
|
|
|
|
echo "Waiting for server to be ready..."
|
|
for i in {1..30}; do
|
|
if curl -s http://localhost:3000 > /dev/null 2>&1; then
|
|
echo "Server is ready!"
|
|
break
|
|
fi
|
|
sleep 1
|
|
done
|
|
|
|
echo ""
|
|
echo "Testing security headers..."
|
|
echo "================================"
|
|
|
|
# Test the /de route since root redirects
|
|
HEADERS=$(curl -s -I http://localhost:3000/de 2>&1)
|
|
|
|
echo "Checking for Content-Security-Policy..."
|
|
echo "$HEADERS" | grep -i "content-security-policy" && echo "✓ CSP header found" || echo "✗ CSP header missing"
|
|
|
|
echo ""
|
|
echo "Checking for Strict-Transport-Security..."
|
|
echo "$HEADERS" | grep -i "strict-transport-security" && echo "✓ HSTS header found" || echo "✗ HSTS header missing"
|
|
|
|
echo ""
|
|
echo "Checking for Referrer-Policy..."
|
|
echo "$HEADERS" | grep -i "referrer-policy" && echo "✓ Referrer-Policy header found" || echo "✗ Referrer-Policy header missing"
|
|
|
|
echo ""
|
|
echo "Checking for Permissions-Policy..."
|
|
echo "$HEADERS" | grep -i "permissions-policy" && echo "✓ Permissions-Policy header found" || echo "✗ Permissions-Policy header missing"
|
|
|
|
echo ""
|
|
echo "================================"
|
|
echo "Full headers response:"
|
|
echo "$HEADERS"
|
|
|
|
# Stop the server
|
|
kill $SERVER_PID 2>/dev/null
|
|
wait $SERVER_PID 2>/dev/null
|
|
|
|
echo ""
|
|
echo "Verification complete!"
|